Zatížení procesoru na 100%
Napsal: 18 pro 2013 19:44
prosím o kontrolu tohoto logu - mám najednou procesor zatížený na 100%
PS: pokud by bylo možné vysvětlení pro někoho kdo neví o PC skoro nic
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-12-2013 03
Ran by Jakub (administrator) on JAKUB-PC on 18-12-2013 17:22:15
Running from C:\Users\Jakub\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
() C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
() C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\dtupdate.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
() C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
() C:\Windows\SysWOW64\WinMsgBalloonServer.exe
() C:\Windows\SysWOW64\WinMsgBalloonClient.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-16] (Realtek Semiconductor)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2184520 2009-03-24] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.EXE [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [BitTorrent] - C:\Program Files (x86)\BitTorrent\BitTorrent.exe [1398680 2012-10-24] (BitTorrent, Inc.)
HKCU\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1641896 2013-06-06] (Valve Corporation)
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
MountPoints2: {78022bfb-7e6e-11e1-bbb8-001d7dc65aea} - G:\setup\rsrc\Autorun.exe
MountPoints2: {b635c6fc-6a32-11e1-ab11-806e6f6e6963} - E:\StartUp.exe
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\FirstStart.exe [40960 2006-05-16] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [QuickTime Task] - D:\fotak\qttask.exe [77824 2012-08-19] (Apple Computer, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKU\acer\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
AppInit_DLLs: C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\IEBHO.dll [1791384 2012-03-06] (Bandoo Media, inc)
AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll [1233816 2012-03-06] (Bandoo Media, inc)
Startup: C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.ividi.org/?src=tbhp&id=fc ... 8&affilt=3
URLSearchHook: HKLM-x32 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
URLSearchHook: HKCU - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
URLSearchHook: HKCU - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - {85E8068E-2E7A-4D13-88D6-6A894DB41809} URL = http://search.ividi.org/?q={searchTerms ... lt=3&r=410
SearchScopes: HKCU - {FD6AEB38-159F-45B0-A2AF-84DD098E7107} URL = http://websearch.ask.com/redirect?clien ... 64EBD41459
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: SecretSauce - {0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} - C:\Program Files (x86)\SecretSauce\SecretSauceBHO.dll (SecretSauce)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: No Name - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No File
BHO-x32: XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: DefaultTab Browser Helper - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\DefaultTabBHO.dll (Search Results LLC.)
BHO-x32: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
BHO-x32: ividi Helper Object - {8B8B2E80-1444-451D-AC8E-EB9A847F3887} - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\bh\ividi.dll (Unitech LLC)
BHO-x32: Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\Apps\RelatedLinksBHO.dll (Search Results)
BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\Apps\RelatedLinksBHO.dll (Search Results)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Extension: OneClickDownloader - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com
FF Extension: No Name - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
Chrome:
=======
CHR DefaultSearchKeyword: google.cz
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR Extension: (Docs) - C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Wallet) - C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM-x32\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx
CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM-x32\...\Chrome\Extension: [hmhfbmpdiffkamakhdbcgojfnbnlcenm] - C:\ProgramData\Microsoft\Windows\DRM\Server\notificatoin_1.0.0.crx
CHR HKLM-x32\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files (x86)\DefaultTab\DefaultTab.crx
CHR HKLM-x32\...\Chrome\Extension: [kpdhgpkkloealnjnmepfhanpcleldbef] - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\ividi.crx
CHR HKLM-x32\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Users\Jakub\AppData\Local\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Users\Jakub\AppData\Local\Temp\YontooLayers.crx
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx
CHR HKLM-x32\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files (x86)\1ClickDownload\oneclickdownloader10.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-14] (Advanced Micro Devices, Inc.)
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [551824 2012-12-25] (Protection Technology)
S2 DefaultTabSearch; C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [573952 2013-10-07] ()
R2 DefaultTabUpdate; C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\dtupdate.exe [107520 2013-10-24] ()
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-07-03] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S2 Update SecretSauce; C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe [66848 2013-11-13] ()
R2 Util SecretSauce; C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe [66848 2013-11-29] ()
R2 Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-01-29] ()
==================== Drivers (Whitelisted) ====================
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [2771056 2012-12-25] (Protection Technology)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-12-03] ()
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-12-03] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-04-04] ()
U3 axjplgb9; C:\Windows\System32\Drivers\axjplgb9.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
S3 X6va001; \??\C:\Users\Jakub\AppData\Local\Temp\001695C.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-18 17:22 - 2013-12-18 17:51 - 00018940 _____ C:\Users\Jakub\Desktop\FRST.txt
2013-12-18 17:21 - 2013-12-18 17:21 - 00000000 ____D C:\FRST
2013-12-18 17:20 - 2013-12-18 17:20 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2013-12-18 17:19 - 2013-12-18 17:20 - 01929306 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2013-12-18 11:38 - 2013-12-18 11:38 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-18 11:38 - 2013-12-18 11:38 - 00001017 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-18 11:37 - 2013-12-18 11:37 - 04618136 _____ (Piriform Ltd) C:\Users\Jakub\Desktop\ccsetup408.exe
2013-12-18 10:49 - 2013-12-18 13:17 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-18 10:49 - 2013-12-18 10:49 - 02365840 _____ C:\Users\Jakub\Desktop\SecurityTaskManager_Setup.exe
2013-12-18 10:39 - 2013-12-18 10:39 - 01502423 _____ C:\Users\Jakub\Desktop\DC3Setup_33.zip
2013-12-18 10:39 - 2004-09-17 17:37 - 01520101 _____ C:\Users\Jakub\Desktop\setup.exe
2013-12-18 10:12 - 2013-12-18 10:48 - 331219155 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-True-Tears-06.mkv
2013-12-18 10:12 - 2013-12-18 10:16 - 188885084 _____ C:\Users\Jakub\Desktop\Nubles20Machine-Doll20wa20Kizutsukanai20-2010.mp4
2013-12-17 23:50 - 2013-12-18 00:38 - 146800640 ____N C:\Users\Jakub\Desktop\[A-Keep]_Yumeria_09.avi
2013-12-17 23:20 - 2013-12-18 00:43 - 716146408 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-Freezing-Vibration-11.mkv
2013-12-13 11:19 - 2013-12-13 11:20 - 00000000 ____D C:\Users\Jakub\Desktop\OP, ED songy
2013-12-12 13:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 13:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 13:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 13:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 13:04 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 13:04 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 13:04 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 13:04 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 13:04 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 13:04 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 13:04 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 13:04 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 13:04 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 13:04 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 13:04 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 13:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 13:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 13:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 13:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 13:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 13:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 13:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 13:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 13:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 13:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 13:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 13:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 13:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 13:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 13:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 13:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 13:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 13:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 13:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 13:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 12:13 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 12:13 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 12:13 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 12:13 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 12:13 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 12:13 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 12:13 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 12:12 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 12:12 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 12:12 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 12:12 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 12:12 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 12:12 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 12:12 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 12:12 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 12:12 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 12:12 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 12:12 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 12:12 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-08 13:45 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Jakub\AppData\Local\Divinity 2
2013-12-08 00:03 - 2013-12-08 00:03 - 00000799 _____ C:\Users\Jakub\Desktop\Divinity II - Ego Draconis.lnk
2013-12-08 00:02 - 2013-12-08 00:02 - 00000000 ____D C:\ProgramData\Divinity 2
2013-12-03 11:15 - 2013-12-03 11:16 - 00000000 ____D C:\Users\Jakub\AppData\Local\Risen
2013-12-03 11:14 - 2013-12-03 11:14 - 00000330 _____ C:\Users\Jakub\Desktop\Risen – zástupce.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00002364 _____ C:\Users\Jakub\Desktop\Google Chrome.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-11-30 15:12 - 2013-11-30 15:13 - 34548576 _____ (Google Inc.) C:\Users\Jakub\Desktop\chrome_installer.exe
2013-11-29 11:08 - 2013-11-29 11:09 - 00000000 ____D C:\Users\Jakub\AppData\Local\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\Documents\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\cache
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\.android
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 _____ C:\Users\Jakub\daemonprocess.txt
2013-11-29 11:07 - 2013-11-29 11:09 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-29 11:06 - 2013-11-29 19:06 - 00000000 ____D C:\Program Files (x86)\SecretSauce
2013-11-29 11:05 - 2013-11-29 11:12 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-11-29 11:05 - 2013-11-29 11:05 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-11-28 16:50 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-25 11:47 - 2013-11-25 11:47 - 00000980 _____ C:\Users\Jakub\Desktop\Wolverine – zástupce.lnk
2013-11-24 18:22 - 2013-11-24 18:22 - 00000000 ____D C:\Users\Jakub\Documents\Wolverine
2013-11-24 18:19 - 2013-11-24 18:19 - 00000000 ____D C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP
2013-11-23 12:06 - 2013-11-23 12:06 - 00002914 _____ C:\Windows\System32\Tasks\{13003E39-C3EE-4ED6-81D6-FA1D1D93818E}
2013-11-23 12:00 - 2013-11-23 12:00 - 00000594 _____ C:\Users\Public\Desktop\Spuštění Bad Boys 2.lnk
2013-11-23 09:19 - 2013-11-23 09:19 - 00000000 ____D C:\ProgramData\McAfee
2013-11-22 21:30 - 2013-11-22 22:35 - 00003339 _____ C:\Windows\wininit.ini
2013-11-22 19:21 - 2013-11-22 19:21 - 00000000 ____D C:\Users\Jakub\Documents\ProcAlyzer Dumps
2013-11-22 19:14 - 2013-06-07 02:53 - 00000054 _____ C:\Windows\system32\Drivers\etc\hosts.20131122-191459.backup
2013-11-22 19:04 - 2013-11-22 21:30 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-22 19:04 - 2013-11-22 19:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-22 19:04 - 2013-11-22 19:04 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-22 19:04 - 2013-11-22 19:04 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-11-22 19:04 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-11-22 18:53 - 2013-11-22 18:55 - 46988968 _____ C:\Users\Jakub\Downloads\spybot-2.2.exe
2013-11-19 23:17 - 2013-11-19 23:18 - 00000000 ____D C:\Users\Jakub\Documents\Shadow Warrior
==================== One Month Modified Files and Folders =======
2013-12-18 17:51 - 2013-12-18 17:22 - 00018940 _____ C:\Users\Jakub\Desktop\FRST.txt
2013-12-18 17:21 - 2013-12-18 17:21 - 00000000 ____D C:\FRST
2013-12-18 17:20 - 2013-12-18 17:20 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2013-12-18 17:20 - 2013-12-18 17:19 - 01929306 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2013-12-18 17:17 - 2013-06-05 13:00 - 01299903 _____ C:\Windows\WindowsUpdate.log
2013-12-18 17:17 - 2012-03-31 13:17 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-18 13:17 - 2013-12-18 10:49 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-18 11:39 - 2013-06-07 19:06 - 00000000 ____D C:\Users\Jakub\AppData\Local\CrashDumps
2013-12-18 11:39 - 2013-02-01 14:38 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-18 11:39 - 2012-06-29 14:34 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\BitTorrent
2013-12-18 11:39 - 2012-04-04 16:52 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\DAEMON Tools Lite
2013-12-18 11:39 - 2012-03-14 18:26 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Skype
2013-12-18 11:39 - 2012-03-10 07:55 - 00000000 ____D C:\Windows\Panther
2013-12-18 11:38 - 2013-12-18 11:38 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-18 11:38 - 2013-12-18 11:38 - 00001017 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-18 11:38 - 2012-03-11 08:53 - 00000000 ____D C:\Program Files (x86)\CCleaner
2013-12-18 11:37 - 2013-12-18 11:37 - 04618136 _____ (Piriform Ltd) C:\Users\Jakub\Desktop\ccsetup408.exe
2013-12-18 11:14 - 2009-07-26 19:41 - 00631276 _____ C:\Windows\system32\perfh005.dat
2013-12-18 11:14 - 2009-07-26 19:41 - 00121930 _____ C:\Windows\system32\perfc005.dat
2013-12-18 11:14 - 2009-07-14 06:13 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-18 11:14 - 2009-07-14 05:45 - 00012624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-18 11:14 - 2009-07-14 05:45 - 00012624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-18 11:06 - 2009-07-14 06:08 - 00032528 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-18 11:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-18 10:49 - 2013-12-18 10:49 - 02365840 _____ C:\Users\Jakub\Desktop\SecurityTaskManager_Setup.exe
2013-12-18 10:48 - 2013-12-18 10:12 - 331219155 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-True-Tears-06.mkv
2013-12-18 10:39 - 2013-12-18 10:39 - 01502423 _____ C:\Users\Jakub\Desktop\DC3Setup_33.zip
2013-12-18 10:16 - 2013-12-18 10:12 - 188885084 _____ C:\Users\Jakub\Desktop\Nubles20Machine-Doll20wa20Kizutsukanai20-2010.mp4
2013-12-18 00:43 - 2013-12-17 23:20 - 716146408 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-Freezing-Vibration-11.mkv
2013-12-18 00:38 - 2013-12-17 23:50 - 146800640 ____N C:\Users\Jakub\Desktop\[A-Keep]_Yumeria_09.avi
2013-12-14 20:51 - 2012-05-02 15:51 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\vlc
2013-12-13 17:09 - 2013-10-24 13:46 - 00001120 __RSH C:\Users\Jakub\ntuser.pol
2013-12-13 17:09 - 2012-03-09 23:12 - 00000000 ____D C:\Users\Jakub
2013-12-13 11:20 - 2013-12-13 11:19 - 00000000 ____D C:\Users\Jakub\Desktop\OP, ED songy
2013-12-13 08:38 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 15:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-12 13:23 - 2009-07-14 05:45 - 00332704 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 13:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
2013-12-12 13:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sk-SK
2013-12-12 13:02 - 2013-08-14 22:25 - 00000000 ____D C:\Windows\system32\MRT
2013-12-12 12:52 - 2012-03-10 01:38 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 13:17 - 2012-03-31 13:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 13:17 - 2012-03-31 13:17 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 13:17 - 2012-03-09 23:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-08 13:45 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Jakub\AppData\Local\Divinity 2
2013-12-08 00:03 - 2013-12-08 00:03 - 00000799 _____ C:\Users\Jakub\Desktop\Divinity II - Ego Draconis.lnk
2013-12-08 00:02 - 2013-12-08 00:02 - 00000000 ____D C:\ProgramData\Divinity 2
2013-12-03 11:31 - 2012-03-10 00:37 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-03 11:16 - 2013-12-03 11:15 - 00000000 ____D C:\Users\Jakub\AppData\Local\Risen
2013-12-03 11:14 - 2013-12-03 11:14 - 00000330 _____ C:\Users\Jakub\Desktop\Risen – zástupce.lnk
2013-12-03 11:12 - 2012-04-04 20:36 - 00314016 _____ C:\Windows\system32\Drivers\atksgt.sys
2013-12-03 11:12 - 2012-04-04 20:36 - 00043680 _____ C:\Windows\system32\Drivers\lirsgt.sys
2013-12-01 10:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-30 15:13 - 2013-11-30 15:13 - 00002364 _____ C:\Users\Jakub\Desktop\Google Chrome.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-11-30 15:13 - 2013-11-30 15:12 - 34548576 _____ (Google Inc.) C:\Users\Jakub\Desktop\chrome_installer.exe
2013-11-30 15:13 - 2012-06-29 14:35 - 00000000 ____D C:\Users\Jakub\AppData\Local\Google
2013-11-29 19:06 - 2013-11-29 11:06 - 00000000 ____D C:\Program Files (x86)\SecretSauce
2013-11-29 11:12 - 2013-11-29 11:05 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-11-29 11:09 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\Mobogenie
2013-11-29 11:09 - 2013-11-29 11:07 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\Documents\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\cache
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\.android
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 _____ C:\Users\Jakub\daemonprocess.txt
2013-11-29 11:05 - 2013-11-29 11:05 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-11-26 12:54 - 2013-12-12 13:03 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 11:19 - 2013-12-12 13:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 11:18 - 2013-12-12 13:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 11:11 - 2013-12-12 13:03 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 10:48 - 2013-12-12 13:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 10:46 - 2013-12-12 13:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 10:41 - 2013-12-12 13:03 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:29 - 2013-12-12 13:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:27 - 2013-12-12 13:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 10:23 - 2013-12-12 13:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 10:21 - 2013-12-12 13:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 10:18 - 2013-12-12 13:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:18 - 2013-12-12 13:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 10:16 - 2013-12-12 13:03 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:57 - 2013-12-12 13:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-12 13:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 09:38 - 2013-12-12 13:03 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 09:35 - 2013-12-12 13:03 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:32 - 2013-12-12 13:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 09:28 - 2013-12-12 13:03 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 09:16 - 2013-12-12 13:03 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-12 13:03 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-12 13:03 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-12 13:03 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-12 13:03 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-12 13:03 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:40 - 2013-12-12 13:03 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-12 13:03 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-12 13:03 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-12 13:03 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-12 13:03 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-25 11:47 - 2013-11-25 11:47 - 00000980 _____ C:\Users\Jakub\Desktop\Wolverine – zástupce.lnk
2013-11-24 18:22 - 2013-11-24 18:22 - 00000000 ____D C:\Users\Jakub\Documents\Wolverine
2013-11-24 18:19 - 2013-11-24 18:19 - 00000000 ____D C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP
2013-11-23 19:26 - 2013-12-12 12:13 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 18:47 - 2013-12-12 12:13 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-23 12:06 - 2013-11-23 12:06 - 00002914 _____ C:\Windows\System32\Tasks\{13003E39-C3EE-4ED6-81D6-FA1D1D93818E}
2013-11-23 12:00 - 2013-11-23 12:00 - 00000594 _____ C:\Users\Public\Desktop\Spuštění Bad Boys 2.lnk
2013-11-23 09:23 - 2012-03-09 23:26 - 00000000 ____D C:\Users\Jakub\AppData\Local\Adobe
2013-11-23 09:19 - 2013-11-23 09:19 - 00000000 ____D C:\ProgramData\McAfee
2013-11-22 22:35 - 2013-11-22 21:30 - 00003339 _____ C:\Windows\wininit.ini
2013-11-22 21:30 - 2013-11-22 19:04 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-22 21:30 - 2012-07-12 21:40 - 00000000 ____D C:\Program Files\Web Assistant
2013-11-22 19:21 - 2013-11-22 19:21 - 00000000 ____D C:\Users\Jakub\Documents\ProcAlyzer Dumps
2013-11-22 19:10 - 2013-11-22 19:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-22 19:04 - 2013-11-22 19:04 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-22 19:04 - 2013-11-22 19:04 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-11-22 18:55 - 2013-11-22 18:53 - 46988968 _____ C:\Users\Jakub\Downloads\spybot-2.2.exe
2013-11-22 14:48 - 2012-03-10 01:17 - 00007644 _____ C:\Users\Jakub\AppData\Local\resmon.resmoncfg
2013-11-19 23:18 - 2013-11-19 23:17 - 00000000 ____D C:\Users\Jakub\Documents\Shadow Warrior
2013-11-19 11:21 - 2012-03-09 23:33 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\ProgramData\1926068.bat
C:\ProgramData\1926068.pad
C:\ProgramData\1926068.reg
C:\ProgramData\req2dz.reg
C:\Users\Jakub\jagex_cl_runescape_LIVE.dat
C:\Users\Jakub\jagex_cl_runescape_LIVE1.dat
C:\Users\Jakub\jagex_cl_runescape_LIVE_BETA.dat
C:\Users\Jakub\random.dat
Some content of TEMP:
====================
C:\Users\Jakub\AppData\Local\Temp\A~NSISu_.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jakub\Desktop" je 2602 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jakub^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regmonstd.lnk
C:\Windows\System32\rundll32.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
PS: pokud by bylo možné vysvětlení pro někoho kdo neví o PC skoro nic

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-12-2013 03
Ran by Jakub (administrator) on JAKUB-PC on 18-12-2013 17:22:15
Running from C:\Users\Jakub\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
() C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
() C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\dtupdate.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
() C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
() C:\Windows\SysWOW64\WinMsgBalloonServer.exe
() C:\Windows\SysWOW64\WinMsgBalloonClient.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-16] (Realtek Semiconductor)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2184520 2009-03-24] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.EXE [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [BitTorrent] - C:\Program Files (x86)\BitTorrent\BitTorrent.exe [1398680 2012-10-24] (BitTorrent, Inc.)
HKCU\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1641896 2013-06-06] (Valve Corporation)
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
MountPoints2: {78022bfb-7e6e-11e1-bbb8-001d7dc65aea} - G:\setup\rsrc\Autorun.exe
MountPoints2: {b635c6fc-6a32-11e1-ab11-806e6f6e6963} - E:\StartUp.exe
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\FirstStart.exe [40960 2006-05-16] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [QuickTime Task] - D:\fotak\qttask.exe [77824 2012-08-19] (Apple Computer, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKU\acer\...\Run: [OM_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
AppInit_DLLs: C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\IEBHO.dll [1791384 2012-03-06] (Bandoo Media, inc)
AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll [1233816 2012-03-06] (Bandoo Media, inc)
Startup: C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.ividi.org/?src=tbhp&id=fc ... 8&affilt=3
URLSearchHook: HKLM-x32 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
URLSearchHook: HKCU - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
URLSearchHook: HKCU - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - {85E8068E-2E7A-4D13-88D6-6A894DB41809} URL = http://search.ividi.org/?q={searchTerms ... lt=3&r=410
SearchScopes: HKCU - {FD6AEB38-159F-45B0-A2AF-84DD098E7107} URL = http://websearch.ask.com/redirect?clien ... 64EBD41459
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: SecretSauce - {0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} - C:\Program Files (x86)\SecretSauce\SecretSauceBHO.dll (SecretSauce)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: No Name - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No File
BHO-x32: XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: DefaultTab Browser Helper - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\DefaultTabBHO.dll (Search Results LLC.)
BHO-x32: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
BHO-x32: ividi Helper Object - {8B8B2E80-1444-451D-AC8E-EB9A847F3887} - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\bh\ividi.dll (Unitech LLC)
BHO-x32: Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\Apps\RelatedLinksBHO.dll (Search Results)
BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - XfireXO D1 Toolbar - {7574dbbe-1c99-41ad-bf35-3497d936152d} - C:\Program Files (x86)\XfireXO_D1\prxtbXfir.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\Apps\RelatedLinksBHO.dll (Search Results)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Extension: OneClickDownloader - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com
FF Extension: No Name - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
Chrome:
=======
CHR DefaultSearchKeyword: google.cz
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR Extension: (Docs) - C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Wallet) - C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM-x32\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx
CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM-x32\...\Chrome\Extension: [hmhfbmpdiffkamakhdbcgojfnbnlcenm] - C:\ProgramData\Microsoft\Windows\DRM\Server\notificatoin_1.0.0.crx
CHR HKLM-x32\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files (x86)\DefaultTab\DefaultTab.crx
CHR HKLM-x32\...\Chrome\Extension: [kpdhgpkkloealnjnmepfhanpcleldbef] - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\ividi.crx
CHR HKLM-x32\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Users\Jakub\AppData\Local\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Users\Jakub\AppData\Local\Temp\YontooLayers.crx
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx
CHR HKLM-x32\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files (x86)\1ClickDownload\oneclickdownloader10.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-14] (Advanced Micro Devices, Inc.)
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [551824 2012-12-25] (Protection Technology)
S2 DefaultTabSearch; C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [573952 2013-10-07] ()
R2 DefaultTabUpdate; C:\Users\Jakub\AppData\Roaming\defaulttab\defaulttab\dtupdate.exe [107520 2013-10-24] ()
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-07-03] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S2 Update SecretSauce; C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe [66848 2013-11-13] ()
R2 Util SecretSauce; C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe [66848 2013-11-29] ()
R2 Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-01-29] ()
==================== Drivers (Whitelisted) ====================
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [2771056 2012-12-25] (Protection Technology)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-12-03] ()
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-12-03] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-04-04] ()
U3 axjplgb9; C:\Windows\System32\Drivers\axjplgb9.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
S3 X6va001; \??\C:\Users\Jakub\AppData\Local\Temp\001695C.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-18 17:22 - 2013-12-18 17:51 - 00018940 _____ C:\Users\Jakub\Desktop\FRST.txt
2013-12-18 17:21 - 2013-12-18 17:21 - 00000000 ____D C:\FRST
2013-12-18 17:20 - 2013-12-18 17:20 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2013-12-18 17:19 - 2013-12-18 17:20 - 01929306 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2013-12-18 11:38 - 2013-12-18 11:38 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-18 11:38 - 2013-12-18 11:38 - 00001017 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-18 11:37 - 2013-12-18 11:37 - 04618136 _____ (Piriform Ltd) C:\Users\Jakub\Desktop\ccsetup408.exe
2013-12-18 10:49 - 2013-12-18 13:17 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-18 10:49 - 2013-12-18 10:49 - 02365840 _____ C:\Users\Jakub\Desktop\SecurityTaskManager_Setup.exe
2013-12-18 10:39 - 2013-12-18 10:39 - 01502423 _____ C:\Users\Jakub\Desktop\DC3Setup_33.zip
2013-12-18 10:39 - 2004-09-17 17:37 - 01520101 _____ C:\Users\Jakub\Desktop\setup.exe
2013-12-18 10:12 - 2013-12-18 10:48 - 331219155 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-True-Tears-06.mkv
2013-12-18 10:12 - 2013-12-18 10:16 - 188885084 _____ C:\Users\Jakub\Desktop\Nubles20Machine-Doll20wa20Kizutsukanai20-2010.mp4
2013-12-17 23:50 - 2013-12-18 00:38 - 146800640 ____N C:\Users\Jakub\Desktop\[A-Keep]_Yumeria_09.avi
2013-12-17 23:20 - 2013-12-18 00:43 - 716146408 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-Freezing-Vibration-11.mkv
2013-12-13 11:19 - 2013-12-13 11:20 - 00000000 ____D C:\Users\Jakub\Desktop\OP, ED songy
2013-12-12 13:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 13:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 13:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 13:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 13:04 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 13:04 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 13:04 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 13:04 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 13:04 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 13:04 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 13:04 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 13:04 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 13:04 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 13:04 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 13:04 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 13:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 13:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 13:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 13:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 13:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 13:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 13:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 13:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 13:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 13:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 13:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 13:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 13:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 13:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 13:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 13:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 13:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 13:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 13:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 13:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 12:13 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 12:13 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 12:13 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 12:13 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 12:13 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 12:13 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 12:13 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 12:12 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 12:12 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 12:12 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 12:12 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 12:12 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 12:12 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 12:12 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 12:12 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 12:12 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 12:12 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 12:12 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 12:12 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-08 13:45 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Jakub\AppData\Local\Divinity 2
2013-12-08 00:03 - 2013-12-08 00:03 - 00000799 _____ C:\Users\Jakub\Desktop\Divinity II - Ego Draconis.lnk
2013-12-08 00:02 - 2013-12-08 00:02 - 00000000 ____D C:\ProgramData\Divinity 2
2013-12-03 11:15 - 2013-12-03 11:16 - 00000000 ____D C:\Users\Jakub\AppData\Local\Risen
2013-12-03 11:14 - 2013-12-03 11:14 - 00000330 _____ C:\Users\Jakub\Desktop\Risen – zástupce.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00002364 _____ C:\Users\Jakub\Desktop\Google Chrome.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-11-30 15:12 - 2013-11-30 15:13 - 34548576 _____ (Google Inc.) C:\Users\Jakub\Desktop\chrome_installer.exe
2013-11-29 11:08 - 2013-11-29 11:09 - 00000000 ____D C:\Users\Jakub\AppData\Local\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\Documents\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\cache
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\.android
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 _____ C:\Users\Jakub\daemonprocess.txt
2013-11-29 11:07 - 2013-11-29 11:09 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-29 11:06 - 2013-11-29 19:06 - 00000000 ____D C:\Program Files (x86)\SecretSauce
2013-11-29 11:05 - 2013-11-29 11:12 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-11-29 11:05 - 2013-11-29 11:05 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-11-28 16:50 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-28 16:50 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-25 11:47 - 2013-11-25 11:47 - 00000980 _____ C:\Users\Jakub\Desktop\Wolverine – zástupce.lnk
2013-11-24 18:22 - 2013-11-24 18:22 - 00000000 ____D C:\Users\Jakub\Documents\Wolverine
2013-11-24 18:19 - 2013-11-24 18:19 - 00000000 ____D C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP
2013-11-23 12:06 - 2013-11-23 12:06 - 00002914 _____ C:\Windows\System32\Tasks\{13003E39-C3EE-4ED6-81D6-FA1D1D93818E}
2013-11-23 12:00 - 2013-11-23 12:00 - 00000594 _____ C:\Users\Public\Desktop\Spuštění Bad Boys 2.lnk
2013-11-23 09:19 - 2013-11-23 09:19 - 00000000 ____D C:\ProgramData\McAfee
2013-11-22 21:30 - 2013-11-22 22:35 - 00003339 _____ C:\Windows\wininit.ini
2013-11-22 19:21 - 2013-11-22 19:21 - 00000000 ____D C:\Users\Jakub\Documents\ProcAlyzer Dumps
2013-11-22 19:14 - 2013-06-07 02:53 - 00000054 _____ C:\Windows\system32\Drivers\etc\hosts.20131122-191459.backup
2013-11-22 19:04 - 2013-11-22 21:30 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-22 19:04 - 2013-11-22 19:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-22 19:04 - 2013-11-22 19:04 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-22 19:04 - 2013-11-22 19:04 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-11-22 19:04 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-11-22 18:53 - 2013-11-22 18:55 - 46988968 _____ C:\Users\Jakub\Downloads\spybot-2.2.exe
2013-11-19 23:17 - 2013-11-19 23:18 - 00000000 ____D C:\Users\Jakub\Documents\Shadow Warrior
==================== One Month Modified Files and Folders =======
2013-12-18 17:51 - 2013-12-18 17:22 - 00018940 _____ C:\Users\Jakub\Desktop\FRST.txt
2013-12-18 17:21 - 2013-12-18 17:21 - 00000000 ____D C:\FRST
2013-12-18 17:20 - 2013-12-18 17:20 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2013-12-18 17:20 - 2013-12-18 17:19 - 01929306 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2013-12-18 17:17 - 2013-06-05 13:00 - 01299903 _____ C:\Windows\WindowsUpdate.log
2013-12-18 17:17 - 2012-03-31 13:17 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-18 13:17 - 2013-12-18 10:49 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-18 11:39 - 2013-06-07 19:06 - 00000000 ____D C:\Users\Jakub\AppData\Local\CrashDumps
2013-12-18 11:39 - 2013-02-01 14:38 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-18 11:39 - 2012-06-29 14:34 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\BitTorrent
2013-12-18 11:39 - 2012-04-04 16:52 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\DAEMON Tools Lite
2013-12-18 11:39 - 2012-03-14 18:26 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Skype
2013-12-18 11:39 - 2012-03-10 07:55 - 00000000 ____D C:\Windows\Panther
2013-12-18 11:38 - 2013-12-18 11:38 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-18 11:38 - 2013-12-18 11:38 - 00001017 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-18 11:38 - 2012-03-11 08:53 - 00000000 ____D C:\Program Files (x86)\CCleaner
2013-12-18 11:37 - 2013-12-18 11:37 - 04618136 _____ (Piriform Ltd) C:\Users\Jakub\Desktop\ccsetup408.exe
2013-12-18 11:14 - 2009-07-26 19:41 - 00631276 _____ C:\Windows\system32\perfh005.dat
2013-12-18 11:14 - 2009-07-26 19:41 - 00121930 _____ C:\Windows\system32\perfc005.dat
2013-12-18 11:14 - 2009-07-14 06:13 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-18 11:14 - 2009-07-14 05:45 - 00012624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-18 11:14 - 2009-07-14 05:45 - 00012624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-18 11:06 - 2009-07-14 06:08 - 00032528 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-18 11:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-18 10:49 - 2013-12-18 10:49 - 02365840 _____ C:\Users\Jakub\Desktop\SecurityTaskManager_Setup.exe
2013-12-18 10:48 - 2013-12-18 10:12 - 331219155 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-True-Tears-06.mkv
2013-12-18 10:39 - 2013-12-18 10:39 - 01502423 _____ C:\Users\Jakub\Desktop\DC3Setup_33.zip
2013-12-18 10:16 - 2013-12-18 10:12 - 188885084 _____ C:\Users\Jakub\Desktop\Nubles20Machine-Doll20wa20Kizutsukanai20-2010.mp4
2013-12-18 00:43 - 2013-12-17 23:20 - 716146408 _____ C:\Users\Jakub\Desktop\[AnimeCzech]-Freezing-Vibration-11.mkv
2013-12-18 00:38 - 2013-12-17 23:50 - 146800640 ____N C:\Users\Jakub\Desktop\[A-Keep]_Yumeria_09.avi
2013-12-14 20:51 - 2012-05-02 15:51 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\vlc
2013-12-13 17:09 - 2013-10-24 13:46 - 00001120 __RSH C:\Users\Jakub\ntuser.pol
2013-12-13 17:09 - 2012-03-09 23:12 - 00000000 ____D C:\Users\Jakub
2013-12-13 11:20 - 2013-12-13 11:19 - 00000000 ____D C:\Users\Jakub\Desktop\OP, ED songy
2013-12-13 08:38 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 15:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-12 13:23 - 2009-07-14 05:45 - 00332704 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 13:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
2013-12-12 13:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sk-SK
2013-12-12 13:02 - 2013-08-14 22:25 - 00000000 ____D C:\Windows\system32\MRT
2013-12-12 12:52 - 2012-03-10 01:38 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 13:17 - 2012-03-31 13:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 13:17 - 2012-03-31 13:17 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 13:17 - 2012-03-09 23:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-08 13:45 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Jakub\AppData\Local\Divinity 2
2013-12-08 00:03 - 2013-12-08 00:03 - 00000799 _____ C:\Users\Jakub\Desktop\Divinity II - Ego Draconis.lnk
2013-12-08 00:02 - 2013-12-08 00:02 - 00000000 ____D C:\ProgramData\Divinity 2
2013-12-03 11:31 - 2012-03-10 00:37 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-03 11:16 - 2013-12-03 11:15 - 00000000 ____D C:\Users\Jakub\AppData\Local\Risen
2013-12-03 11:14 - 2013-12-03 11:14 - 00000330 _____ C:\Users\Jakub\Desktop\Risen – zástupce.lnk
2013-12-03 11:12 - 2012-04-04 20:36 - 00314016 _____ C:\Windows\system32\Drivers\atksgt.sys
2013-12-03 11:12 - 2012-04-04 20:36 - 00043680 _____ C:\Windows\system32\Drivers\lirsgt.sys
2013-12-01 10:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-30 15:13 - 2013-11-30 15:13 - 00002364 _____ C:\Users\Jakub\Desktop\Google Chrome.lnk
2013-11-30 15:13 - 2013-11-30 15:13 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-11-30 15:13 - 2013-11-30 15:12 - 34548576 _____ (Google Inc.) C:\Users\Jakub\Desktop\chrome_installer.exe
2013-11-30 15:13 - 2012-06-29 14:35 - 00000000 ____D C:\Users\Jakub\AppData\Local\Google
2013-11-29 19:06 - 2013-11-29 11:06 - 00000000 ____D C:\Program Files (x86)\SecretSauce
2013-11-29 11:12 - 2013-11-29 11:05 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-11-29 11:09 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\Mobogenie
2013-11-29 11:09 - 2013-11-29 11:07 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\Documents\Mobogenie
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\AppData\Local\cache
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 ____D C:\Users\Jakub\.android
2013-11-29 11:08 - 2013-11-29 11:08 - 00000000 _____ C:\Users\Jakub\daemonprocess.txt
2013-11-29 11:05 - 2013-11-29 11:05 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-11-26 12:54 - 2013-12-12 13:03 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 11:19 - 2013-12-12 13:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 11:18 - 2013-12-12 13:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 11:11 - 2013-12-12 13:03 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 10:48 - 2013-12-12 13:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 10:46 - 2013-12-12 13:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 10:41 - 2013-12-12 13:03 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:29 - 2013-12-12 13:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:27 - 2013-12-12 13:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 10:23 - 2013-12-12 13:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 10:21 - 2013-12-12 13:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 10:18 - 2013-12-12 13:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:18 - 2013-12-12 13:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 10:16 - 2013-12-12 13:03 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:57 - 2013-12-12 13:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-12 13:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 09:38 - 2013-12-12 13:03 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 09:35 - 2013-12-12 13:03 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:32 - 2013-12-12 13:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 09:28 - 2013-12-12 13:03 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 09:16 - 2013-12-12 13:03 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-12 13:03 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-12 13:03 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-12 13:03 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-12 13:03 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-12 13:03 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:40 - 2013-12-12 13:03 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-12 13:03 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-12 13:03 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-12 13:03 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-12 13:03 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-25 11:47 - 2013-11-25 11:47 - 00000980 _____ C:\Users\Jakub\Desktop\Wolverine – zástupce.lnk
2013-11-24 18:22 - 2013-11-24 18:22 - 00000000 ____D C:\Users\Jakub\Documents\Wolverine
2013-11-24 18:19 - 2013-11-24 18:19 - 00000000 ____D C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP
2013-11-23 19:26 - 2013-12-12 12:13 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 18:47 - 2013-12-12 12:13 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-23 12:06 - 2013-11-23 12:06 - 00002914 _____ C:\Windows\System32\Tasks\{13003E39-C3EE-4ED6-81D6-FA1D1D93818E}
2013-11-23 12:00 - 2013-11-23 12:00 - 00000594 _____ C:\Users\Public\Desktop\Spuštění Bad Boys 2.lnk
2013-11-23 09:23 - 2012-03-09 23:26 - 00000000 ____D C:\Users\Jakub\AppData\Local\Adobe
2013-11-23 09:19 - 2013-11-23 09:19 - 00000000 ____D C:\ProgramData\McAfee
2013-11-22 22:35 - 2013-11-22 21:30 - 00003339 _____ C:\Windows\wininit.ini
2013-11-22 21:30 - 2013-11-22 19:04 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-22 21:30 - 2012-07-12 21:40 - 00000000 ____D C:\Program Files\Web Assistant
2013-11-22 19:21 - 2013-11-22 19:21 - 00000000 ____D C:\Users\Jakub\Documents\ProcAlyzer Dumps
2013-11-22 19:10 - 2013-11-22 19:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-22 19:04 - 2013-11-22 19:04 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-22 19:04 - 2013-11-22 19:04 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-11-22 18:55 - 2013-11-22 18:53 - 46988968 _____ C:\Users\Jakub\Downloads\spybot-2.2.exe
2013-11-22 14:48 - 2012-03-10 01:17 - 00007644 _____ C:\Users\Jakub\AppData\Local\resmon.resmoncfg
2013-11-19 23:18 - 2013-11-19 23:17 - 00000000 ____D C:\Users\Jakub\Documents\Shadow Warrior
2013-11-19 11:21 - 2012-03-09 23:33 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\ProgramData\1926068.bat
C:\ProgramData\1926068.pad
C:\ProgramData\1926068.reg
C:\ProgramData\req2dz.reg
C:\Users\Jakub\jagex_cl_runescape_LIVE.dat
C:\Users\Jakub\jagex_cl_runescape_LIVE1.dat
C:\Users\Jakub\jagex_cl_runescape_LIVE_BETA.dat
C:\Users\Jakub\random.dat
Some content of TEMP:
====================
C:\Users\Jakub\AppData\Local\Temp\A~NSISu_.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jakub\Desktop" je 2602 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jakub^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regmonstd.lnk
C:\Windows\System32\rundll32.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================