FRST log - Policejní vir
Napsal: 19 led 2014 18:52
Dobrý den,
Chtěla bych Vás poprosit, jestli byste mi nepomohli? Můj počítač počítač byl napadený policejním virem a chtějí po mě zaplatit 2000,- za nějaké nesmyslné porušení. Zároveň bych Vás chtěla poprosit, zda by nešel můj počítač vyčistit od podobné havěti?
Předem děkuji za pomoc.
Petra
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2014 03
Ran by Petra (administrator) on PETRA-PC on 19-01-2014 18:41:57
Running from C:\Users\Petra\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Oceanis) C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AdminService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Symantec Corporation) C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Atheros Communications) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
() C:\Users\Petra\KoopP7BNExtern\KoopPDFServerSA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-08-03] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files\Bluetooth Suite\BtvStack.exe [486560 2010-09-27] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240 2010-09-27] (Atheros Commnucations)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [SSDMonitor] - C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-04-26] (PC Tools)
HKLM\...\Run: [RMAlert] - C:\Program Files\PC Tools Registry Mechanic\Alert.exe [1318872 2012-04-26] (PC Tools)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Facebook Update] - C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-13] (Facebook Inc.)
HKCU\...\Run: [SpeedUpMyPC] - C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe [406936 2012-09-28] (Uniblue Systems Ltd)
HKCU\...\Run: [Google Update] - C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-03-24] (Google Inc.)
HKCU\...\Winlogon: [Shell] C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe [115888 2009-12-10] (Oceanis) <==== ATTENTION
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kooperativa - PDF Server.lnk
ShortcutTarget: Kooperativa - PDF Server.lnk -> C:\Users\Petra\KoopP7BNExtern\KoopPDFServerSA.exe ()
Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
URLSearchHook: HKCU - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Windows 7 Starter Helper - {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - C:\Program Files\Oceanis\SystemSetting\StarterHelper.dll (Oceanis)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
FireFox:
========
FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default
FF user.js: detected! => C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Petra\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Petra\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Petra\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: uTorrentBar Community Toolbar - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default\Extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2011-07-30]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-06-22]
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Petra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (AT_LillyPulitzer) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbpppaoddgakkggpcadaefofdnbmfkcm [2011-04-01]
CHR Extension: (YouTube) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-16]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2011-06-24]
CHR Extension: (Gmail) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\Petra\AppData\Local\Temp\crxB8F1.tmp [2011-12-16]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-05-23]
CHR StartMenuInternet: Google Chrome - C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-06-11] (Acer Incorporated)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 NOBU; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2057560 2010-06-01] (Symantec Corporation)
R2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-04-26] (PC Tools)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
S3 WMZuneComm; C:\Program Files\WMZuneComm.exe [268512 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; C:\Program Files\ZuneNss.exe [6363872 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; C:\Program Files\ZuneWlanCfgSvc.exe [444640 2011-08-05] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-09-27] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-09-27] (Windows (R) Win 7 DDK provider)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [260968 2010-09-27] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [26984 2010-09-27] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [178024 2010-09-27] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [51560 2010-09-27] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143336 2010-09-27] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [242024 2010-09-27] (Atheros)
S3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-17] (ENE Technology Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 18:41 - 2014-01-19 18:43 - 00016480 _____ C:\Users\Petra\Desktop\FRST.txt
2014-01-19 18:40 - 2014-01-19 18:40 - 00000000 ____D C:\FRST
2014-01-19 18:20 - 2014-01-19 18:20 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
2014-01-19 18:19 - 2014-01-19 18:19 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 137955.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 740027.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 189522.crdownload
2014-01-19 18:16 - 2014-01-19 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 961838.crdownload
2014-01-19 18:14 - 2014-01-19 18:14 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 947217.crdownload
2014-01-19 18:13 - 2014-01-19 18:13 - 01221120 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe
2014-01-19 18:13 - 2014-01-19 18:13 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 250317.crdownload
2014-01-16 19:50 - 2014-01-16 19:50 - 00166912 _____ C:\Users\Petra\Downloads\P13_Platebni_instrumenty.ppt
2014-01-16 19:49 - 2014-01-16 19:49 - 00360448 _____ C:\Users\Petra\Downloads\SERWATKA_MEO_Obchodn_z_vazkov_vztahy.ppt
2014-01-15 21:41 - 2014-01-15 21:41 - 00219648 _____ C:\Users\Petra\Downloads\baf24.ppt
2014-01-14 19:08 - 2014-01-14 19:08 - 01492992 _____ C:\Users\Petra\Downloads\II.Platební styk.ppt
2014-01-14 18:59 - 2014-01-14 18:59 - 01511424 _____ C:\Users\Petra\Downloads\Přednáška č9.ppt
2014-01-14 16:53 - 2014-01-14 16:53 - 00115712 _____ C:\Users\Petra\Downloads\Finan_n_deriv_ty.ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00558080 _____ C:\Users\Petra\Downloads\Obchodování s CP (3).ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP (2).ppt
2014-01-14 10:00 - 2014-01-14 10:01 - 00269824 _____ C:\Users\Petra\Downloads\Obchodování s CP (1).ppt
2014-01-14 00:04 - 2014-01-14 00:04 - 00374784 _____ C:\Users\Petra\Downloads\Finance a úvěr př.č 11.ppt
2014-01-13 23:35 - 2014-01-13 23:35 - 00450560 _____ C:\Users\Petra\Downloads\Finance a úvěr př.7.ppt
2014-01-13 22:38 - 2014-01-13 22:38 - 00457216 _____ C:\Users\Petra\Downloads\Kolektivní investováníppt.moodleppt.ppt
2014-01-13 21:51 - 2014-01-13 21:51 - 04246760 _____ C:\Users\Petra\Downloads\Příklady finance a úvět.rar
2014-01-13 16:10 - 2014-01-13 17:36 - 768739080 _____ C:\Users\Petra\Downloads\Twilight-saga---Rozbřesk-1.část-CZ.avi
2014-01-13 10:30 - 2014-01-13 10:30 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00228864 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_klady_FU_D_lka_i.ppt.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00161792 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._.5pptmoodle.ppt
2014-01-13 09:24 - 2014-01-13 09:24 - 00253952 _____ C:\Users\Petra\Downloads\Cvčení FU úvěrový proces.ppt
2014-01-12 15:25 - 2014-01-12 17:57 - 1353013782 _____ C:\Users\Petra\Downloads\Twilight-saga---Zatmeni-CZ.avi
2014-01-12 09:40 - 2014-01-12 09:40 - 00462848 _____ C:\Users\Petra\Downloads\Finance a úvěr př.3.ppt
2014-01-12 09:40 - 2014-01-12 09:40 - 00128512 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._4.moodleppt.ppt
2014-01-03 19:26 - 2014-01-03 19:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 19:26 - 2012-09-27 01:30 - 00100256 _____ (HP) C:\Windows\system32\HPSIsvc.exe
2014-01-03 19:17 - 2014-01-03 19:17 - 00000000 ____D C:\Program Files\HP
2014-01-03 19:17 - 2012-09-26 06:45 - 00048128 _____ C:\Windows\system32\HP1100SMs.dll
2014-01-03 19:17 - 2012-08-31 15:01 - 01511424 _____ C:\Windows\system32\HP1100SM.EXE
2014-01-03 19:17 - 2012-08-31 15:01 - 00151552 _____ C:\Windows\system32\HP1100LM.DLL
2014-01-03 19:17 - 2012-08-31 08:10 - 00284160 _____ C:\Windows\system32\mvhlewsi.dll
2014-01-02 13:40 - 2014-01-02 13:40 - 00124520 _____ C:\Users\Petra\Downloads\02.zip
2013-12-28 13:09 - 2013-12-28 13:09 - 00747906 _____ C:\Users\Petra\Downloads\resenytesta(czuborec.cz-4o8i6).jpg.zip
2013-12-27 12:27 - 2013-12-27 12:27 - 01845545 _____ C:\Users\Petra\Downloads\ekonomieteor.otazky(czuborec.cz-qt5ce).rar
2013-12-27 12:17 - 2013-12-27 12:17 - 08385747 _____ C:\Users\Petra\Downloads\Ek-prednasky.rar
==================== One Month Modified Files and Folders =======
2014-01-19 18:43 - 2014-01-19 18:41 - 00016480 _____ C:\Users\Petra\Desktop\FRST.txt
2014-01-19 18:40 - 2014-01-19 18:40 - 00000000 ____D C:\FRST
2014-01-19 18:39 - 2010-09-17 10:43 - 00000000 ____D C:\ProgramData\Adobe
2014-01-19 18:39 - 2010-09-17 10:42 - 00000000 ____D C:\Program Files\Common Files\Adobe
2014-01-19 18:38 - 2010-11-13 09:23 - 01148085 _____ C:\Windows\WindowsUpdate.log
2014-01-19 18:37 - 2010-12-17 01:36 - 00000000 ____D C:\Users\Petra\AppData\Roaming\Adobe
2014-01-19 18:37 - 2010-09-17 10:42 - 00000000 ____D C:\Program Files\Adobe
2014-01-19 18:35 - 2010-12-18 17:47 - 00000000 ____D C:\Users\Petra\AppData\Local\Adobe
2014-01-19 18:30 - 2010-12-18 17:08 - 00000362 _____ C:\Windows\Tasks\Acer Registration - Reminder Recall task.job
2014-01-19 18:20 - 2014-01-19 18:20 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
2014-01-19 18:19 - 2014-01-19 18:19 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 137955.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 740027.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 189522.crdownload
2014-01-19 18:17 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 18:17 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 18:16 - 2014-01-19 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 961838.crdownload
2014-01-19 18:14 - 2014-01-19 18:14 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 947217.crdownload
2014-01-19 18:14 - 2012-07-04 18:23 - 00000960 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job
2014-01-19 18:13 - 2014-01-19 18:13 - 01221120 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe
2014-01-19 18:13 - 2014-01-19 18:13 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 250317.crdownload
2014-01-19 18:06 - 2011-03-24 19:35 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job
2014-01-19 18:06 - 2010-11-13 09:55 - 00000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2014-01-19 18:05 - 2012-10-05 13:43 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 18:05 - 2012-07-04 18:23 - 00000982 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job
2014-01-19 01:55 - 2011-03-24 19:35 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job
2014-01-17 17:41 - 2010-09-17 09:53 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-17 17:40 - 2012-07-15 20:23 - 00019934 _____ C:\Windows\setupact.log
2014-01-16 19:50 - 2014-01-16 19:50 - 00166912 _____ C:\Users\Petra\Downloads\P13_Platebni_instrumenty.ppt
2014-01-16 19:49 - 2014-01-16 19:49 - 00360448 _____ C:\Users\Petra\Downloads\SERWATKA_MEO_Obchodn_z_vazkov_vztahy.ppt
2014-01-16 13:26 - 2011-06-22 17:40 - 00000402 ____H C:\Windows\Tasks\Norton Security Scan for Petra.job
2014-01-16 11:59 - 2011-06-24 11:29 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2014-01-15 21:41 - 2014-01-15 21:41 - 00219648 _____ C:\Users\Petra\Downloads\baf24.ppt
2014-01-14 19:08 - 2014-01-14 19:08 - 01492992 _____ C:\Users\Petra\Downloads\II.Platební styk.ppt
2014-01-14 18:59 - 2014-01-14 18:59 - 01511424 _____ C:\Users\Petra\Downloads\Přednáška č9.ppt
2014-01-14 16:53 - 2014-01-14 16:53 - 00115712 _____ C:\Users\Petra\Downloads\Finan_n_deriv_ty.ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00558080 _____ C:\Users\Petra\Downloads\Obchodování s CP (3).ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP (2).ppt
2014-01-14 10:01 - 2014-01-14 10:00 - 00269824 _____ C:\Users\Petra\Downloads\Obchodování s CP (1).ppt
2014-01-14 00:04 - 2014-01-14 00:04 - 00374784 _____ C:\Users\Petra\Downloads\Finance a úvěr př.č 11.ppt
2014-01-13 23:35 - 2014-01-13 23:35 - 00450560 _____ C:\Users\Petra\Downloads\Finance a úvěr př.7.ppt
2014-01-13 22:38 - 2014-01-13 22:38 - 00457216 _____ C:\Users\Petra\Downloads\Kolektivní investováníppt.moodleppt.ppt
2014-01-13 21:51 - 2014-01-13 21:51 - 04246760 _____ C:\Users\Petra\Downloads\Příklady finance a úvět.rar
2014-01-13 17:36 - 2014-01-13 16:10 - 768739080 _____ C:\Users\Petra\Downloads\Twilight-saga---Rozbřesk-1.část-CZ.avi
2014-01-13 10:30 - 2014-01-13 10:30 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00228864 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_klady_FU_D_lka_i.ppt.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00161792 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._.5pptmoodle.ppt
2014-01-13 09:24 - 2014-01-13 09:24 - 00253952 _____ C:\Users\Petra\Downloads\Cvčení FU úvěrový proces.ppt
2014-01-12 19:39 - 2010-12-26 21:11 - 00000000 ____D C:\Users\Petra\AppData\Roaming\vlc
2014-01-12 17:57 - 2014-01-12 15:25 - 1353013782 _____ C:\Users\Petra\Downloads\Twilight-saga---Zatmeni-CZ.avi
2014-01-12 09:40 - 2014-01-12 09:40 - 00462848 _____ C:\Users\Petra\Downloads\Finance a úvěr př.3.ppt
2014-01-12 09:40 - 2014-01-12 09:40 - 00128512 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._4.moodleppt.ppt
2014-01-11 11:45 - 2013-12-13 12:44 - 00000000 ____D C:\Users\Petra\Documents\ČZU
2014-01-10 12:55 - 2012-06-18 11:23 - 00000000 ___RD C:\Users\Petra\SkyDrive
2014-01-09 08:35 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2014-01-08 08:49 - 2010-12-18 12:39 - 00000000 ____D C:\Users\Petra\AppData\Local\CrashDumps
2014-01-03 19:26 - 2014-01-03 19:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 19:17 - 2014-01-03 19:17 - 00000000 ____D C:\Program Files\HP
2014-01-02 13:40 - 2014-01-02 13:40 - 00124520 _____ C:\Users\Petra\Downloads\02.zip
2013-12-28 13:09 - 2013-12-28 13:09 - 00747906 _____ C:\Users\Petra\Downloads\resenytesta(czuborec.cz-4o8i6).jpg.zip
2013-12-27 12:27 - 2013-12-27 12:27 - 01845545 _____ C:\Users\Petra\Downloads\ekonomieteor.otazky(czuborec.cz-qt5ce).rar
2013-12-27 12:17 - 2013-12-27 12:17 - 08385747 _____ C:\Users\Petra\Downloads\Ek-prednasky.rar
2013-12-21 13:23 - 2012-08-18 21:26 - 00000000 ____D C:\Users\Petra\KoopP7BNExtern
2013-12-21 13:22 - 2012-06-06 10:29 - 00000272 _____ C:\Windows\Tasks\RMAutoUpdate.job
2013-12-21 13:21 - 2012-10-05 21:51 - 00000324 _____ C:\Windows\Tasks\SpeedUpMyPC.job
2013-12-21 13:21 - 2012-06-06 10:26 - 00000000 ____D C:\Program Files\PC Tools Registry Mechanic
2013-12-21 13:20 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-21 13:17 - 2012-09-23 15:58 - 148300202 _____ C:\Windows\MEMORY.DMP
Some content of TEMP:
====================
C:\Users\Petra\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
C:\Users\Petra\AppData\Local\Temp\KoopFlash10FF.exe
C:\Users\Petra\AppData\Local\Temp\KoopFlash10IE.exe
C:\Users\Petra\AppData\Local\Temp\siinst.exe
C:\Users\Petra\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Petra\AppData\Local\Temp\strings.dll
C:\Users\Petra\AppData\Local\Temp\tbuTor.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Acer Registration - Reminder Recall task.job => C:\Program Files\Acer\Registration\GREG.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job => C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job => C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job => C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job => C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Petra.job => C:\PROGRA~1\NORTON~2\Engine\311~1.6\Nss.exe
Task: C:\Windows\Tasks\RMAutoUpdate.job => C:\Program Files\PC Tools Registry Mechanic\SULauncher.exe
Task: C:\Windows\Tasks\SpeedUpMyPC.job => C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:E36F5B57
AlternateDataStreams: C:\ProgramData\TEMP:E3C56885
==================== Security Center ==================
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Petra\Desktop" je 2 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AndroidManager
C:\Program Files\Acer\Android Manager\AML.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecPMMUpdate
"C:\Program Files\EgisTec IPS\PmmUpdate.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisUpdate
"C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPatchData
C:\Program Files\Acer\Updater\iUpdate.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iSyncData
C:\Program Files\Acer\Android Manager\iSync.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon
C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Online Backup
C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyDrive
"C:\Users\Petra\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuiteTray
"C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
"C:\Program Files\ZuneLauncher.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Chtěla bych Vás poprosit, jestli byste mi nepomohli? Můj počítač počítač byl napadený policejním virem a chtějí po mě zaplatit 2000,- za nějaké nesmyslné porušení. Zároveň bych Vás chtěla poprosit, zda by nešel můj počítač vyčistit od podobné havěti?
Předem děkuji za pomoc.
Petra
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2014 03
Ran by Petra (administrator) on PETRA-PC on 19-01-2014 18:41:57
Running from C:\Users\Petra\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Oceanis) C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AdminService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Symantec Corporation) C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Atheros Communications) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
() C:\Users\Petra\KoopP7BNExtern\KoopPDFServerSA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-08-03] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files\Bluetooth Suite\BtvStack.exe [486560 2010-09-27] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240 2010-09-27] (Atheros Commnucations)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [SSDMonitor] - C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-04-26] (PC Tools)
HKLM\...\Run: [RMAlert] - C:\Program Files\PC Tools Registry Mechanic\Alert.exe [1318872 2012-04-26] (PC Tools)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Facebook Update] - C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-13] (Facebook Inc.)
HKCU\...\Run: [SpeedUpMyPC] - C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe [406936 2012-09-28] (Uniblue Systems Ltd)
HKCU\...\Run: [Google Update] - C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-03-24] (Google Inc.)
HKCU\...\Winlogon: [Shell] C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe [115888 2009-12-10] (Oceanis) <==== ATTENTION
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kooperativa - PDF Server.lnk
ShortcutTarget: Kooperativa - PDF Server.lnk -> C:\Users\Petra\KoopP7BNExtern\KoopPDFServerSA.exe ()
Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
URLSearchHook: HKCU - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Windows 7 Starter Helper - {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - C:\Program Files\Oceanis\SystemSetting\StarterHelper.dll (Oceanis)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
FireFox:
========
FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default
FF user.js: detected! => C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Petra\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Petra\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Petra\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: uTorrentBar Community Toolbar - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\gxxub46k.default\Extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2011-07-30]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-06-22]
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Petra\AppData\Local\Google\Chrome\Application\32.0.1700.76\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Petra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (AT_LillyPulitzer) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbpppaoddgakkggpcadaefofdnbmfkcm [2011-04-01]
CHR Extension: (YouTube) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-16]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2011-06-24]
CHR Extension: (Gmail) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\Petra\AppData\Local\Temp\crxB8F1.tmp [2011-12-16]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-05-23]
CHR StartMenuInternet: Google Chrome - C:\Users\Petra\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-06-11] (Acer Incorporated)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 NOBU; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2057560 2010-06-01] (Symantec Corporation)
R2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-04-26] (PC Tools)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
S3 WMZuneComm; C:\Program Files\WMZuneComm.exe [268512 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; C:\Program Files\ZuneNss.exe [6363872 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; C:\Program Files\ZuneWlanCfgSvc.exe [444640 2011-08-05] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-09-27] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-09-27] (Windows (R) Win 7 DDK provider)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [260968 2010-09-27] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [26984 2010-09-27] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [178024 2010-09-27] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [51560 2010-09-27] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143336 2010-09-27] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [242024 2010-09-27] (Atheros)
S3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-17] (ENE Technology Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 18:41 - 2014-01-19 18:43 - 00016480 _____ C:\Users\Petra\Desktop\FRST.txt
2014-01-19 18:40 - 2014-01-19 18:40 - 00000000 ____D C:\FRST
2014-01-19 18:20 - 2014-01-19 18:20 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
2014-01-19 18:19 - 2014-01-19 18:19 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 137955.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 740027.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 189522.crdownload
2014-01-19 18:16 - 2014-01-19 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 961838.crdownload
2014-01-19 18:14 - 2014-01-19 18:14 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 947217.crdownload
2014-01-19 18:13 - 2014-01-19 18:13 - 01221120 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe
2014-01-19 18:13 - 2014-01-19 18:13 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 250317.crdownload
2014-01-16 19:50 - 2014-01-16 19:50 - 00166912 _____ C:\Users\Petra\Downloads\P13_Platebni_instrumenty.ppt
2014-01-16 19:49 - 2014-01-16 19:49 - 00360448 _____ C:\Users\Petra\Downloads\SERWATKA_MEO_Obchodn_z_vazkov_vztahy.ppt
2014-01-15 21:41 - 2014-01-15 21:41 - 00219648 _____ C:\Users\Petra\Downloads\baf24.ppt
2014-01-14 19:08 - 2014-01-14 19:08 - 01492992 _____ C:\Users\Petra\Downloads\II.Platební styk.ppt
2014-01-14 18:59 - 2014-01-14 18:59 - 01511424 _____ C:\Users\Petra\Downloads\Přednáška č9.ppt
2014-01-14 16:53 - 2014-01-14 16:53 - 00115712 _____ C:\Users\Petra\Downloads\Finan_n_deriv_ty.ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00558080 _____ C:\Users\Petra\Downloads\Obchodování s CP (3).ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP (2).ppt
2014-01-14 10:00 - 2014-01-14 10:01 - 00269824 _____ C:\Users\Petra\Downloads\Obchodování s CP (1).ppt
2014-01-14 00:04 - 2014-01-14 00:04 - 00374784 _____ C:\Users\Petra\Downloads\Finance a úvěr př.č 11.ppt
2014-01-13 23:35 - 2014-01-13 23:35 - 00450560 _____ C:\Users\Petra\Downloads\Finance a úvěr př.7.ppt
2014-01-13 22:38 - 2014-01-13 22:38 - 00457216 _____ C:\Users\Petra\Downloads\Kolektivní investováníppt.moodleppt.ppt
2014-01-13 21:51 - 2014-01-13 21:51 - 04246760 _____ C:\Users\Petra\Downloads\Příklady finance a úvět.rar
2014-01-13 16:10 - 2014-01-13 17:36 - 768739080 _____ C:\Users\Petra\Downloads\Twilight-saga---Rozbřesk-1.část-CZ.avi
2014-01-13 10:30 - 2014-01-13 10:30 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00228864 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_klady_FU_D_lka_i.ppt.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00161792 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._.5pptmoodle.ppt
2014-01-13 09:24 - 2014-01-13 09:24 - 00253952 _____ C:\Users\Petra\Downloads\Cvčení FU úvěrový proces.ppt
2014-01-12 15:25 - 2014-01-12 17:57 - 1353013782 _____ C:\Users\Petra\Downloads\Twilight-saga---Zatmeni-CZ.avi
2014-01-12 09:40 - 2014-01-12 09:40 - 00462848 _____ C:\Users\Petra\Downloads\Finance a úvěr př.3.ppt
2014-01-12 09:40 - 2014-01-12 09:40 - 00128512 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._4.moodleppt.ppt
2014-01-03 19:26 - 2014-01-03 19:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 19:26 - 2012-09-27 01:30 - 00100256 _____ (HP) C:\Windows\system32\HPSIsvc.exe
2014-01-03 19:17 - 2014-01-03 19:17 - 00000000 ____D C:\Program Files\HP
2014-01-03 19:17 - 2012-09-26 06:45 - 00048128 _____ C:\Windows\system32\HP1100SMs.dll
2014-01-03 19:17 - 2012-08-31 15:01 - 01511424 _____ C:\Windows\system32\HP1100SM.EXE
2014-01-03 19:17 - 2012-08-31 15:01 - 00151552 _____ C:\Windows\system32\HP1100LM.DLL
2014-01-03 19:17 - 2012-08-31 08:10 - 00284160 _____ C:\Windows\system32\mvhlewsi.dll
2014-01-02 13:40 - 2014-01-02 13:40 - 00124520 _____ C:\Users\Petra\Downloads\02.zip
2013-12-28 13:09 - 2013-12-28 13:09 - 00747906 _____ C:\Users\Petra\Downloads\resenytesta(czuborec.cz-4o8i6).jpg.zip
2013-12-27 12:27 - 2013-12-27 12:27 - 01845545 _____ C:\Users\Petra\Downloads\ekonomieteor.otazky(czuborec.cz-qt5ce).rar
2013-12-27 12:17 - 2013-12-27 12:17 - 08385747 _____ C:\Users\Petra\Downloads\Ek-prednasky.rar
==================== One Month Modified Files and Folders =======
2014-01-19 18:43 - 2014-01-19 18:41 - 00016480 _____ C:\Users\Petra\Desktop\FRST.txt
2014-01-19 18:40 - 2014-01-19 18:40 - 00000000 ____D C:\FRST
2014-01-19 18:39 - 2010-09-17 10:43 - 00000000 ____D C:\ProgramData\Adobe
2014-01-19 18:39 - 2010-09-17 10:42 - 00000000 ____D C:\Program Files\Common Files\Adobe
2014-01-19 18:38 - 2010-11-13 09:23 - 01148085 _____ C:\Windows\WindowsUpdate.log
2014-01-19 18:37 - 2010-12-17 01:36 - 00000000 ____D C:\Users\Petra\AppData\Roaming\Adobe
2014-01-19 18:37 - 2010-09-17 10:42 - 00000000 ____D C:\Program Files\Adobe
2014-01-19 18:35 - 2010-12-18 17:47 - 00000000 ____D C:\Users\Petra\AppData\Local\Adobe
2014-01-19 18:30 - 2010-12-18 17:08 - 00000362 _____ C:\Windows\Tasks\Acer Registration - Reminder Recall task.job
2014-01-19 18:20 - 2014-01-19 18:20 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Desktop\FRSTLauncher (6).exe
2014-01-19 18:19 - 2014-01-19 18:19 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 137955.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 740027.crdownload
2014-01-19 18:17 - 2014-01-19 18:17 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 189522.crdownload
2014-01-19 18:17 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 18:17 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 18:16 - 2014-01-19 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 961838.crdownload
2014-01-19 18:14 - 2014-01-19 18:14 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 947217.crdownload
2014-01-19 18:14 - 2012-07-04 18:23 - 00000960 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job
2014-01-19 18:13 - 2014-01-19 18:13 - 01221120 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe
2014-01-19 18:13 - 2014-01-19 18:13 - 00112640 _____ (forum.viry.cz) C:\Users\Petra\Downloads\Nepotvrzeno 250317.crdownload
2014-01-19 18:06 - 2011-03-24 19:35 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job
2014-01-19 18:06 - 2010-11-13 09:55 - 00000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2014-01-19 18:05 - 2012-10-05 13:43 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 18:05 - 2012-07-04 18:23 - 00000982 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job
2014-01-19 01:55 - 2011-03-24 19:35 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job
2014-01-17 17:41 - 2010-09-17 09:53 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-17 17:40 - 2012-07-15 20:23 - 00019934 _____ C:\Windows\setupact.log
2014-01-16 19:50 - 2014-01-16 19:50 - 00166912 _____ C:\Users\Petra\Downloads\P13_Platebni_instrumenty.ppt
2014-01-16 19:49 - 2014-01-16 19:49 - 00360448 _____ C:\Users\Petra\Downloads\SERWATKA_MEO_Obchodn_z_vazkov_vztahy.ppt
2014-01-16 13:26 - 2011-06-22 17:40 - 00000402 ____H C:\Windows\Tasks\Norton Security Scan for Petra.job
2014-01-16 11:59 - 2011-06-24 11:29 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2014-01-15 21:41 - 2014-01-15 21:41 - 00219648 _____ C:\Users\Petra\Downloads\baf24.ppt
2014-01-14 19:08 - 2014-01-14 19:08 - 01492992 _____ C:\Users\Petra\Downloads\II.Platební styk.ppt
2014-01-14 18:59 - 2014-01-14 18:59 - 01511424 _____ C:\Users\Petra\Downloads\Přednáška č9.ppt
2014-01-14 16:53 - 2014-01-14 16:53 - 00115712 _____ C:\Users\Petra\Downloads\Finan_n_deriv_ty.ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00558080 _____ C:\Users\Petra\Downloads\Obchodování s CP (3).ppt
2014-01-14 10:01 - 2014-01-14 10:01 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP (2).ppt
2014-01-14 10:01 - 2014-01-14 10:00 - 00269824 _____ C:\Users\Petra\Downloads\Obchodování s CP (1).ppt
2014-01-14 00:04 - 2014-01-14 00:04 - 00374784 _____ C:\Users\Petra\Downloads\Finance a úvěr př.č 11.ppt
2014-01-13 23:35 - 2014-01-13 23:35 - 00450560 _____ C:\Users\Petra\Downloads\Finance a úvěr př.7.ppt
2014-01-13 22:38 - 2014-01-13 22:38 - 00457216 _____ C:\Users\Petra\Downloads\Kolektivní investováníppt.moodleppt.ppt
2014-01-13 21:51 - 2014-01-13 21:51 - 04246760 _____ C:\Users\Petra\Downloads\Příklady finance a úvět.rar
2014-01-13 17:36 - 2014-01-13 16:10 - 768739080 _____ C:\Users\Petra\Downloads\Twilight-saga---Rozbřesk-1.část-CZ.avi
2014-01-13 10:30 - 2014-01-13 10:30 - 00331776 _____ C:\Users\Petra\Downloads\Obchodování s CP.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00228864 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_klady_FU_D_lka_i.ppt.ppt
2014-01-13 10:24 - 2014-01-13 10:24 - 00161792 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._.5pptmoodle.ppt
2014-01-13 09:24 - 2014-01-13 09:24 - 00253952 _____ C:\Users\Petra\Downloads\Cvčení FU úvěrový proces.ppt
2014-01-12 19:39 - 2010-12-26 21:11 - 00000000 ____D C:\Users\Petra\AppData\Roaming\vlc
2014-01-12 17:57 - 2014-01-12 15:25 - 1353013782 _____ C:\Users\Petra\Downloads\Twilight-saga---Zatmeni-CZ.avi
2014-01-12 09:40 - 2014-01-12 09:40 - 00462848 _____ C:\Users\Petra\Downloads\Finance a úvěr př.3.ppt
2014-01-12 09:40 - 2014-01-12 09:40 - 00128512 _____ C:\Users\Petra\Downloads\Finance_a_v_r_p_._4.moodleppt.ppt
2014-01-11 11:45 - 2013-12-13 12:44 - 00000000 ____D C:\Users\Petra\Documents\ČZU
2014-01-10 12:55 - 2012-06-18 11:23 - 00000000 ___RD C:\Users\Petra\SkyDrive
2014-01-09 08:35 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2014-01-08 08:49 - 2010-12-18 12:39 - 00000000 ____D C:\Users\Petra\AppData\Local\CrashDumps
2014-01-03 19:26 - 2014-01-03 19:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 19:17 - 2014-01-03 19:17 - 00000000 ____D C:\Program Files\HP
2014-01-02 13:40 - 2014-01-02 13:40 - 00124520 _____ C:\Users\Petra\Downloads\02.zip
2013-12-28 13:09 - 2013-12-28 13:09 - 00747906 _____ C:\Users\Petra\Downloads\resenytesta(czuborec.cz-4o8i6).jpg.zip
2013-12-27 12:27 - 2013-12-27 12:27 - 01845545 _____ C:\Users\Petra\Downloads\ekonomieteor.otazky(czuborec.cz-qt5ce).rar
2013-12-27 12:17 - 2013-12-27 12:17 - 08385747 _____ C:\Users\Petra\Downloads\Ek-prednasky.rar
2013-12-21 13:23 - 2012-08-18 21:26 - 00000000 ____D C:\Users\Petra\KoopP7BNExtern
2013-12-21 13:22 - 2012-06-06 10:29 - 00000272 _____ C:\Windows\Tasks\RMAutoUpdate.job
2013-12-21 13:21 - 2012-10-05 21:51 - 00000324 _____ C:\Windows\Tasks\SpeedUpMyPC.job
2013-12-21 13:21 - 2012-06-06 10:26 - 00000000 ____D C:\Program Files\PC Tools Registry Mechanic
2013-12-21 13:20 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-21 13:17 - 2012-09-23 15:58 - 148300202 _____ C:\Windows\MEMORY.DMP
Some content of TEMP:
====================
C:\Users\Petra\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
C:\Users\Petra\AppData\Local\Temp\KoopFlash10FF.exe
C:\Users\Petra\AppData\Local\Temp\KoopFlash10IE.exe
C:\Users\Petra\AppData\Local\Temp\siinst.exe
C:\Users\Petra\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Petra\AppData\Local\Temp\strings.dll
C:\Users\Petra\AppData\Local\Temp\tbuTor.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Acer Registration - Reminder Recall task.job => C:\Program Files\Acer\Registration\GREG.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job => C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job => C:\Users\Petra\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000Core.job => C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1137310038-2637773365-2720436077-1000UA.job => C:\Users\Petra\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Petra.job => C:\PROGRA~1\NORTON~2\Engine\311~1.6\Nss.exe
Task: C:\Windows\Tasks\RMAutoUpdate.job => C:\Program Files\PC Tools Registry Mechanic\SULauncher.exe
Task: C:\Windows\Tasks\SpeedUpMyPC.job => C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:E36F5B57
AlternateDataStreams: C:\ProgramData\TEMP:E3C56885
==================== Security Center ==================
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Petra\Desktop" je 2 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AndroidManager
C:\Program Files\Acer\Android Manager\AML.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecPMMUpdate
"C:\Program Files\EgisTec IPS\PmmUpdate.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisUpdate
"C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPatchData
C:\Program Files\Acer\Updater\iUpdate.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iSyncData
C:\Program Files\Acer\Android Manager\iSync.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon
C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Online Backup
C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyDrive
"C:\Users\Petra\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuiteTray
"C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
"C:\Program Files\ZuneLauncher.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================