Prosím o preventivku
Napsal: 06 lis 2013 20:08
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by Klingy1 (administrator) on KLINGY1-HTNMKO8 on 06-11-2013 20:04:00
Running from C:\Documents and Settings\Klingy1\Plocha\Download data from internet
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkManagerDMS.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Ask) C:\Program Files\Ask.com\Updater\Updater.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
(Nokia.) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(The Author of QIP) C:\Program Files\QIP\qip.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
() C:\Program Files\USB TV\EM28XX\BDARemote.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkDMS.exe
(The Author of QIP) C:\Program Files\QIP\qip.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [790528 2003-05-29] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe [585728 2003-05-30] (Analog Devices, Inc.)
HKLM\...\Run: [ATIModeChange] - C:\WINDOWS\system32\Ati2mdxx.exe [26112 2010-02-11] (ATI Technologies, Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1719944 2013-04-01] (Ask)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [PCSuiteTrayApplication] - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [227328 2007-03-23] (Nokia)
HKLM\...\Run: [Samsung Link] - F:\TV samsung\Samsung Link\Samsung Link Tray Agent.exe [567368 2013-10-30] (Copyright 2013 SAMSUNG)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [QIP2005] - C:\Program Files\QIP\qip.exe [3259392 2008-12-09] (The Author of QIP)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe [ 2008-06-24] (Nero AG)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk
ShortcutTarget: BDARemote.lnk -> C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?l=dis&o=15187
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60194
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
SearchScopes: HKCU - DefaultScope {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?clien ... B670797BFD
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?clien ... B670797BFD
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM - KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKCU - KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Klingy1\Data aplikací\Mozilla\Firefox\Profiles\3zhpg6kj.default
FF SelectedSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF DefaultSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: samsung.com/SamsungLinkPCPlugin - F:\TV samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll (Samsung)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\gp.xpi
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\staged-xpis
FF HKLM\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files\SiteRanker\firefox\
FF Extension: SiteRanker - C:\Program Files\SiteRanker\firefox\
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (Ask) - http://websearch.ask.com/redirect?clien ... earchTerms}
CHR DefaultSuggestURL: (Ask) - http://ss.websearch.ask.com/query?qsrc= ... earchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.11_0
CHR Extension: (Google Wallet) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
========================== Services (Whitelisted) =================
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkManagerDMS.exe [401800 2013-10-11] (Samsung)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2010-02-10] ()
S2 NOD32FiXTemDono; C:\WINDOWS\nod32fixtemdono.reg [568 2008-03-03] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [274432 2008-10-02] ()
S2 Samsung Link Service; F:\TV samsung\Samsung Link\Samsung Link.exe [574536 2013-10-30] (Copyright 2013 SAMSUNG)
R2 SoundMAX Agent Service (default); C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.)
S3 SystemExplorerHelpService; C:\Program Files\System Explorer\service\SystemExplorerService.exe [567256 2012-11-25] (Mister Group)
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
==================== Drivers (Whitelisted) ====================
S3 EL90X; C:\Windows\System32\DRIVERS\el90xnd5.sys [153631 2001-10-24] (3Com Corporation)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [25280 2009-01-01] (LogMeIn, Inc.)
S3 MidiSyn; C:\Windows\System32\drivers\MidiSyn.sys [235100 2002-09-20] (Analog Devices Inc)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-01-18] ()
R3 yukonwxp; C:\Windows\System32\DRIVERS\yukonwxp.sys [174336 2003-10-23] (Marvell Semiconductor Inc.)
U3 a4iokphw; C:\Windows\System32\Drivers\a4iokphw.sys [0 ] (Microsoft Corporation)
S3 GarenaPEngine; \??\C:\DOCUME~1\Klingy1\LOCALS~1\Temp\JCPF.tmp [x]
S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [x]
S4 IntelIde; No ImagePath
S3 k750bus; system32\DRIVERS\k750bus.sys [x]
S3 k750mdfl; system32\DRIVERS\k750mdfl.sys [x]
S3 k750mdm; system32\DRIVERS\k750mdm.sys [x]
S3 k750mgmt; system32\DRIVERS\k750mgmt.sys [x]
S3 k750obex; system32\DRIVERS\k750obex.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-06 20:03 - 2013-11-06 20:03 - 00029696 _____ C:\Documents and Settings\Klingy1\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-06 20:03 - 2013-11-06 20:03 - 00000000 ____D C:\FRST
2013-11-04 21:19 - 2013-11-06 19:36 - 00001128 _____ C:\WINDOWS\setupapi.log
2013-11-04 19:08 - 2013-11-04 19:08 - 00000000 ____D C:\Upload
2013-11-04 19:07 - 2013-11-04 19:07 - 00000000 ____D C:\Program Files\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\Klingy1\.swt
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SAMSUNG
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-10 20:44 - 2013-10-10 20:44 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
2013-10-10 19:24 - 2013-07-03 03:12 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidparse.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00123008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbvideo.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00060160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbaudio.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00046848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\irbus.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00144128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbport.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00032384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbd.sys
2013-10-10 19:22 - 2009-03-18 12:02 - 00030336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbehci.sys
==================== One Month Modified Files and Folders =======
2013-11-06 20:03 - 2013-11-06 20:03 - 00029696 _____ C:\Documents and Settings\Klingy1\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-06 20:03 - 2013-11-06 20:03 - 00000000 ____D C:\FRST
2013-11-06 20:03 - 2012-04-17 20:11 - 00000000 ____D C:\Documents and Settings\Klingy1\Plocha\Download data from internet
2013-11-06 20:03 - 2008-12-26 19:57 - 00000000 ___HD C:\Documents and Settings\Klingy1\Local Settings\Data aplikací
2013-11-06 20:02 - 2013-04-20 10:52 - 00000238 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-11-06 19:58 - 2002-01-02 06:33 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-06 19:38 - 2012-03-13 17:29 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-11-06 19:38 - 2008-12-27 00:26 - 01887346 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-06 19:37 - 2012-03-13 17:29 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-11-06 19:37 - 2010-03-21 14:41 - 00000260 _____ C:\WINDOWS\Tasks\WGASetup.job
2013-11-06 19:37 - 2008-12-26 19:54 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-06 19:37 - 2002-01-02 06:33 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-06 19:36 - 2013-11-04 21:19 - 00001128 _____ C:\WINDOWS\setupapi.log
2013-11-06 19:36 - 2012-12-08 13:34 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-11-06 19:36 - 2008-12-26 19:57 - 00000178 ___SH C:\Documents and Settings\Klingy1\ntuser.ini
2013-11-06 19:36 - 2008-12-26 19:56 - 00032620 _____ C:\WINDOWS\SchedLgU.Txt
2013-11-06 19:34 - 2008-12-26 20:39 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-11-06 17:39 - 2010-10-16 19:59 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-11-06 17:39 - 2001-10-25 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-11-04 19:08 - 2013-11-04 19:08 - 00000000 ____D C:\Upload
2013-11-04 19:08 - 2010-04-11 11:36 - 00000000 ____D C:\WINDOWS\Minidump
2013-11-04 19:08 - 2008-12-26 19:57 - 00000000 ____D C:\Documents and Settings\Klingy1
2013-11-04 19:07 - 2013-11-04 19:07 - 00000000 ____D C:\Program Files\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\Klingy1\.swt
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SAMSUNG
2013-11-04 19:00 - 2008-12-26 20:39 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-11-04 19:00 - 2008-12-26 20:38 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-11-04 19:00 - 2008-12-26 19:57 - 00000000 ___RD C:\Documents and Settings\Klingy1\Nabídka Start
2013-10-30 20:02 - 2009-04-02 21:44 - 00000069 _____ C:\WINDOWS\NeroDigital.ini
2013-10-30 20:01 - 2008-12-26 19:57 - 00000000 ___HD C:\Documents and Settings\Klingy1\Okolní síť
2013-10-27 14:47 - 2008-12-26 20:39 - 01030600 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-20 22:09 - 2002-01-02 06:34 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-10-14 20:03 - 2011-02-13 14:27 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-10-12 19:10 - 2008-12-26 20:38 - 00284520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-10 20:51 - 2013-08-15 21:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-10-10 20:47 - 2010-09-07 20:03 - 78106760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-10 20:44 - 2013-10-10 20:44 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
Some content of TEMP:
====================
C:\Documents and Settings\Klingy1\Local Settings\Temp\APNStub.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\firefoxjre_exe-1.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\firefoxjre_exe.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\KMP_3.7.0.113.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2001-10-25 15:00] - [2008-04-14 08:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2001-10-25 15:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2002-09-20 19:04] - [2008-04-14 08:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2001-10-25 15:00] - [2008-04-14 07:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
Ran by Klingy1 (administrator) on KLINGY1-HTNMKO8 on 06-11-2013 20:04:00
Running from C:\Documents and Settings\Klingy1\Plocha\Download data from internet
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkManagerDMS.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Ask) C:\Program Files\Ask.com\Updater\Updater.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
(Nokia.) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(The Author of QIP) C:\Program Files\QIP\qip.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
() C:\Program Files\USB TV\EM28XX\BDARemote.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkDMS.exe
(The Author of QIP) C:\Program Files\QIP\qip.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [790528 2003-05-29] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe [585728 2003-05-30] (Analog Devices, Inc.)
HKLM\...\Run: [ATIModeChange] - C:\WINDOWS\system32\Ati2mdxx.exe [26112 2010-02-11] (ATI Technologies, Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1719944 2013-04-01] (Ask)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [PCSuiteTrayApplication] - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [227328 2007-03-23] (Nokia)
HKLM\...\Run: [Samsung Link] - F:\TV samsung\Samsung Link\Samsung Link Tray Agent.exe [567368 2013-10-30] (Copyright 2013 SAMSUNG)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [QIP2005] - C:\Program Files\QIP\qip.exe [3259392 2008-12-09] (The Author of QIP)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe [ 2008-06-24] (Nero AG)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk
ShortcutTarget: BDARemote.lnk -> C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?l=dis&o=15187
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60194
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
SearchScopes: HKCU - DefaultScope {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?clien ... B670797BFD
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?clien ... B670797BFD
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM - KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKCU - KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Klingy1\Data aplikací\Mozilla\Firefox\Profiles\3zhpg6kj.default
FF SelectedSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF DefaultSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: samsung.com/SamsungLinkPCPlugin - F:\TV samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll (Samsung)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\gp.xpi
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\staged-xpis
FF HKLM\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files\SiteRanker\firefox\
FF Extension: SiteRanker - C:\Program Files\SiteRanker\firefox\
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (Ask) - http://websearch.ask.com/redirect?clien ... earchTerms}
CHR DefaultSuggestURL: (Ask) - http://ss.websearch.ask.com/query?qsrc= ... earchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.11_0
CHR Extension: (Google Wallet) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\DOCUME~1\Klingy1\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
========================== Services (Whitelisted) =================
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.21\AllShareFrameworkManagerDMS.exe [401800 2013-10-11] (Samsung)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2010-02-10] ()
S2 NOD32FiXTemDono; C:\WINDOWS\nod32fixtemdono.reg [568 2008-03-03] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [274432 2008-10-02] ()
S2 Samsung Link Service; F:\TV samsung\Samsung Link\Samsung Link.exe [574536 2013-10-30] (Copyright 2013 SAMSUNG)
R2 SoundMAX Agent Service (default); C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.)
S3 SystemExplorerHelpService; C:\Program Files\System Explorer\service\SystemExplorerService.exe [567256 2012-11-25] (Mister Group)
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
==================== Drivers (Whitelisted) ====================
S3 EL90X; C:\Windows\System32\DRIVERS\el90xnd5.sys [153631 2001-10-24] (3Com Corporation)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [25280 2009-01-01] (LogMeIn, Inc.)
S3 MidiSyn; C:\Windows\System32\drivers\MidiSyn.sys [235100 2002-09-20] (Analog Devices Inc)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-01-18] ()
R3 yukonwxp; C:\Windows\System32\DRIVERS\yukonwxp.sys [174336 2003-10-23] (Marvell Semiconductor Inc.)
U3 a4iokphw; C:\Windows\System32\Drivers\a4iokphw.sys [0 ] (Microsoft Corporation)
S3 GarenaPEngine; \??\C:\DOCUME~1\Klingy1\LOCALS~1\Temp\JCPF.tmp [x]
S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [x]
S4 IntelIde; No ImagePath
S3 k750bus; system32\DRIVERS\k750bus.sys [x]
S3 k750mdfl; system32\DRIVERS\k750mdfl.sys [x]
S3 k750mdm; system32\DRIVERS\k750mdm.sys [x]
S3 k750mgmt; system32\DRIVERS\k750mgmt.sys [x]
S3 k750obex; system32\DRIVERS\k750obex.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-06 20:03 - 2013-11-06 20:03 - 00029696 _____ C:\Documents and Settings\Klingy1\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-06 20:03 - 2013-11-06 20:03 - 00000000 ____D C:\FRST
2013-11-04 21:19 - 2013-11-06 19:36 - 00001128 _____ C:\WINDOWS\setupapi.log
2013-11-04 19:08 - 2013-11-04 19:08 - 00000000 ____D C:\Upload
2013-11-04 19:07 - 2013-11-04 19:07 - 00000000 ____D C:\Program Files\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\Klingy1\.swt
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SAMSUNG
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-10 20:44 - 2013-10-10 20:44 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
2013-10-10 19:24 - 2013-07-03 03:12 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidparse.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00123008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbvideo.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00060160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbaudio.sys
2013-10-10 19:23 - 2013-07-17 01:58 - 00046848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\irbus.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00144128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbport.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00032384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
2013-10-10 19:22 - 2013-08-09 01:55 - 00005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbd.sys
2013-10-10 19:22 - 2009-03-18 12:02 - 00030336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbehci.sys
==================== One Month Modified Files and Folders =======
2013-11-06 20:03 - 2013-11-06 20:03 - 00029696 _____ C:\Documents and Settings\Klingy1\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-06 20:03 - 2013-11-06 20:03 - 00000000 ____D C:\FRST
2013-11-06 20:03 - 2012-04-17 20:11 - 00000000 ____D C:\Documents and Settings\Klingy1\Plocha\Download data from internet
2013-11-06 20:03 - 2008-12-26 19:57 - 00000000 ___HD C:\Documents and Settings\Klingy1\Local Settings\Data aplikací
2013-11-06 20:02 - 2013-04-20 10:52 - 00000238 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-11-06 19:58 - 2002-01-02 06:33 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-06 19:38 - 2012-03-13 17:29 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-11-06 19:38 - 2008-12-27 00:26 - 01887346 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-06 19:37 - 2012-03-13 17:29 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-11-06 19:37 - 2010-03-21 14:41 - 00000260 _____ C:\WINDOWS\Tasks\WGASetup.job
2013-11-06 19:37 - 2008-12-26 19:54 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-06 19:37 - 2002-01-02 06:33 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-06 19:36 - 2013-11-04 21:19 - 00001128 _____ C:\WINDOWS\setupapi.log
2013-11-06 19:36 - 2012-12-08 13:34 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-11-06 19:36 - 2008-12-26 19:57 - 00000178 ___SH C:\Documents and Settings\Klingy1\ntuser.ini
2013-11-06 19:36 - 2008-12-26 19:56 - 00032620 _____ C:\WINDOWS\SchedLgU.Txt
2013-11-06 19:34 - 2008-12-26 20:39 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-11-06 17:39 - 2010-10-16 19:59 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-11-06 17:39 - 2001-10-25 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-11-04 19:08 - 2013-11-04 19:08 - 00000000 ____D C:\Upload
2013-11-04 19:08 - 2010-04-11 11:36 - 00000000 ____D C:\WINDOWS\Minidump
2013-11-04 19:08 - 2008-12-26 19:57 - 00000000 ____D C:\Documents and Settings\Klingy1
2013-11-04 19:07 - 2013-11-04 19:07 - 00000000 ____D C:\Program Files\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\Klingy1\.swt
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Samsung
2013-11-04 19:00 - 2013-11-04 19:00 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SAMSUNG
2013-11-04 19:00 - 2008-12-26 20:39 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-11-04 19:00 - 2008-12-26 20:38 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-11-04 19:00 - 2008-12-26 19:57 - 00000000 ___RD C:\Documents and Settings\Klingy1\Nabídka Start
2013-10-30 20:02 - 2009-04-02 21:44 - 00000069 _____ C:\WINDOWS\NeroDigital.ini
2013-10-30 20:01 - 2008-12-26 19:57 - 00000000 ___HD C:\Documents and Settings\Klingy1\Okolní síť
2013-10-27 14:47 - 2008-12-26 20:39 - 01030600 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-20 22:09 - 2002-01-02 06:34 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-10-14 20:03 - 2011-02-13 14:27 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-10-12 19:10 - 2008-12-26 20:38 - 00284520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-10 20:51 - 2013-10-10 20:51 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-10 20:51 - 2013-08-15 21:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-10-10 20:47 - 2010-09-07 20:03 - 78106760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-10 20:45 - 2013-10-10 20:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-10 20:44 - 2013-10-10 20:44 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
Some content of TEMP:
====================
C:\Documents and Settings\Klingy1\Local Settings\Temp\APNStub.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\firefoxjre_exe-1.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\firefoxjre_exe.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\KMP_3.7.0.113.exe
C:\Documents and Settings\Klingy1\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2001-10-25 15:00] - [2008-04-14 08:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2001-10-25 15:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2002-09-20 19:04] - [2008-04-14 08:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2002-09-20 19:05] - [2008-04-14 08:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2001-10-25 15:00] - [2008-04-14 07:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================