Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by kory (administrator) on PB-7D1560991FC9 on 08-10-2013 09:02:50
Running from C:\Documents and Settings\kory\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD13\PowerDVD13Agent.exe
(forum.viry.cz) C:\Documents and Settings\kory\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKCU\...\Policies\system: [EnableLUA] 0
HKU\Default User\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32
HKU\LocalService\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32
HKU\UpdatusUser\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32
BootExecute: autocheck autochk * sh4native Sh4Removal
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... R}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {DA9BD144-37DB-4C47-9C2E-BB9104FFE825} URL =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {DA9BD144-37DB-4C47-9C2E-BB9104FFE825} URL =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [
jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR Extension: () - C:\DOCUME~1\kory\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\fbephpdejkehiohdhedkphnmphcoafdk\1
========================== Services (Whitelisted) =================
S4 ACS; C:\WINDOWS\system32\acs.exe [499796 2011-04-11] (Atheros)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
S4 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-07-05] (CyberLink)
S4 CyberLink PowerDVD 13 Media Server Service; C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-07-05] (CyberLink)
S3 jswpsapi; C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe [360529 2011-04-11] (wireless)
S4 ADExchange;
S4 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1606976 2011-04-11] (Atheros Communications, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [177864 2013-08-30] ()
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51120 2005-03-08] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-03-08] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2005-03-08] (HP)
R3 JSWSCIMD; C:\Windows\System32\DRIVERS\jswscimd.sys [57440 2011-04-11] (Atheros Communications, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2005-11-02] (Padus, Inc.)
R2 thdudf; C:\Windows\System32\DRIVERS\thdudf.sys [66944 2006-11-11] (TOSHIBA Corporation)
R0 TPkd; C:\Windows\System32\Drivers\TPkd.sys [93232 2008-09-08] (PACE Anti-Piracy, Inc.)
R3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [58208 2011-04-11] (Atheros Communications, Inc.)
S3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [232064 2005-05-06] (Marvell)
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [76560 2013-07-06] (CyberLink Corp.)
S1 ArcCtrl; system32\drivers\ArcCtrl.sys [x]
S1 ArcSec; system32\drivers\ArcSec.sys [x]
S3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [x]
S4 IntelIde; No ImagePath
S3 RT61; system32\DRIVERS\RT61.sys [x]
U1 WS2IFSL;
S2 zumbus; system32\DRIVERS\zumbus.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-08 09:02 - 2013-10-08 09:02 - 00000000 ____D C:\FRST
2013-10-08 09:01 - 2013-10-08 09:01 - 00112128 _____ (forum.viry.cz) C:\Documents and Settings\kory\Plocha\FRSTLauncher.exe
2013-10-08 08:59 - 2013-10-08 08:59 - 01087213 _____ (Farbar) C:\Documents and Settings\kory\Plocha\FRST.exe
2013-10-08 08:56 - 2013-10-08 08:56 - 00001525 _____ C:\Documents and Settings\All Users\Plocha\mkvmerge GUI.lnk
2013-10-08 08:56 - 2013-10-08 08:56 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MKVToolNix
2013-10-08 08:44 - 2013-10-08 08:44 - 00000821 _____ C:\Documents and Settings\kory\Plocha\tsMuxerGUI.lnk
2013-10-08 08:35 - 2013-10-08 08:35 - 02806952 _____ C:\Documents and Settings\kory\Dokumenty\tsMuxeR_1.12.14b.zip
2013-10-08 07:54 - 2013-10-08 07:56 - 112060463 _____ C:\Documents and Settings\kory\Dokumenty\Aplikace Nokia Pro Cam - Stereo video pro Lumia 820, Lumia 920 ....mp4
2013-10-08 06:39 - 2013-10-08 06:39 - 00000000 ___HD C:\WINDOWS\PIF
2013-10-07 23:53 - 2013-10-07 23:53 - 00000841 _____ C:\WINDOWS\WindowsUpdate.log
2013-10-07 22:11 - 2013-10-07 22:11 - 04369632 _____ (Piriform Ltd) C:\Documents and Settings\kory\Dokumenty\ccsetup406.exe
2013-10-04 07:43 - 2013-10-07 23:02 - 00000000 ____D C:\rsit
2013-10-04 07:43 - 2013-10-07 23:02 - 00000000 ____D C:\Program Files\trend micro
2013-10-04 07:43 - 2013-10-04 07:43 - 00781909 _____ C:\Documents and Settings\kory\Plocha\RSIT.exe
2013-10-03 08:37 - 2013-10-03 08:37 - 01278372 _____ C:\Documents and Settings\kory\Plocha\Track 2013-08-17 10_32.gpx
2013-10-02 16:07 - 2013-10-04 13:34 - 00000130 _____ C:\WINDOWS\pink
2013-10-02 16:07 - 2013-10-02 16:08 - 00000000 ____D C:\Documents and Settings\kory\Plocha\rytir hra
2013-10-02 16:07 - 2013-10-02 16:07 - 05846158 _____ C:\Documents and Settings\kory\Plocha\wf.zip
2013-09-30 17:54 - 2013-09-30 19:08 - 682168321 _____ C:\Documents and Settings\kory\Dokumenty\Ucastnici-zajezdu.avi
2013-09-30 09:58 - 2013-09-30 09:58 - 00000000 ____D C:\Documents and Settings\kory\Local Settings\Data aplikací\Cyberlink SoftDMA
2013-09-30 09:58 - 2013-09-30 09:58 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\CyberLink
2013-09-30 09:56 - 2013-09-30 09:56 - 00001808 _____ C:\Documents and Settings\All Users\Plocha\CyberLink PowerDVD 13.lnk
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\MediaServer
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\kory\CyberLink
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CyberLink PowerDVD 13
2013-09-30 09:54 - 2013-09-30 09:54 - 00000000 ____D C:\Program Files\CyberLink
2013-09-28 22:45 - 2013-09-30 09:31 - 09743083 _____ (Moritz Bunkus) C:\Documents and Settings\kory\Dokumenty\mkvtoolnix-unicode-6.4.1-setup.exe
2013-09-28 07:41 - 2013-09-28 07:41 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\045662
2013-09-24 06:04 - 2013-09-24 06:04 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\Nabijecka_ze_zdroje_PC
2013-09-24 06:01 - 2011-11-22 17:37 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\Kniha Inteligentní nabíječky
2013-09-24 05:51 - 2013-09-24 05:57 - 118697383 _____ C:\Documents and Settings\kory\Dokumenty\Kniha-Inteligentní-nabíječky.rar
2013-09-11 07:06 - 2013-09-11 07:06 - 00042348 _____ C:\Documents and Settings\kory\Dokumenty\kyo126.xps
2013-09-11 06:48 - 2013-09-11 06:48 - 11611134 _____ C:\Documents and Settings\kory\Dokumenty\onkyo.bmp
2013-09-10 00:25 - 2013-09-10 00:26 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\FLASH
2013-09-10 00:23 - 2010-08-07 15:38 - 07997251 _____ (AIMP DevTeam) C:\Documents and Settings\kory\Dokumenty\aimp_2.61.583.exe
2013-09-08 16:39 - 2013-09-08 16:39 - 00001460 _____ C:\Documents and Settings\All Users\Plocha\Counter-Strike Source.lnk
2013-09-08 16:39 - 2013-09-08 16:39 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Counter-Strike Source
2013-09-08 16:24 - 2013-09-08 16:39 - 00000000 ____D C:\Documents and Settings\kory\Plocha\css
==================== One Month Modified Files and Folders =======
2013-10-08 09:02 - 2013-10-08 09:02 - 00000000 ____D C:\FRST
2013-10-08 09:02 - 2012-02-19 18:51 - 00000000 ___HD C:\Documents and Settings\kory\Local Settings\Data aplikací
2013-10-08 09:02 - 2012-02-19 18:51 - 00000000 ____D C:\Documents and Settings\kory\Plocha
2013-10-08 09:01 - 2013-10-08 09:01 - 00112128 _____ (forum.viry.cz) C:\Documents and Settings\kory\Plocha\FRSTLauncher.exe
2013-10-08 08:59 - 2013-10-08 08:59 - 01087213 _____ (Farbar) C:\Documents and Settings\kory\Plocha\FRST.exe
2013-10-08 08:56 - 2013-10-08 08:56 - 00001525 _____ C:\Documents and Settings\All Users\Plocha\mkvmerge GUI.lnk
2013-10-08 08:56 - 2013-10-08 08:56 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MKVToolNix
2013-10-08 08:56 - 2012-03-05 18:30 - 00000000 ____D C:\Program Files\MKVtoolnix
2013-10-08 08:56 - 2012-02-19 19:35 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-10-08 08:56 - 2012-02-19 19:35 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-10-08 08:44 - 2013-10-08 08:44 - 00000821 _____ C:\Documents and Settings\kory\Plocha\tsMuxerGUI.lnk
2013-10-08 08:43 - 2012-02-24 06:52 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\ÚPRAVA HD
2013-10-08 08:43 - 2012-02-19 18:51 - 00000000 __RHD C:\Documents and Settings\kory\Dokumenty
2013-10-08 08:35 - 2013-10-08 08:35 - 02806952 _____ C:\Documents and Settings\kory\Dokumenty\tsMuxeR_1.12.14b.zip
2013-10-08 08:10 - 2012-10-29 09:39 - 00002698 _____ C:\Documents and Settings\kory\Dokumenty\ytd.xml
2013-10-08 08:10 - 2012-02-23 11:19 - 00000000 ____D C:\Documents and Settings\kory\Data aplikací\CyberLink
2013-10-08 07:56 - 2013-10-08 07:54 - 112060463 _____ C:\Documents and Settings\kory\Dokumenty\Aplikace Nokia Pro Cam - Stereo video pro Lumia 820, Lumia 920 ....mp4
2013-10-08 07:52 - 2013-08-05 16:49 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\Lumia Amber
2013-10-08 06:48 - 2012-07-11 14:29 - 00000316 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2013-10-08 06:39 - 2013-10-08 06:39 - 00000000 ___HD C:\WINDOWS\PIF
2013-10-08 06:20 - 2012-02-24 17:34 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-10-08 06:20 - 2012-02-24 17:34 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-10-08 06:20 - 2012-02-19 18:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-10-08 06:20 - 2001-10-25 18:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-10-07 23:53 - 2013-10-07 23:53 - 00000841 _____ C:\WINDOWS\WindowsUpdate.log
2013-10-07 23:53 - 2012-05-22 11:10 - 00032186 _____ C:\WINDOWS\SchedLgU.Txt
2013-10-07 23:53 - 2012-02-19 18:51 - 00000178 ___SH C:\Documents and Settings\kory\ntuser.ini
2013-10-07 23:02 - 2013-10-04 07:43 - 00000000 ____D C:\rsit
2013-10-07 23:02 - 2013-10-04 07:43 - 00000000 ____D C:\Program Files\trend micro
2013-10-07 22:50 - 2012-02-19 18:51 - 00000000 ____D C:\Documents and Settings\kory
2013-10-07 22:45 - 2012-02-19 18:51 - 00000000 ___HD C:\Documents and Settings\kory\Data aplikací
2013-10-07 22:39 - 2012-02-19 19:35 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-10-07 22:12 - 2012-02-20 17:31 - 00000682 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2013-10-07 22:12 - 2012-02-20 17:31 - 00000000 ____D C:\Program Files\CCleaner
2013-10-07 22:11 - 2013-10-07 22:11 - 04369632 _____ (Piriform Ltd) C:\Documents and Settings\kory\Dokumenty\ccsetup406.exe
2013-10-07 22:06 - 2012-02-19 19:34 - 02003640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-07 22:02 - 2012-02-19 18:52 - 00087008 _____ C:\Documents and Settings\kory\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-10-07 20:59 - 2012-03-08 13:06 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-10-07 20:59 - 2012-03-08 13:04 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-10-07 20:59 - 2012-02-19 19:36 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-06 17:02 - 2012-03-08 13:07 - 00065536 _____ C:\WINDOWS\system32\config\OAlerts.evt
2013-10-04 13:34 - 2013-10-02 16:07 - 00000130 _____ C:\WINDOWS\pink
2013-10-04 07:43 - 2013-10-04 07:43 - 00781909 _____ C:\Documents and Settings\kory\Plocha\RSIT.exe
2013-10-03 09:02 - 2012-02-19 21:51 - 00000000 ____D C:\Documents and Settings\kory\Data aplikací\AIMP
2013-10-03 08:37 - 2013-10-03 08:37 - 01278372 _____ C:\Documents and Settings\kory\Plocha\Track 2013-08-17 10_32.gpx
2013-10-02 16:08 - 2013-10-02 16:07 - 00000000 ____D C:\Documents and Settings\kory\Plocha\rytir hra
2013-10-02 16:07 - 2013-10-02 16:07 - 05846158 _____ C:\Documents and Settings\kory\Plocha\wf.zip
2013-09-30 19:08 - 2013-09-30 17:54 - 682168321 _____ C:\Documents and Settings\kory\Dokumenty\Ucastnici-zajezdu.avi
2013-09-30 16:30 - 2012-03-12 07:19 - 00000000 ____D C:\Documents and Settings\kory\Data aplikací\uTorrent
2013-09-30 11:17 - 2013-04-10 13:18 - 1051591300 _____ C:\Documents and Settings\kory\Dokumenty\Opl.rar
2013-09-30 09:58 - 2013-09-30 09:58 - 00000000 ____D C:\Documents and Settings\kory\Local Settings\Data aplikací\Cyberlink SoftDMA
2013-09-30 09:58 - 2013-09-30 09:58 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\CyberLink
2013-09-30 09:58 - 2012-02-23 11:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\CyberLink
2013-09-30 09:56 - 2013-09-30 09:56 - 00001808 _____ C:\Documents and Settings\All Users\Plocha\CyberLink PowerDVD 13.lnk
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\MediaServer
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\kory\CyberLink
2013-09-30 09:56 - 2013-09-30 09:56 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CyberLink PowerDVD 13
2013-09-30 09:56 - 2012-02-23 11:47 - 00000000 ____D C:\Documents and Settings\kory\Local Settings\Data aplikací\Cyberlink
2013-09-30 09:56 - 2012-02-23 11:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\PDVD
2013-09-30 09:56 - 2012-02-23 11:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\install_clap
2013-09-30 09:56 - 2012-02-19 18:50 - 00000000 ___HD C:\Documents and Settings\NetworkService\Local Settings\Data aplikací
2013-09-30 09:54 - 2013-09-30 09:54 - 00000000 ____D C:\Program Files\CyberLink
2013-09-30 09:54 - 2012-02-19 19:17 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-09-30 09:31 - 2013-09-28 22:45 - 09743083 _____ (Moritz Bunkus) C:\Documents and Settings\kory\Dokumenty\mkvtoolnix-unicode-6.4.1-setup.exe
2013-09-28 07:41 - 2013-09-28 07:41 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\045662
2013-09-24 06:04 - 2013-09-24 06:04 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\Nabijecka_ze_zdroje_PC
2013-09-24 05:57 - 2013-09-24 05:51 - 118697383 _____ C:\Documents and Settings\kory\Dokumenty\Kniha-Inteligentní-nabíječky.rar
2013-09-19 18:48 - 2012-02-19 18:47 - 00002504 _____ C:\WINDOWS\system32\CONFIG.NT
2013-09-14 17:07 - 2012-03-08 17:25 - 00000349 _____ C:\WINDOWS\system32\lsprst7.tgz
2013-09-14 17:07 - 2012-03-08 17:25 - 00000335 _____ C:\WINDOWS\system32\lsprst7.dll
2013-09-14 17:07 - 2012-03-08 17:25 - 00000087 _____ C:\WINDOWS\system32\ssprs.tgz
2013-09-14 17:07 - 2012-03-08 17:25 - 00000073 _____ C:\WINDOWS\system32\ssprs.dll
2013-09-11 08:49 - 2012-02-19 22:00 - 00000000 ____D C:\Program Files\PhotoFiltre Studio X
2013-09-11 07:06 - 2013-09-11 07:06 - 00042348 _____ C:\Documents and Settings\kory\Dokumenty\kyo126.xps
2013-09-11 06:48 - 2013-09-11 06:48 - 11611134 _____ C:\Documents and Settings\kory\Dokumenty\onkyo.bmp
2013-09-11 05:56 - 2013-04-29 09:11 - 00002485 _____ C:\Documents and Settings\All Users\Plocha\ABBYY FineReader 11.lnk
2013-09-10 00:26 - 2013-09-10 00:25 - 00000000 ____D C:\Documents and Settings\kory\Dokumenty\FLASH
2013-09-08 16:39 - 2013-09-08 16:39 - 00001460 _____ C:\Documents and Settings\All Users\Plocha\Counter-Strike Source.lnk
2013-09-08 16:39 - 2013-09-08 16:39 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Counter-Strike Source
2013-09-08 16:39 - 2013-09-08 16:24 - 00000000 ____D C:\Documents and Settings\kory\Plocha\css
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 10:52] - [2008-04-14 10:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2008-04-14 10:52] - [2008-04-14 10:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2008-04-14 10:52] - [2008-04-14 10:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2008-04-14 10:52] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2008-04-14 10:52] - [2008-04-14 10:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2008-04-14 10:52] - [2008-04-14 10:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 09:42] - [2008-04-14 09:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:232.88 GB) (Free:30.11 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (Místní disk) (Fixed) (Total:232.88 GB) (Free:1.31 GB) NTFS
Drive n: (Místní disk) (Fixed) (Total:465.76 GB) (Free:23.06 GB) NTFS
Available physical RAM: 2402.06 MB
Total physical RAM: 3199.17 MB
Percentage of memory in use: 24%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 233 GB) (Disk ID: 0FD80FD7)
Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: ABFF3AF6)
Partition 1: (Not Active) - (Size=466 GB) - (Type=42)
Disk: 2 (Size: 233 GB) (Disk ID: 87F587F5)
Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:0888F409
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:3440EB47
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:373E1720
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:66633281
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus (Disabled) {7591DB91-41F0-48A3-B128-1A293FD8233D}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 28_09_2013 (06)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\kory\Plocha" je 1455 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge
"C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager
"C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bonus.SSR.FR11
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
C:\Program Files\PowerISO\PWRISOVM.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter
"C:\Program Files\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL
Reim ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel
Reim ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
Reim ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard
Reim ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender
Reim ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^HP Digital Imaging Monitor.lnk
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^Ralink Wireless Utility.lnk
C:\PROGRA~1\TP-LINK\TP-LIN~1\TWCU.exe -nogui [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^TotalMedia Server.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^TP-LINK Wireless Configuration Utility.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kory^Nabdka Start^Programy^Po sputn^Vezy obrazovky a sputn aplikace OneNote 2010.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
Microsoft SharePoint Workspace Audit Service REG_DWORD 0x3
osppsvc REG_DWORD 0x3
ose REG_DWORD 0x3
JavaQuickStarterService REG_DWORD 0x2
FlowFinder3MonstersOFX32 REG_DWORD 0x2
Transbase REG_DWORD 0x3
ACS REG_DWORD 0x3
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13.exe:*:Enabled:CyberLink PowerDVD13"
"C:\\Program Files\\CyberLink\\PowerDVD13\\Kernel\\DMS\\CLMSServerPDVD13.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\Kernel\\DMS\\CLMSServerPDVD13.exe:*:Enabled:CyberLink PowerDVD 13 Media Server Service"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13Agent.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13Agent.exe:*:Enabled:CyberLink PowerDVD13 Agent"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13ML.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13ML.exe:*:Enabled:CyberLink PowerDVD13 Moovie Live"
"C:\\Program Files\\CyberLink\\PowerDVD13\\Movie\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\Movie\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD13 Movie Module"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Documents and Settings\\kory\\Local Settings\\Temp\\7zS7340\\HPDiagnosticCoreUI.exe"="C:\\Documents and Settings\\kory\\Local Settings\\Temp\\7zS7340\\HPDiagnosticCoreUI.exe:*:Enabled:HPSAPS"
"C:\\Documents and Settings\\kory\\Local Settings\\Temp\\7zS1389\\HPDiagnosticCoreUI.exe"="C:\\Documents and Settings\\kory\\Local Settings\\Temp\\7zS1389\\HPDiagnosticCoreUI.exe:*:Enabled:HPSAPS"
"C:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"="C:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\\Program Files\\theHunter\\launcher\\launcher.exe"="C:\\Program Files\\theHunter\\launcher\\launcher.exe:*:Enabled:theHunter Launcher"
"C:\\Program Files\\theHunter\\game\\theHunter.exe"="C:\\Program Files\\theHunter\\game\\theHunter.exe:*:Enabled:theHunter"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13.exe:*:Enabled:CyberLink PowerDVD13"
"C:\\Program Files\\CyberLink\\PowerDVD13\\Kernel\\DMS\\CLMSServerPDVD13.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\Kernel\\DMS\\CLMSServerPDVD13.exe:*:Enabled:CyberLink PowerDVD 13 Media Server Service"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13Agent.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13Agent.exe:*:Enabled:CyberLink PowerDVD13 Agent"
"C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13ML.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\PowerDVD13ML.exe:*:Enabled:CyberLink PowerDVD13 Moovie Live"
"C:\\Program Files\\CyberLink\\PowerDVD13\\Movie\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD13\\Movie\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD13 Movie Module"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================