Tak se Nouzový režim podařil, tady je FRST log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01
Ran by Administrator (administrator) on MILA_HP on 11-11-2013 19:52:51
Running from D:\
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Safe Mode (minimal)
==================== Processes (Whitelisted) ===================
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Microsoft Corporation) C:\windows\system32\cmd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QLBController] - C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DTRun] - C:\Program Files\Arcsoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [518656 2009-11-18] (ArcSoft Inc.)
HKLM\...\Run: [NortonOnlineBackupReminder] - C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe [600936 2009-06-29] (Symantec Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [495708 2013-07-03] (IDT, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2013-07-03] (Synaptics Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2345296 2013-10-01] (LogMeIn Inc.)
HKLM\...\RunOnce: [*Restore] - C:\windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] C:\windows\system32\userinit.exe,C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\DeviceNP: C:\Windows\system32\DeviceNP.dll (Hewlett-Packard Limited)
HKCU\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-10-25] (Hewlett-Packard)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Guest\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Guest\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Hynek\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Hynek\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [ 2009-07-14] (Microsoft Corporation)
HKU\Hynek\...\Policies\system: [LogonHoursAction] 2
HKU\Hynek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Hynek.Mila_HP\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Hynek.Mila_HP\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Hynek.Mila_HP\...\Run: [Clownfish] - [x]
HKU\Hynek.Mila_HP\...\Run: [Google Update] - C:\Users\Hynek.Mila_HP\AppData\Local\Google\Update\GoogleUpdate.exe [ 2012-07-23] (Google Inc.)
HKU\Hynek.Mila_HP\...\Run: [WebCake Desktop] - C:\Users\Hynek.Mila_HP\AppData\Roaming\Movdap\WebCakeDesktop.exe [ 2013-08-29] (WebCake LLC)
HKU\Hynek.Mila_HP\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Hynek.Mila_HP\AppData\Roaming\Seznam.cz\szninstall.exe [ 2013-05-16] ()
HKU\Hynek.Mila_HP\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Hynek.Mila_HP\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [ 2013-04-12] ()
HKU\Hynek.Mila_HP\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-10-09] (Valve Corporation)
HKU\Kačenka\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Kačenka\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Kačenka\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Kačenka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [ 2013-04-12] ()
HKU\Kačenka\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Kačenka\AppData\Roaming\Seznam.cz\szninstall.exe [ 2013-05-16] ()
HKU\Mila\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Mila\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Mila\...\Policies\system: [LogonHoursAction] 2
HKU\Mila\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Mila.Mila_HP\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Mila.Mila_HP\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-04-19] (Skype Technologies S.A.)
HKU\Mila.Mila_HP\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [ 2013-03-22] (TomTom)
HKU\Mila.Mila_HP\...\Run: [Google Update] - C:\Users\Mila.Mila_HP\AppData\Local\Google\Update\GoogleUpdate.exe [ 2012-07-23] (Google Inc.)
HKU\Mila.Mila_HP\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Mila.Mila_HP\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [ 2013-04-12] ()
HKU\Mila.Mila_HP\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Mila.Mila_HP\AppData\Roaming\Seznam.cz\szninstall.exe [ 2013-05-16] ()
HKU\user\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\user\...\Run: [Skype] - C:\Program Files\Skype\\Phone\Skype.exe [ 2013-04-19] (Skype Technologies S.A.)
HKU\user\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Veverka\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Veverka\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Veverka\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Veverka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [ 2013-04-12] ()
HKU\Veverka\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Veverka\AppData\Roaming\Seznam.cz\szninstall.exe [ 2013-05-16] ()
HKU\Štěpánek\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-10-25] (Hewlett-Packard)
HKU\Štěpánek\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
HKU\Štěpánek\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Štěpánek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [ 2013-04-12] ()
HKU\Štěpánek\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Štěpánek\AppData\Roaming\Seznam.cz\szninstall.exe [ 2013-05-16] ()
AppInit_DLLs: c:\progra~1\savesh~1\sprote~1.dll c:\progra~1\websea~1\sprote~1.dll [ 2013-01-24] ()
Lsa: [Notification Packages] DPPassFilter scecli
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://websearch.searchesplace.info/?pi ... Z&unqvl=30
SearchScopes: HKLM - DefaultScope {A1159ED1-4374-4E71-A66C-74943BD7D314} URL =
http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {A1159ED1-4374-4E71-A66C-74943BD7D314} URL =
http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL =
http://websearch.searchesplace.info/?l= ... Z&unqvl=30
SearchScopes: HKCU - DefaultScope {A1159ED1-4374-4E71-A66C-74943BD7D314} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO: SearchNewTab - {71FAFC9F-906C-2BFB-1626-0C839BE9717E} - C:\ProgramData\SearchNewTab\xJV.dll ()
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{1C8A17AC-18ED-49F9-832E-C3B6A0327739}: [NameServer]81.92.155.4,81.92.158.236
Chrome:
=======
CHR Extension: (Docs) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Web Cake) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_0
CHR Extension: () - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1482_0
CHR Extension: (Gmail) - C:\Users\ADMINI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files\Movdap\WebCakeLayers.crx
========================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-09-28] (ArcSoft Inc.)
S2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
S3 Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [3528968 2010-04-15] (Motorola, Inc.)
S3 Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [824584 2010-04-15] (Motorola, Inc.)
S2 Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [512776 2010-04-22] (Motorola, Inc.)
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [300880 2010-07-16] (DigitalPersona, Inc.)
S2 FLCDLOCK; c:\Windows\system32\flcdlock.exe [362040 2009-11-17] (Hewlett-Packard Ltd)
S2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1612112 2013-10-01] (LogMeIn Inc.)
S2 HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [102968 2009-12-16] (Hewlett-Packard)
S2 HP ProtectTools Service; C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P)
S2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
S2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe [90112 2010-05-10] (Hewlett-Packard Company)
S2 HpFkCryptService; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-01] (McAfee, Inc.)
S2 HPFSService; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [297984 2009-12-12] (Hewlett-Packard)
S2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
S2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2013-08-26] (LogMeIn, Inc.)
S2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-10-23] (PDF Complete Inc)
S2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [254034 2013-07-03] (IDT, Inc.)
S2 uArcCapture; C:\windows\system32\uArcCapture.exe [506472 2009-12-04] (ArcSoft, Inc.)
S2 vcsFPService; C:\windows\system32\vcsFPService.exe [1639728 2009-12-14] (Validity Sensors, Inc.)
S2 WebCakeUpdater; C:\Program Files\Movdap\WBDesktop.Updater.1.0.0.16.exe [51992 2013-08-29] (cake bake)
==================== Drivers (Whitelisted) ====================
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [29824 2009-12-04] (ArcSoft, Inc.)
S3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [31616 2010-04-23] (Motorola, Inc.)
S3 BTMCOM; C:\Windows\System32\Drivers\btmcom.sys [41344 2010-04-09] (Motorola, Inc.)
S3 BTMMODEM; C:\Windows\System32\DRIVERS\btmcom.sys [41344 2010-04-09] (Motorola, Inc.)
S3 BTMUSB; C:\Windows\System32\Drivers\btmusb.sys [375296 2010-04-15] (Motorola, Inc.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv.sys [32312 2009-10-21] (Hewlett-Packard Development Company L.P.)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 MfeAVFK; C:\Windows\System32\drivers\MfeAVFK.sys [79816 2009-05-16] (McAfee, Inc.)
S3 MfeBOPK; C:\Windows\System32\drivers\MfeBOPK.sys [35272 2009-05-16] (McAfee, Inc.)
S1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [214024 2009-05-16] (McAfee, Inc.)
S3 MfeRKDK; C:\Windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
S1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [40088 2010-02-01] (McAfee, Inc.)
S3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [73344 2009-12-22] (Realtek Semiconductor Corp.)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [110520 2010-02-01] (McAfee, Inc.)
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [51800 2010-02-01] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [13256 2010-02-01] (McAfee, Inc.)
S1 vmm; C:\windows\system32\Drivers\vmm.sys [232816 2007-02-18] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MILA~1.MIL\AppData\Local\Temp\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\MILA~1.MIL\AppData\Local\Temp\CFcatchme.sys [x]
S1 lzmqruib; \??\C:\windows\system32\drivers\lzmqruib.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-11 19:52 - 2013-11-11 19:52 - 00000000 ____D C:\FRST
2013-11-11 18:34 - 2013-11-11 18:34 - 00000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn
2013-11-07 11:23 - 2013-11-07 11:23 - 00000000 ____D C:\Users\Veverka\AppData\Local\Apple
2013-11-02 19:33 - 2013-11-02 19:33 - 00000000 ____D C:\Users\Kačenka\AppData\Local\LogMeIn
2013-11-02 19:26 - 2013-11-02 19:26 - 00000000 ____D C:\HP_RECOVERY_mountHPSF
2013-11-02 19:24 - 2013-11-02 19:24 - 00000000 ____D C:\Users\Veverka\AppData\Local\LogMeIn
2013-11-02 19:16 - 2013-11-11 18:47 - 95025368 ____T C:\ProgramData\orwla9.bxx
2013-11-02 19:16 - 2013-11-11 17:46 - 00000000 _____ C:\ProgramData\orwla9.fvv
2013-11-02 19:16 - 2013-11-02 19:16 - 00151552 _____ (Корпорация Майкрософт) C:\ProgramData\9alwro.dss
2013-11-01 09:23 - 2013-11-01 09:23 - 00000000 ____D C:\Program Files\Common Files\Portrait Displays
2013-11-01 09:22 - 2013-11-01 09:22 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Roaming\Hewlett-Packard Company
2013-10-27 13:05 - 2013-10-27 13:05 - 00001355 _____ C:\Users\Hynek.Mila_HP\Desktop\ROBLOX Player.lnk
2013-10-26 19:44 - 2013-10-27 13:05 - 00001174 _____ C:\Users\Hynek.Mila_HP\Desktop\ROBLOX Studio 2013.lnk
2013-10-26 19:44 - 2013-10-27 13:05 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2013-10-26 19:43 - 2013-10-27 13:37 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\Roblox
2013-10-26 19:42 - 2013-10-26 19:43 - 00542576 _____ (ROBLOX Corporation) C:\Users\Hynek.Mila_HP\Desktop\RobloxPlayerLauncher.exe
2013-10-26 14:17 - 2013-10-27 14:16 - 00000000 ____D C:\Program Files\Steam
2013-10-26 14:17 - 2013-10-26 16:06 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-10-26 14:14 - 2013-10-26 14:15 - 01669632 _____ C:\Users\Hynek.Mila_HP\Desktop\SteamInstall.msi
2013-10-26 13:41 - 2013-10-26 13:41 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\Clownfish
2013-10-26 13:40 - 2013-10-26 13:40 - 00537827 _____ C:\Users\Hynek.Mila_HP\Desktop\clownfish_portable_340.zip
2013-10-26 13:24 - 2013-10-26 13:31 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\Dubstep
2013-10-26 13:20 - 2013-10-26 13:22 - 36794880 _____ C:\Users\Hynek.Mila_HP\Desktop\Reapers EP - Winside.rar
2013-10-26 13:05 - 2013-10-26 13:05 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\BetterWorld
2013-10-26 13:04 - 2013-10-26 13:04 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft Eden mods helper
2013-10-26 11:34 - 2013-10-26 11:34 - 00675988 _____ C:\Users\Hynek.Mila_HP\Desktop\MinecraftNew.exe
2013-10-26 11:33 - 2013-10-26 11:42 - 77236500 _____ C:\Users\Hynek.Mila_HP\Desktop\Eden-BP-1.5.2.exe
2013-10-26 11:14 - 2013-10-26 11:14 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\LogMeIn
2013-10-23 20:16 - 2013-10-23 20:16 - 00000925 _____ C:\Users\Mila.Mila_HP\Desktop\Microsoft Office 2007 – zástupce.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000243 _____ C:\Users\Mila.Mila_HP\Desktop\Email (2).url
2013-10-23 19:26 - 2013-10-27 20:26 - 00000316 _____ C:\windows\Tasks\HPCeeScheduleForMila.job
2013-10-20 23:16 - 2013-10-20 23:16 - 00000000 ___HD C:\windows\AxInstSV
2013-10-18 13:24 - 2013-10-18 13:24 - 00371568 _____ C:\windows\Minidump\101813-29577-01.dmp
==================== One Month Modified Files and Folders =======
2013-11-11 19:52 - 2013-11-11 19:52 - 00000000 ____D C:\FRST
2013-11-11 19:52 - 2011-08-17 03:46 - 00000000 ____D C:\Users\Mila.Mila_HP
2013-11-11 19:52 - 2010-06-06 05:29 - 01577410 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-11 19:48 - 2010-06-06 05:41 - 00000000 ____D C:\ProgramData\HPQLOG
2013-11-11 19:47 - 2012-07-23 09:57 - 00000934 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-11 19:47 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-11 19:47 - 2009-07-14 05:39 - 00076280 _____ C:\windows\setupact.log
2013-11-11 19:46 - 2013-09-28 11:59 - 00000000 ____D C:\Users\Veverka\AppData\Roaming\Seznam.cz
2013-11-11 19:46 - 2013-08-11 20:33 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Roaming\Seznam.cz
2013-11-11 19:46 - 2013-08-04 12:11 - 00000000 ____D C:\Users\Štěpánek
2013-11-11 19:46 - 2013-07-01 12:03 - 00000000 ___RD C:\Users\Veverka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-11 19:46 - 2013-07-01 12:03 - 00000000 ___RD C:\Users\Veverka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-11 19:46 - 2013-07-01 12:03 - 00000000 ____D C:\Users\Veverka\AppData\Local\LogMeIn Hamachi
2013-11-11 19:46 - 2013-07-01 12:03 - 00000000 ____D C:\Users\Veverka
2013-11-11 19:46 - 2013-03-05 17:33 - 00000000 ____D C:\Users\Kačenka
2013-11-11 19:46 - 2012-11-25 11:28 - 00000000 ____D C:\Users\Administrator
2013-11-11 19:46 - 2011-08-21 12:04 - 00000000 ____D C:\Users\Hynek.Mila_HP
2013-11-11 19:46 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\wfp
2013-11-11 19:46 - 2009-07-14 03:37 - 00000000 ____D C:\windows\AppCompat
2013-11-11 19:45 - 2013-03-05 17:34 - 00000000 ____D C:\Users\Kačenka\AppData\Local\LogMeIn Hamachi
2013-11-11 19:45 - 2012-02-04 17:47 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Local\LogMeIn Hamachi
2013-11-11 19:45 - 2011-07-15 14:04 - 00000000 ____D C:\ProgramData\FLEXnet
2013-11-11 19:45 - 2009-07-14 03:37 - 00000000 ____D C:\windows\registration
2013-11-11 19:44 - 2013-07-01 18:17 - 00000000 ____D C:\Users\Veverka\AppData\Local\Microsoft Games
2013-11-11 19:44 - 2011-08-23 08:50 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Roaming\Skype
2013-11-11 18:47 - 2013-11-02 19:16 - 95025368 ____T C:\ProgramData\orwla9.bxx
2013-11-11 18:34 - 2013-11-11 18:34 - 00000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn
2013-11-11 17:46 - 2013-11-02 19:16 - 00000000 _____ C:\ProgramData\orwla9.fvv
2013-11-07 11:23 - 2013-11-07 11:23 - 00000000 ____D C:\Users\Veverka\AppData\Local\Apple
2013-11-02 19:33 - 2013-11-02 19:33 - 00000000 ____D C:\Users\Kačenka\AppData\Local\LogMeIn
2013-11-02 19:27 - 2013-07-01 12:05 - 00109688 _____ C:\Users\Veverka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-02 19:26 - 2013-11-02 19:26 - 00000000 ____D C:\HP_RECOVERY_mountHPSF
2013-11-02 19:24 - 2013-11-02 19:24 - 00000000 ____D C:\Users\Veverka\AppData\Local\LogMeIn
2013-11-02 19:16 - 2013-11-02 19:16 - 00151552 _____ (Корпорация Майкрософт) C:\ProgramData\9alwro.dss
2013-11-01 09:23 - 2013-11-01 09:23 - 00000000 ____D C:\Program Files\Common Files\Portrait Displays
2013-11-01 09:22 - 2013-11-01 09:22 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Roaming\Hewlett-Packard Company
2013-10-29 19:29 - 2012-04-25 18:58 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-29 19:29 - 2011-07-15 22:55 - 01998593 _____ C:\windows\WindowsUpdate.log
2013-10-29 19:28 - 2012-08-06 13:04 - 00000922 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-976819227-3545367544-2869399780-1003Core.job
2013-10-29 19:21 - 2012-08-06 11:51 - 00000978 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-976819227-3545367544-2869399780-1004UA.job
2013-10-29 19:19 - 2012-08-06 13:04 - 00000974 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-976819227-3545367544-2869399780-1003UA.job
2013-10-29 19:19 - 2012-07-23 09:57 - 00000938 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-29 19:18 - 2012-08-06 11:51 - 00000926 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-976819227-3545367544-2869399780-1004Core.job
2013-10-27 20:26 - 2013-10-23 19:26 - 00000316 _____ C:\windows\Tasks\HPCeeScheduleForMila.job
2013-10-27 14:16 - 2013-10-26 14:17 - 00000000 ____D C:\Program Files\Steam
2013-10-27 13:42 - 2012-05-01 16:18 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\.techniclauncher
2013-10-27 13:37 - 2013-10-26 19:43 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\Roblox
2013-10-27 13:09 - 2013-08-06 19:37 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Seznam.cz
2013-10-27 13:07 - 2013-01-13 12:08 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\LogMeIn Hamachi
2013-10-27 13:06 - 2013-08-29 08:21 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Movdap
2013-10-27 13:05 - 2013-10-27 13:05 - 00001355 _____ C:\Users\Hynek.Mila_HP\Desktop\ROBLOX Player.lnk
2013-10-27 13:05 - 2013-10-26 19:44 - 00001174 _____ C:\Users\Hynek.Mila_HP\Desktop\ROBLOX Studio 2013.lnk
2013-10-27 13:05 - 2013-10-26 19:44 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2013-10-26 19:43 - 2013-10-26 19:42 - 00542576 _____ (ROBLOX Corporation) C:\Users\Hynek.Mila_HP\Desktop\RobloxPlayerLauncher.exe
2013-10-26 19:35 - 2011-12-16 17:39 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Skype
2013-10-26 18:59 - 2011-09-10 08:41 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\Microsoft Games
2013-10-26 16:06 - 2013-10-26 14:17 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-10-26 14:15 - 2013-10-26 14:14 - 01669632 _____ C:\Users\Hynek.Mila_HP\Desktop\SteamInstall.msi
2013-10-26 13:41 - 2013-10-26 13:41 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\Clownfish
2013-10-26 13:40 - 2013-10-26 13:40 - 00537827 _____ C:\Users\Hynek.Mila_HP\Desktop\clownfish_portable_340.zip
2013-10-26 13:37 - 2012-04-09 12:20 - 00000000 ____D C:\Users\Hynek.Mila_HP\Documents\Skype Voice Records
2013-10-26 13:31 - 2013-10-26 13:24 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\Dubstep
2013-10-26 13:22 - 2013-10-26 13:20 - 36794880 _____ C:\Users\Hynek.Mila_HP\Desktop\Reapers EP - Winside.rar
2013-10-26 13:09 - 2012-07-24 10:10 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\.minecraft
2013-10-26 13:05 - 2013-10-26 13:05 - 00000000 ____D C:\Users\Hynek.Mila_HP\Desktop\BetterWorld
2013-10-26 13:04 - 2013-10-26 13:04 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft Eden mods helper
2013-10-26 12:32 - 2013-04-26 19:26 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\.technic
2013-10-26 12:32 - 2013-04-26 19:25 - 02110334 _____ C:\Users\Hynek.Mila_HP\Desktop\TechnicLauncher.jar
2013-10-26 11:52 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-26 11:52 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-26 11:42 - 2013-10-26 11:33 - 77236500 _____ C:\Users\Hynek.Mila_HP\Desktop\Eden-BP-1.5.2.exe
2013-10-26 11:34 - 2013-10-26 11:34 - 00675988 _____ C:\Users\Hynek.Mila_HP\Desktop\MinecraftNew.exe
2013-10-26 11:23 - 2012-11-17 12:21 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Roaming\Mozilla
2013-10-26 11:14 - 2013-10-26 11:14 - 00000000 ____D C:\Users\Hynek.Mila_HP\AppData\Local\LogMeIn
2013-10-25 07:17 - 2011-08-24 12:55 - 00000000 ____D C:\Users\Mila.Mila_HP\AppData\Roaming\Mozilla
2013-10-23 20:16 - 2013-10-23 20:16 - 00000925 _____ C:\Users\Mila.Mila_HP\Desktop\Microsoft Office 2007 – zástupce.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000243 _____ C:\Users\Mila.Mila_HP\Desktop\Email (2).url
2013-10-23 19:25 - 2012-05-04 17:46 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-10-23 19:25 - 2012-04-24 21:00 - 00000052 _____ C:\windows\system32\DOErrors.log
2013-10-20 23:16 - 2013-10-20 23:16 - 00000000 ___HD C:\windows\AxInstSV
2013-10-19 08:56 - 2013-10-10 16:24 - 00000000 ____D C:\ProgramData\LogMeIn
2013-10-19 07:37 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache
2013-10-19 07:10 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-10-18 13:24 - 2013-10-18 13:24 - 00371568 _____ C:\windows\Minidump\101813-29577-01.dmp
2013-10-18 13:24 - 2012-06-23 15:35 - 00000000 ____D C:\windows\Minidump
2013-10-18 13:24 - 2012-06-23 15:34 - 400797939 _____ C:\windows\MEMORY.DMP
Files to move or delete:
====================
C:\ProgramData\9alwro.dss
Some content of TEMP:
====================
C:\Users\Hynek.Mila_HP\AppData\Local\temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Hynek.Mila_HP\AppData\Local\temp\Mountain_Lion_Skin_Pack_1.0-X86.exe
C:\Users\Hynek.Mila_HP\AppData\Local\temp\Setup-D2502DD2B71B5.exe
C:\Users\Hynek.Mila_HP\AppData\Local\temp\SkypeSetup.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\Extract.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\SkypeSetup.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\SP49415.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\SP51115.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\SP54600.exe
C:\Users\Mila.Mila_HP\AppData\Local\temp\~tmf4707502267313107155.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-04 14:50
==================== End Of Log ============================