Prosim o kontrolu logu
Napsal: 09 led 2014 00:27
Dobry den poprosil by som o kontrolu cisto z prevencneho dovodu aj ked mam pocit ze pc reaguje pomalsie ako by mal avsak snazim sa co tyzden upratovat s ccleanerom aspon. Dakujem velmi pekne.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by jurtan (administrator) on JURTAN-MSI on 08-01-2014 23:20:52
Running from C:\Users\jurtan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
() C:\Program Files (x86)\lucky leap\updateluckyleap.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
() C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor)
HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-29] (AVAST Software)
HKCU\...\Run: [Google Update] - C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-08-12] (Google Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\jurtan\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\Mcx1-JURTAN-MSI\...\Winlogon: [Shell] C:\windows\eHome\McrMgr.exe [343552 2009-07-14] (Microsoft Corporation) <==== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB02B705CB351CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - DefaultScope {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {F5A7009E-B064-432B-AB20-12204AB6989A} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: lucky leap - {d77aa852-def3-43cb-a3f5-bd679de72f32} - C:\Program Files (x86)\lucky leap\luckyleapBHO.dll (luckyleap)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default
FF user.js: detected! => C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\staged
FF Extension: Adblock Plus - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=
CHR RestoreOnStartup: "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: mysearchdial.com
CHR DefaultSearchProvider: Mysearchdial
CHR DefaultSearchURL: http://start.mysearchdial.com/results.p ... 043553&ir=
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\jurtan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Google Talk Plugin) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Extension: (Google Docs) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (lucky leap) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.10_0
CHR Extension: (Gmail) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKLM-x32\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files (x86)\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx
CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43624 2012-08-14] (ArcSoft, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-29] (AVAST Software)
S2 BitMng; C:\windows\BitAdmin.exe [4279552 2013-12-28] ()
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1444120 2013-12-02] (Trusteer Ltd.)
R2 Update lucky leap; C:\Program Files (x86)\lucky leap\updateluckyleap.exe [66336 2013-11-07] ()
R2 Util lucky leap; C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe [66336 2013-11-07] ()
R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2013-12-29] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1034464 2013-12-29] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [422216 2013-12-29] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [79672 2013-12-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-29] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-27] (NVIDIA Corporation)
S1 PQNTDrv; C:\Windows\SysWow64\Drivers\PQNTDrv.sys [4228 2003-03-14] (PowerQuest Corporation)
R1 RapportCerberus_59849; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [606672 2013-10-27] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [282648 2013-12-02] (Trusteer Ltd.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [316248 2013-12-02] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [397784 2013-12-02] (Trusteer Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2014-01-01] ()
U3 aaz1tgtw; C:\Windows\System32\Drivers\aaz1tgtw.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 23:20 - 2014-01-08 23:21 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-08 18:37 - 00001680 _____ C:\windows\setupact.log
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-01 11:59 - 2014-01-08 18:38 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-01 11:59 - 2014-01-03 18:35 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-01 11:59 - 2014-01-03 18:20 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:51 - 2014-01-01 00:52 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 15:20 - 2012-10-08 02:51 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Trusteer
2013-12-30 15:20 - 2009-08-14 09:43 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\IsolatedStorage
2013-12-30 15:20 - 2009-08-14 09:39 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\kidoz.52BCFEE1FEAB03D960EAF75B15C2A56D33E8320D.1
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Macromedia
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Adobe
2013-12-30 15:20 - 2009-08-14 09:36 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Skype
2013-12-30 15:20 - 2009-08-14 09:35 - 00067872 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-30 15:20 - 2009-08-14 09:35 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\SRS Labs
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\Documents\My Print Creations
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:30 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:28 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-30 15:20 - 2009-08-14 09:21 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Microsoft Help
2013-12-30 15:20 - 2009-07-14 05:09 - 00001449 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00001415 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00000020 ___SH C:\Users\Mcx1-JURTAN-MSI\ntuser.ini
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 15:20 - 2009-07-14 04:54 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-30 15:20 - 2009-07-14 04:49 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-30 12:03 - 2013-12-30 14:06 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-29 14:28 - 2013-12-29 14:29 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-13 01:27 - 2013-05-10 05:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2013-12-13 01:27 - 2013-05-10 05:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2013-12-13 01:24 - 2013-11-26 11:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-13 01:24 - 2013-11-26 10:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 10:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2013-12-13 01:24 - 2013-11-26 10:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-13 01:24 - 2013-11-26 09:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-12-13 01:24 - 2013-11-26 09:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2013-12-13 01:24 - 2013-11-26 09:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-13 01:24 - 2013-11-26 09:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 09:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-12-13 01:24 - 2013-11-26 09:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 09:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-12-13 01:24 - 2013-11-26 09:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-12-13 01:24 - 2013-11-26 09:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2013-12-13 01:24 - 2013-11-26 09:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-13 01:24 - 2013-11-26 08:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-13 01:24 - 2013-11-26 08:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 08:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-12-13 01:24 - 2013-11-26 08:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-12 13:37 - 2013-11-23 18:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-12 13:37 - 2013-11-23 17:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-12 13:37 - 2013-11-12 02:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-12-12 13:37 - 2013-11-12 02:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-12-12 13:37 - 2013-10-30 02:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-12 13:37 - 2013-10-30 02:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-12 13:37 - 2013-10-30 01:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-12 13:37 - 2013-10-19 02:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-12 13:37 - 2013-10-19 01:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-12 13:36 - 2013-10-12 02:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-12 13:36 - 2013-10-12 02:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-12 13:36 - 2013-10-12 01:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-12 13:36 - 2013-10-04 02:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2013-12-12 13:36 - 2013-10-04 01:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
==================== One Month Modified Files and Folders =======
2014-01-08 23:21 - 2014-01-08 23:20 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-08 23:08 - 2013-09-18 20:43 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-08 23:07 - 2013-09-18 20:43 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-08 23:05 - 2013-08-12 08:49 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
2014-01-08 23:05 - 2013-03-15 23:46 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 22:09 - 2013-03-24 08:37 - 01999152 _____ C:\windows\WindowsUpdate.log
2014-01-08 21:59 - 2009-07-14 03:20 - 00000000 ____D C:\windows\system32\NDF
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:38 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-08 18:37 - 2014-01-04 06:54 - 00001680 _____ C:\windows\setupact.log
2014-01-08 18:37 - 2013-06-30 00:01 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 18:37 - 2009-07-14 05:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-08 07:05 - 2013-08-12 08:49 - 00000860 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
2014-01-08 00:10 - 2013-09-18 20:45 - 00002193 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 13:39 - 2012-09-13 14:55 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2014-01-06 07:01 - 2009-07-14 05:13 - 00779092 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-03 18:35 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-03 18:20 - 2014-01-01 11:59 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 12:07 - 2012-11-28 23:36 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\DAEMON Tools Lite
2014-01-01 12:01 - 2012-11-11 23:42 - 00000000 ____D C:\Users\jurtan\AppData\Local\cache
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 11:59 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan
2014-01-01 01:12 - 2009-08-14 09:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:52 - 2014-01-01 00:51 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 14:37 - 2013-04-28 11:35 - 00004608 _____ C:\Users\jurtan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-30 14:06 - 2013-12-30 12:03 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-30 13:14 - 2012-09-13 23:08 - 00000000 ___RD C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 12:03 - 2009-07-14 03:20 - 00000000 ___HD C:\windows\system32\GroupPolicy
2013-12-29 14:29 - 2013-12-29 14:28 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-29 14:29 - 2013-03-31 07:26 - 00001976 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-29 14:28 - 2013-03-15 05:35 - 00207904 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 01034464 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00422216 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00334136 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-29 14:28 - 2012-09-13 14:55 - 00078648 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-28 12:03 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\ArcSoft
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:58 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Local\ArcSoft
2013-12-28 11:58 - 2009-08-14 09:30 - 00000000 ____D C:\ProgramData\ArcSoft
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-28 11:57 - 2009-08-14 09:29 - 00000000 ____D C:\Program Files (x86)\ArcSoft
2013-12-27 13:06 - 2013-06-30 00:02 - 00000000 ____D C:\Users\UpdatusUser.jurtan-msi
2013-12-24 09:19 - 2012-09-13 14:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-14 13:50 - 2013-07-16 15:59 - 00000000 ____D C:\windows\system32\MRT
2013-12-14 13:48 - 2012-09-14 07:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-14 08:27 - 2009-07-14 05:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2013-12-14 00:33 - 2009-07-14 03:20 - 00000000 ____D C:\windows\rescache
2013-12-13 13:00 - 2009-07-14 04:45 - 00363008 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 01:26 - 2009-08-14 09:21 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-10 21:05 - 2013-03-15 23:46 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:05 - 2012-09-13 21:59 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:05 - 2012-09-13 21:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-09 09:58 - 2009-07-14 05:08 - 00032620 _____ C:\windows\Tasks\SCHEDLGU.TXT
ZeroAccess:
C:\Windows\Installer\{9e5eb2ba-c9bf-e656-3b47-38699ca6115f}
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\jurtan\Desktop" je 1477 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by jurtan (administrator) on JURTAN-MSI on 08-01-2014 23:20:52
Running from C:\Users\jurtan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
() C:\Program Files (x86)\lucky leap\updateluckyleap.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
() C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor)
HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-29] (AVAST Software)
HKCU\...\Run: [Google Update] - C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-08-12] (Google Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\jurtan\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\Mcx1-JURTAN-MSI\...\Winlogon: [Shell] C:\windows\eHome\McrMgr.exe [343552 2009-07-14] (Microsoft Corporation) <==== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB02B705CB351CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - DefaultScope {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {F5A7009E-B064-432B-AB20-12204AB6989A} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: lucky leap - {d77aa852-def3-43cb-a3f5-bd679de72f32} - C:\Program Files (x86)\lucky leap\luckyleapBHO.dll (luckyleap)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default
FF user.js: detected! => C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\staged
FF Extension: Adblock Plus - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=
CHR RestoreOnStartup: "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: mysearchdial.com
CHR DefaultSearchProvider: Mysearchdial
CHR DefaultSearchURL: http://start.mysearchdial.com/results.p ... 043553&ir=
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\jurtan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Google Talk Plugin) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Extension: (Google Docs) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (lucky leap) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.10_0
CHR Extension: (Gmail) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKLM-x32\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files (x86)\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx
CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43624 2012-08-14] (ArcSoft, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-29] (AVAST Software)
S2 BitMng; C:\windows\BitAdmin.exe [4279552 2013-12-28] ()
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1444120 2013-12-02] (Trusteer Ltd.)
R2 Update lucky leap; C:\Program Files (x86)\lucky leap\updateluckyleap.exe [66336 2013-11-07] ()
R2 Util lucky leap; C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe [66336 2013-11-07] ()
R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2013-12-29] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1034464 2013-12-29] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [422216 2013-12-29] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [79672 2013-12-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-29] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-27] (NVIDIA Corporation)
S1 PQNTDrv; C:\Windows\SysWow64\Drivers\PQNTDrv.sys [4228 2003-03-14] (PowerQuest Corporation)
R1 RapportCerberus_59849; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [606672 2013-10-27] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [282648 2013-12-02] (Trusteer Ltd.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [316248 2013-12-02] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [397784 2013-12-02] (Trusteer Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2014-01-01] ()
U3 aaz1tgtw; C:\Windows\System32\Drivers\aaz1tgtw.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 23:20 - 2014-01-08 23:21 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-08 18:37 - 00001680 _____ C:\windows\setupact.log
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-01 11:59 - 2014-01-08 18:38 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-01 11:59 - 2014-01-03 18:35 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-01 11:59 - 2014-01-03 18:20 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:51 - 2014-01-01 00:52 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 15:20 - 2012-10-08 02:51 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Trusteer
2013-12-30 15:20 - 2009-08-14 09:43 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\IsolatedStorage
2013-12-30 15:20 - 2009-08-14 09:39 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\kidoz.52BCFEE1FEAB03D960EAF75B15C2A56D33E8320D.1
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Macromedia
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Adobe
2013-12-30 15:20 - 2009-08-14 09:36 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Skype
2013-12-30 15:20 - 2009-08-14 09:35 - 00067872 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-30 15:20 - 2009-08-14 09:35 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\SRS Labs
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\Documents\My Print Creations
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:30 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:28 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-30 15:20 - 2009-08-14 09:21 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Microsoft Help
2013-12-30 15:20 - 2009-07-14 05:09 - 00001449 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00001415 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00000020 ___SH C:\Users\Mcx1-JURTAN-MSI\ntuser.ini
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 15:20 - 2009-07-14 04:54 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-30 15:20 - 2009-07-14 04:49 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-30 12:03 - 2013-12-30 14:06 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-29 14:28 - 2013-12-29 14:29 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-13 01:27 - 2013-05-10 05:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2013-12-13 01:27 - 2013-05-10 05:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2013-12-13 01:24 - 2013-11-26 11:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-13 01:24 - 2013-11-26 10:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 10:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2013-12-13 01:24 - 2013-11-26 10:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-13 01:24 - 2013-11-26 09:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-12-13 01:24 - 2013-11-26 09:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2013-12-13 01:24 - 2013-11-26 09:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-13 01:24 - 2013-11-26 09:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 09:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-12-13 01:24 - 2013-11-26 09:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 09:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-12-13 01:24 - 2013-11-26 09:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-12-13 01:24 - 2013-11-26 09:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2013-12-13 01:24 - 2013-11-26 09:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-13 01:24 - 2013-11-26 08:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-13 01:24 - 2013-11-26 08:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 08:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-12-13 01:24 - 2013-11-26 08:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-12 13:37 - 2013-11-23 18:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-12 13:37 - 2013-11-23 17:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-12 13:37 - 2013-11-12 02:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-12-12 13:37 - 2013-11-12 02:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-12-12 13:37 - 2013-10-30 02:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-12 13:37 - 2013-10-30 02:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-12 13:37 - 2013-10-30 01:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-12 13:37 - 2013-10-19 02:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-12 13:37 - 2013-10-19 01:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-12 13:36 - 2013-10-12 02:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-12 13:36 - 2013-10-12 02:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-12 13:36 - 2013-10-12 01:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-12 13:36 - 2013-10-04 02:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2013-12-12 13:36 - 2013-10-04 01:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
==================== One Month Modified Files and Folders =======
2014-01-08 23:21 - 2014-01-08 23:20 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-08 23:08 - 2013-09-18 20:43 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-08 23:07 - 2013-09-18 20:43 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-08 23:05 - 2013-08-12 08:49 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
2014-01-08 23:05 - 2013-03-15 23:46 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 22:09 - 2013-03-24 08:37 - 01999152 _____ C:\windows\WindowsUpdate.log
2014-01-08 21:59 - 2009-07-14 03:20 - 00000000 ____D C:\windows\system32\NDF
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:38 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-08 18:37 - 2014-01-04 06:54 - 00001680 _____ C:\windows\setupact.log
2014-01-08 18:37 - 2013-06-30 00:01 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 18:37 - 2009-07-14 05:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-08 07:05 - 2013-08-12 08:49 - 00000860 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
2014-01-08 00:10 - 2013-09-18 20:45 - 00002193 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 13:39 - 2012-09-13 14:55 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2014-01-06 07:01 - 2009-07-14 05:13 - 00779092 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-03 18:35 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-03 18:20 - 2014-01-01 11:59 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 12:07 - 2012-11-28 23:36 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\DAEMON Tools Lite
2014-01-01 12:01 - 2012-11-11 23:42 - 00000000 ____D C:\Users\jurtan\AppData\Local\cache
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 11:59 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan
2014-01-01 01:12 - 2009-08-14 09:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:52 - 2014-01-01 00:51 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 14:37 - 2013-04-28 11:35 - 00004608 _____ C:\Users\jurtan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-30 14:06 - 2013-12-30 12:03 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-30 13:14 - 2012-09-13 23:08 - 00000000 ___RD C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 12:03 - 2009-07-14 03:20 - 00000000 ___HD C:\windows\system32\GroupPolicy
2013-12-29 14:29 - 2013-12-29 14:28 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-29 14:29 - 2013-03-31 07:26 - 00001976 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-29 14:28 - 2013-03-15 05:35 - 00207904 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 01034464 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00422216 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00334136 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-29 14:28 - 2012-09-13 14:55 - 00078648 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-28 12:03 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\ArcSoft
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:58 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Local\ArcSoft
2013-12-28 11:58 - 2009-08-14 09:30 - 00000000 ____D C:\ProgramData\ArcSoft
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-28 11:57 - 2009-08-14 09:29 - 00000000 ____D C:\Program Files (x86)\ArcSoft
2013-12-27 13:06 - 2013-06-30 00:02 - 00000000 ____D C:\Users\UpdatusUser.jurtan-msi
2013-12-24 09:19 - 2012-09-13 14:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-14 13:50 - 2013-07-16 15:59 - 00000000 ____D C:\windows\system32\MRT
2013-12-14 13:48 - 2012-09-14 07:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-14 08:27 - 2009-07-14 05:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2013-12-14 00:33 - 2009-07-14 03:20 - 00000000 ____D C:\windows\rescache
2013-12-13 13:00 - 2009-07-14 04:45 - 00363008 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 01:26 - 2009-08-14 09:21 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-10 21:05 - 2013-03-15 23:46 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:05 - 2012-09-13 21:59 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:05 - 2012-09-13 21:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-09 09:58 - 2009-07-14 05:08 - 00032620 _____ C:\windows\Tasks\SCHEDLGU.TXT
ZeroAccess:
C:\Windows\Installer\{9e5eb2ba-c9bf-e656-3b47-38699ca6115f}
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\jurtan\Desktop" je 1477 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================