opakovaná infekce
Napsal: 22 led 2014 07:16
Dobrý den, prosím o pomoc. V posledních dnech mi po startu PC pokaždé ESET hlásil nález trojského koně (Boaxxe.BH.gen) a vyžadoval restart PC.
Včera mě to přestalo bavit, tak jsem nainstalovala ještě Malwarebytes antimalware, ktreý během úplné kontroly více než 100krát dal do karantény VirTool.VBcrypt, stále ve stejném umístění. Během této kontroly nastaly potíže se spouštěním programů (IE, word, kalkulačka...) A současně ESET hlásí potenciálně nechtěnou aplikaci Win32/Toolbar.widgi - tady tuším, že reaguje na ten Malwarebytes.
Momentálně mám znovu spuštěný PC, po startu nová hláška:
RegSVR32
.../adp_data-2_5.dll se nepodařilo načíst.
programy co se včera nespouštěly, jedou.
Předem děkuju za rady.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-01-2014
Ran by Martin (administrator) on VER on 22-01-2014 06:57:30
Running from C:\Users\Martin\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
(Acresso Software Inc.) C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
() C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Acresso Software Inc.) C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
() C:\Program Files\ESRI\License\arcgis9x\ARCGIS.EXE
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
() C:\Program Files\ICQ6Toolbar\ICQ Service.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(SafeNet, Inc) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
() C:\Program Files\ASUS\Turbo Key\TurboKey.exe
() C:\Program Files\ASUS\TurboV\TurboV.exe
(HP) C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Company) C:\Program Files\HP\hp laserjet m1522\hppfaxprintersrv.exe
() C:\Program Files\HP\HP UT\bin\hppusg.exe
(Mireo) C:\Program Files\Mio\MMD2\RunMMD.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Adobe Systems, Inc.) C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Bret Taylor) C:\Program Files\Bret Taylor\Stickies\Stickies.exe
(ICQ, LLC.) C:\Program Files\ICQ7.4\ICQ.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
(Panasonic Corporation) C:\Program Files\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [36X Raid Configurer] - C:\WINDOWS\System32\xRaidSetup.exe [1970176 2007-11-19] (JMicron Technology Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2011-01-31] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS4ServiceManager] - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [33570816 2009-01-09] (VIA Technologies, Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-01-12] (Hewlett-Packard)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2008-12-04] (Intel Corporation)
HKLM\...\Run: [JMB36X IDE Setup] - C:\WINDOWS\RaidTool\xInsIDE.exe [36864 2007-03-20] ()
HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [570664 2008-07-14] (Nero AG)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-06-28] (Cyberlink Corp.)
HKLM\...\Run: [Six Engine] - C:\Program Files\ASUS\Six Engine\SixEngine.exe [5993984 2009-02-10] ()
HKLM\...\Run: [Turbo Key] - C:\Program Files\ASUS\Turbo Key\TurboKey.exe [1753600 2009-02-17] ()
HKLM\...\Run: [TurboV] - C:\Program Files\ASUS\TurboV\TurboV.exe [5384192 2009-02-05] ()
HKLM\...\Run: [ToolBoxFX] - C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe [53248 2010-03-03] (HP)
HKLM\...\Run: [HP LaserJet M1522 MFP Series Fax] - C:\Program Files\HP\hp LaserJet M1522\hppfaxprintersrv.exe [2453504 2009-09-22] (Hewlett-Packard Company)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [HPUsageTracking] - C:\Program Files\HP\HP UT\bin\hppusg.exe [36864 2007-08-31] ()
HKLM\...\Run: [RunMMD] - C:\Program Files\Mio\MMD2\RunMMD.exe [49152 2010-05-17] (Mireo)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2219184 2011-01-12] (ESET)
HKLM\...\Run: [IndexSearch] - C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Program Files\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort12reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] - C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2010-12-02] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM\...\Run: [VX3000] - C:\Windows\vVX3000.exe [709992 2007-04-10] (Microsoft Corporation)
HKLM\...\Command Processor: <======= ATTENTION
HKCU\...\Run: [AdobeBridge] - C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe [13145448 2008-08-28] (Adobe Systems, Inc.)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-07-30] (Hewlett-Packard Company)
HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [433872 2011-10-21] (Sony Ericsson)
HKCU\...\Run: [Stickies] - C:\Program Files\Bret Taylor\Stickies\Stickies.exe [335872 2007-03-14] (Bret Taylor)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.4\ICQ.exe [119608 2011-04-12] (ICQ, LLC.)
HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKCU\...\Run: [GameXN GO] - C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-11-06] (EasyBits Software AS)
HKCU\...\Run: [Aslwworks] - regsvr32.exe C:\Users\Martin\AppData\Local\Aslwworks\adp_data-2_5.dll <===== ATTENTION
HKCU\...\Winlogon: [Shell] explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: HKCU - pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
URLSearchHook: HKCU - SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
SearchScopes: HKCU - DefaultScope {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {22CC10DF-C285-4EC4-8769-CC9F481F7874} URL = http://slovnik.seznam.cz/?lg=cz_en&wd={ ... rer:source?}
SearchScopes: HKCU - {3EC4DBFF-46C7-4964-AB26-60E942F7387C} URL = http://encyklopedie.seznam.cz/search?s= ... rer:source?}
SearchScopes: HKCU - {400375A6-E7C5-4CF5-8CB4-F18257510E53} URL = http://zbozi.seznam.cz/?q={searchTerms} ... rer:source?}
SearchScopes: HKCU - {4921EDF0-1C7B-456E-8F03-FC43C10A97AF} URL = http://www.mapy.cz/?query={searchTerms} ... rer:source?}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {75C3F1D5-F961-47FC-9C9F-5E573C85DDA6} URL = http://slovnik.seznam.cz/?lg=en_cz&wd={ ... rer:source?}
SearchScopes: HKCU - {9BA58561-8738-48B3-838D-5115098764CE} URL = http://www.firmy.cz/phr/{searchTerms}?p ... rer:source?}
SearchScopes: HKCU - {A3B1A68E-51A6-4355-BBD8-4F9F33248A0A} URL = http://search.seznam.cz/searchScreen?w= ... rer:source?}
SearchScopes: HKCU - {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... earchTerms}
SearchScopes: HKCU - {FC572E0F-A3C8-4FB4-B574-58E035F5A052} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No File
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: DeLorme Send To GPS - {FBAAD182-3C7A-4BC4-A5E9-207B8E0F02FD} - C:\Program Files\DeLorme\SendToGPS\PNPluginForIE.dll (DeLorme)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKLM - pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKCU - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKCU - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\..\Interfaces\{E6CB90A5-10A9-4717-B1F7-5FD9D66D9174}: [NameServer]212.96.161.6,212.96.160.7
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default
FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: ICQ Search
FF Homepage: hxxp://home.sweetim.com
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @delorme.com/SendToGPS - C:\Program Files\DeLorme\SendToGPS\nppnplugin.dll (DeLorme)
FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.449 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfiller.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\sweetim.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-09-28]
FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009-08-15]
FF Extension: SweetIM Toolbar for Firefox - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847} [2010-01-08]
FF Extension: 602XML Filler - C:\Program Files\Mozilla Firefox\extensions\xmlfiller@software602.cz [2010-11-22]
FF Extension: ICQ Toolbar - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010-08-12]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011-10-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [2009-08-14]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009-11-05]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [2010-04-01]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-08-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-06]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-05]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-09-19]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [2011-11-11]
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-08-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011-08-16]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Skype Toolbars) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8312_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Google\Chrome\Application\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Google\Chrome\Application\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: ( "name": "",) - C:\Program Files\Mozilla Firefox\plugins\npfiller.dll ()
CHR Plugin: (Microsoft Office 2003) - C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (getPlusPlus for Adobe 16241) - C:\Program Files\Mozilla Firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-15]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-15]
CHR Extension: (Skype Click to Call) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-10-12]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-15]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-09-21]
========================== Services (Whitelisted) =================
R2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [73728 2010-04-14] (Software602 a.s.)
R2 ArcGIS License Manager; C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe [1431440 2008-08-02] (Acresso Software Inc.)
R2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [86016 2008-08-15] ()
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [33584 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [810144 2011-01-12] (ESET)
S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [45816 2009-08-07] (NOS Microsystems Ltd.)
S2 gupdate1ca65f4cc6001b0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-11-15] (Google Inc.)
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [136192 2010-03-03] (HP)
R2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [222968 2009-06-01] ()
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2011-10-03] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
R2 SentinelProtectionServer; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [206400 2006-03-14] (SafeNet, Inc)
S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software)
S4 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [x]
==================== Drivers (Whitelisted) ====================
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] ()
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [137144 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [115008 2010-12-21] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [134000 2010-12-21] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33120 2010-12-21] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [41336 2010-12-21] (ESET)
R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2009-09-04] (Aladdin Knowledge Systems)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [82784 2008-11-21] (JMicron Technology Corp.)
R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [47104 2009-07-13] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-01-22] (Malwarebytes Corporation)
R3 monfilt; C:\Windows\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [993280 2008-12-19] (VIA Technologies, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-22 06:57 - 2014-01-22 06:57 - 00028380 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-22 06:57 - 2014-01-22 06:57 - 00000000 ____D C:\FRST
2014-01-22 06:55 - 2014-01-22 06:55 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-01-22 06:54 - 2014-01-22 06:54 - 01221632 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-22 06:26 - 2014-01-22 06:26 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-21 20:26 - 2014-01-21 20:26 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-21 20:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-15 21:10 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 21:10 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 21:10 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-27 18:01 - 2013-12-27 18:01 - 00000000 ____D C:\ProgramData\Panasonic
2013-12-27 17:50 - 2013-12-27 17:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Common Files\Panasonic
2013-12-27 17:49 - 2007-06-22 00:10 - 00501912 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICSDK2.dll
2013-12-27 17:49 - 2007-06-22 00:10 - 00000097 _____ C:\Windows\system32\PICSDK.ini
2013-12-27 17:49 - 2006-10-31 00:10 - 00120992 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\EpPicPrt.dll
2013-12-27 17:49 - 2006-10-31 00:10 - 00071840 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\EPPicMgr.dll
2013-12-27 17:49 - 2006-10-20 00:10 - 00108704 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICEntry.dll
2013-12-27 17:49 - 2006-10-20 00:10 - 00080024 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICSDK.dll
2013-12-27 17:49 - 2005-06-01 00:20 - 00111932 _____ C:\Windows\system32\EPPICPrinterDB.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00031053 _____ C:\Windows\system32\EPPICPattern131.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00027417 _____ C:\Windows\system32\EPPICPattern121.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00026154 _____ C:\Windows\system32\EPPICPattern1.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00024903 _____ C:\Windows\system32\EPPICPattern3.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00021390 _____ C:\Windows\system32\EPPICPattern5.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00020148 _____ C:\Windows\system32\EPPICPattern2.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00013732 _____ C:\Windows\system32\EPPICLocal_EN.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00011811 _____ C:\Windows\system32\EPPICPattern4.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00006442 _____ C:\Windows\system32\EPPICLocal_IT.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\system32\EPPICLocal_PT.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\system32\EPPICLocal_BP.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006335 _____ C:\Windows\system32\EPPICLocal_GE.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\system32\EPPICLocal_FR.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\system32\EPPICLocal_CF.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006122 _____ C:\Windows\system32\EPPICLocal_DU.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006103 _____ C:\Windows\system32\EPPICLocal_ES.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00005817 _____ C:\Windows\system32\EPPICLocal_KO.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00005436 _____ C:\Windows\system32\EPPICLocal_SC.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00004943 _____ C:\Windows\system32\EPPICPattern6.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00002889 _____ C:\Windows\system32\EPPICLocal_RU.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00002426 _____ C:\Windows\system32\EPPICLocal_TC.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00001146 _____ C:\Windows\system32\EPPICPresetData_DU.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\system32\EPPICPresetData_PT.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\system32\EPPICPresetData_BP.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001136 _____ C:\Windows\system32\EPPICPresetData_ES.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\system32\EPPICPresetData_FR.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\system32\EPPICPresetData_CF.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001120 _____ C:\Windows\system32\EPPICPresetData_IT.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001107 _____ C:\Windows\system32\EPPICPresetData_GE.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001104 _____ C:\Windows\system32\EPPICPresetData_EN.dat
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
==================== One Month Modified Files and Folders =======
2014-01-22 06:57 - 2014-01-22 06:57 - 00028380 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-22 06:57 - 2014-01-22 06:57 - 00000000 ____D C:\FRST
2014-01-22 06:55 - 2014-01-22 06:55 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-01-22 06:55 - 2009-11-15 14:17 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-22 06:54 - 2014-01-22 06:54 - 01221632 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-22 06:54 - 2011-09-02 09:02 - 00000000 ____D C:\ProgramData\GameXN
2014-01-22 06:31 - 2011-04-06 12:08 - 00011456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-22 06:31 - 2011-04-06 12:08 - 00011456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-22 06:26 - 2014-01-22 06:26 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-22 06:26 - 2011-04-06 12:52 - 01780479 _____ C:\Windows\WindowsUpdate.log
2014-01-22 06:24 - 2012-11-18 13:24 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-22 06:24 - 2009-11-15 14:17 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-22 06:24 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-22 06:24 - 2009-07-14 05:39 - 27183859 _____ C:\Windows\setupact.log
2014-01-22 06:23 - 2011-04-06 12:49 - 00128254 _____ C:\Windows\PFRO.log
2014-01-22 01:25 - 2013-11-28 13:51 - 00000000 ____D C:\Users\Martin\AppData\Local\Aslwworks
2014-01-22 01:10 - 2013-08-20 19:03 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-22 00:01 - 2011-05-29 09:05 - 00000000 ____D C:\Users\Martin\AppData\Roaming\go
2014-01-21 21:46 - 2009-08-28 07:38 - 00000000 ____D C:\Users\Martin\AppData\Roaming\ICQ
2014-01-21 20:59 - 2009-09-02 08:22 - 00000000 ____D C:\Users\Martin\AppData\Local\Seznam.cz
2014-01-21 20:44 - 2009-10-02 08:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2014-01-21 20:44 - 2009-10-02 08:25 - 00000000 ___RD C:\Program Files\Skype
2014-01-21 20:44 - 2009-10-02 08:25 - 00000000 ____D C:\ProgramData\Skype
2014-01-21 20:26 - 2014-01-21 20:26 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-16 22:03 - 2012-07-07 14:23 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-16 07:11 - 2009-07-14 05:33 - 02541008 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:06 - 2002-09-23 13:00 - 00000718 _____ C:\Windows\win.ini
2014-01-15 21:11 - 2013-08-06 04:56 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 21:08 - 2011-05-23 15:25 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 21:05 - 2009-08-11 20:25 - 00032582 _____ C:\Windows\SchedLgU.Txt
2014-01-13 13:01 - 2011-12-07 23:13 - 00000288 _____ C:\Windows\Tasks\Synology Data Replicator 3-VER-Martin.job
2014-01-09 20:24 - 2011-04-06 12:10 - 01690670 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-29 17:38 - 2009-08-15 10:49 - 00000000 ____D C:\DATA
2013-12-29 10:54 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-27 18:01 - 2013-12-27 18:01 - 00000000 ____D C:\ProgramData\Panasonic
2013-12-27 17:56 - 2009-08-13 17:26 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-27 17:50 - 2013-12-27 17:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Panasonic
2013-12-27 17:50 - 2011-04-06 22:33 - 00186616 _____ C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Common Files\Panasonic
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-27 17:48 - 2009-08-12 16:46 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
Files to move or delete:
====================
C:\Users\Martin\AppData\Roaming\settings.ini
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\ABD2BC~1.exe
C:\Users\Martin\AppData\Local\Temp\hRDUSLU.exe
C:\Users\Martin\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Martin\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Martin\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Martin\AppData\Local\Temp\Refresh.exe
C:\Users\Martin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Martin\AppData\Local\Temp\_is52D0.exe
C:\Users\Martin\AppData\Local\Temp\_isD5B.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-21 08:39
==================== End Of Log ============================
Včera mě to přestalo bavit, tak jsem nainstalovala ještě Malwarebytes antimalware, ktreý během úplné kontroly více než 100krát dal do karantény VirTool.VBcrypt, stále ve stejném umístění. Během této kontroly nastaly potíže se spouštěním programů (IE, word, kalkulačka...) A současně ESET hlásí potenciálně nechtěnou aplikaci Win32/Toolbar.widgi - tady tuším, že reaguje na ten Malwarebytes.
Momentálně mám znovu spuštěný PC, po startu nová hláška:
RegSVR32
.../adp_data-2_5.dll se nepodařilo načíst.
programy co se včera nespouštěly, jedou.
Předem děkuju za rady.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-01-2014
Ran by Martin (administrator) on VER on 22-01-2014 06:57:30
Running from C:\Users\Martin\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
(Acresso Software Inc.) C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
() C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Acresso Software Inc.) C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
() C:\Program Files\ESRI\License\arcgis9x\ARCGIS.EXE
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
() C:\Program Files\ICQ6Toolbar\ICQ Service.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(SafeNet, Inc) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
() C:\Program Files\ASUS\Turbo Key\TurboKey.exe
() C:\Program Files\ASUS\TurboV\TurboV.exe
(HP) C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Company) C:\Program Files\HP\hp laserjet m1522\hppfaxprintersrv.exe
() C:\Program Files\HP\HP UT\bin\hppusg.exe
(Mireo) C:\Program Files\Mio\MMD2\RunMMD.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Adobe Systems, Inc.) C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Bret Taylor) C:\Program Files\Bret Taylor\Stickies\Stickies.exe
(ICQ, LLC.) C:\Program Files\ICQ7.4\ICQ.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
(Panasonic Corporation) C:\Program Files\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [36X Raid Configurer] - C:\WINDOWS\System32\xRaidSetup.exe [1970176 2007-11-19] (JMicron Technology Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2011-01-31] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS4ServiceManager] - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [33570816 2009-01-09] (VIA Technologies, Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-01-12] (Hewlett-Packard)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2008-12-04] (Intel Corporation)
HKLM\...\Run: [JMB36X IDE Setup] - C:\WINDOWS\RaidTool\xInsIDE.exe [36864 2007-03-20] ()
HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [570664 2008-07-14] (Nero AG)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-06-28] (Cyberlink Corp.)
HKLM\...\Run: [Six Engine] - C:\Program Files\ASUS\Six Engine\SixEngine.exe [5993984 2009-02-10] ()
HKLM\...\Run: [Turbo Key] - C:\Program Files\ASUS\Turbo Key\TurboKey.exe [1753600 2009-02-17] ()
HKLM\...\Run: [TurboV] - C:\Program Files\ASUS\TurboV\TurboV.exe [5384192 2009-02-05] ()
HKLM\...\Run: [ToolBoxFX] - C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe [53248 2010-03-03] (HP)
HKLM\...\Run: [HP LaserJet M1522 MFP Series Fax] - C:\Program Files\HP\hp LaserJet M1522\hppfaxprintersrv.exe [2453504 2009-09-22] (Hewlett-Packard Company)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [HPUsageTracking] - C:\Program Files\HP\HP UT\bin\hppusg.exe [36864 2007-08-31] ()
HKLM\...\Run: [RunMMD] - C:\Program Files\Mio\MMD2\RunMMD.exe [49152 2010-05-17] (Mireo)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2219184 2011-01-12] (ESET)
HKLM\...\Run: [IndexSearch] - C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Program Files\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort12reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] - C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2010-12-02] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM\...\Run: [VX3000] - C:\Windows\vVX3000.exe [709992 2007-04-10] (Microsoft Corporation)
HKLM\...\Command Processor: <======= ATTENTION
HKCU\...\Run: [AdobeBridge] - C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe [13145448 2008-08-28] (Adobe Systems, Inc.)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-07-30] (Hewlett-Packard Company)
HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [433872 2011-10-21] (Sony Ericsson)
HKCU\...\Run: [Stickies] - C:\Program Files\Bret Taylor\Stickies\Stickies.exe [335872 2007-03-14] (Bret Taylor)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.4\ICQ.exe [119608 2011-04-12] (ICQ, LLC.)
HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKCU\...\Run: [GameXN GO] - C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-11-06] (EasyBits Software AS)
HKCU\...\Run: [Aslwworks] - regsvr32.exe C:\Users\Martin\AppData\Local\Aslwworks\adp_data-2_5.dll <===== ATTENTION
HKCU\...\Winlogon: [Shell] explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: HKCU - pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
URLSearchHook: HKCU - SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
SearchScopes: HKCU - DefaultScope {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {22CC10DF-C285-4EC4-8769-CC9F481F7874} URL = http://slovnik.seznam.cz/?lg=cz_en&wd={ ... rer:source?}
SearchScopes: HKCU - {3EC4DBFF-46C7-4964-AB26-60E942F7387C} URL = http://encyklopedie.seznam.cz/search?s= ... rer:source?}
SearchScopes: HKCU - {400375A6-E7C5-4CF5-8CB4-F18257510E53} URL = http://zbozi.seznam.cz/?q={searchTerms} ... rer:source?}
SearchScopes: HKCU - {4921EDF0-1C7B-456E-8F03-FC43C10A97AF} URL = http://www.mapy.cz/?query={searchTerms} ... rer:source?}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {75C3F1D5-F961-47FC-9C9F-5E573C85DDA6} URL = http://slovnik.seznam.cz/?lg=en_cz&wd={ ... rer:source?}
SearchScopes: HKCU - {9BA58561-8738-48B3-838D-5115098764CE} URL = http://www.firmy.cz/phr/{searchTerms}?p ... rer:source?}
SearchScopes: HKCU - {A3B1A68E-51A6-4355-BBD8-4F9F33248A0A} URL = http://search.seznam.cz/searchScreen?w= ... rer:source?}
SearchScopes: HKCU - {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... earchTerms}
SearchScopes: HKCU - {FC572E0F-A3C8-4FB4-B574-58E035F5A052} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No File
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: DeLorme Send To GPS - {FBAAD182-3C7A-4BC4-A5E9-207B8E0F02FD} - C:\Program Files\DeLorme\SendToGPS\PNPluginForIE.dll (DeLorme)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKLM - pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKCU - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKCU - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\..\Interfaces\{E6CB90A5-10A9-4717-B1F7-5FD9D66D9174}: [NameServer]212.96.161.6,212.96.160.7
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default
FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: ICQ Search
FF Homepage: hxxp://home.sweetim.com
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @delorme.com/SendToGPS - C:\Program Files\DeLorme\SendToGPS\nppnplugin.dll (DeLorme)
FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.449 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfiller.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\searchplugins\sweetim.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-09-28]
FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009-08-15]
FF Extension: SweetIM Toolbar for Firefox - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\sgfnnw13.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847} [2010-01-08]
FF Extension: 602XML Filler - C:\Program Files\Mozilla Firefox\extensions\xmlfiller@software602.cz [2010-11-22]
FF Extension: ICQ Toolbar - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010-08-12]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011-10-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [2009-08-14]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009-11-05]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [2010-04-01]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-08-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-06]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-05]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-09-19]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [2011-11-11]
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-08-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011-08-16]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Skype Toolbars) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8312_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Google\Chrome\Application\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Google\Chrome\Application\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: ( "name": "",) - C:\Program Files\Mozilla Firefox\plugins\npfiller.dll ()
CHR Plugin: (Microsoft Office 2003) - C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (getPlusPlus for Adobe 16241) - C:\Program Files\Mozilla Firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-15]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-15]
CHR Extension: (Skype Click to Call) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-10-12]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-15]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-09-21]
========================== Services (Whitelisted) =================
R2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [73728 2010-04-14] (Software602 a.s.)
R2 ArcGIS License Manager; C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe [1431440 2008-08-02] (Acresso Software Inc.)
R2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [86016 2008-08-15] ()
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [33584 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [810144 2011-01-12] (ESET)
S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [45816 2009-08-07] (NOS Microsystems Ltd.)
S2 gupdate1ca65f4cc6001b0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-11-15] (Google Inc.)
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [136192 2010-03-03] (HP)
R2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [222968 2009-06-01] ()
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2011-10-03] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
R2 SentinelProtectionServer; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [206400 2006-03-14] (SafeNet, Inc)
S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software)
S4 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [x]
==================== Drivers (Whitelisted) ====================
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] ()
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [137144 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [115008 2010-12-21] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [134000 2010-12-21] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33120 2010-12-21] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [41336 2010-12-21] (ESET)
R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2009-09-04] (Aladdin Knowledge Systems)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [82784 2008-11-21] (JMicron Technology Corp.)
R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [47104 2009-07-13] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-01-22] (Malwarebytes Corporation)
R3 monfilt; C:\Windows\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [993280 2008-12-19] (VIA Technologies, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-22 06:57 - 2014-01-22 06:57 - 00028380 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-22 06:57 - 2014-01-22 06:57 - 00000000 ____D C:\FRST
2014-01-22 06:55 - 2014-01-22 06:55 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-01-22 06:54 - 2014-01-22 06:54 - 01221632 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-22 06:26 - 2014-01-22 06:26 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-21 20:26 - 2014-01-21 20:26 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-21 20:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-15 21:10 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 21:10 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 21:10 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 21:10 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-27 18:01 - 2013-12-27 18:01 - 00000000 ____D C:\ProgramData\Panasonic
2013-12-27 17:50 - 2013-12-27 17:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Common Files\Panasonic
2013-12-27 17:49 - 2007-06-22 00:10 - 00501912 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICSDK2.dll
2013-12-27 17:49 - 2007-06-22 00:10 - 00000097 _____ C:\Windows\system32\PICSDK.ini
2013-12-27 17:49 - 2006-10-31 00:10 - 00120992 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\EpPicPrt.dll
2013-12-27 17:49 - 2006-10-31 00:10 - 00071840 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\EPPicMgr.dll
2013-12-27 17:49 - 2006-10-20 00:10 - 00108704 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICEntry.dll
2013-12-27 17:49 - 2006-10-20 00:10 - 00080024 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\PICSDK.dll
2013-12-27 17:49 - 2005-06-01 00:20 - 00111932 _____ C:\Windows\system32\EPPICPrinterDB.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00031053 _____ C:\Windows\system32\EPPICPattern131.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00027417 _____ C:\Windows\system32\EPPICPattern121.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00026154 _____ C:\Windows\system32\EPPICPattern1.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00024903 _____ C:\Windows\system32\EPPICPattern3.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00021390 _____ C:\Windows\system32\EPPICPattern5.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00020148 _____ C:\Windows\system32\EPPICPattern2.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00013732 _____ C:\Windows\system32\EPPICLocal_EN.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00011811 _____ C:\Windows\system32\EPPICPattern4.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00006442 _____ C:\Windows\system32\EPPICLocal_IT.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\system32\EPPICLocal_PT.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\system32\EPPICLocal_BP.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006335 _____ C:\Windows\system32\EPPICLocal_GE.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\system32\EPPICLocal_FR.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\system32\EPPICLocal_CF.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006122 _____ C:\Windows\system32\EPPICLocal_DU.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00006103 _____ C:\Windows\system32\EPPICLocal_ES.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00005817 _____ C:\Windows\system32\EPPICLocal_KO.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00005436 _____ C:\Windows\system32\EPPICLocal_SC.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00004943 _____ C:\Windows\system32\EPPICPattern6.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00002889 _____ C:\Windows\system32\EPPICLocal_RU.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00002426 _____ C:\Windows\system32\EPPICLocal_TC.cfg
2013-12-27 17:49 - 2004-03-03 06:10 - 00001146 _____ C:\Windows\system32\EPPICPresetData_DU.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\system32\EPPICPresetData_PT.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\system32\EPPICPresetData_BP.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001136 _____ C:\Windows\system32\EPPICPresetData_ES.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\system32\EPPICPresetData_FR.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\system32\EPPICPresetData_CF.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001120 _____ C:\Windows\system32\EPPICPresetData_IT.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001107 _____ C:\Windows\system32\EPPICPresetData_GE.dat
2013-12-27 17:49 - 2004-03-03 06:10 - 00001104 _____ C:\Windows\system32\EPPICPresetData_EN.dat
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
==================== One Month Modified Files and Folders =======
2014-01-22 06:57 - 2014-01-22 06:57 - 00028380 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-22 06:57 - 2014-01-22 06:57 - 00000000 ____D C:\FRST
2014-01-22 06:55 - 2014-01-22 06:55 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-01-22 06:55 - 2009-11-15 14:17 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-22 06:54 - 2014-01-22 06:54 - 01221632 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-22 06:54 - 2011-09-02 09:02 - 00000000 ____D C:\ProgramData\GameXN
2014-01-22 06:31 - 2011-04-06 12:08 - 00011456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-22 06:31 - 2011-04-06 12:08 - 00011456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-22 06:26 - 2014-01-22 06:26 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-22 06:26 - 2011-04-06 12:52 - 01780479 _____ C:\Windows\WindowsUpdate.log
2014-01-22 06:24 - 2012-11-18 13:24 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-22 06:24 - 2009-11-15 14:17 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-22 06:24 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-22 06:24 - 2009-07-14 05:39 - 27183859 _____ C:\Windows\setupact.log
2014-01-22 06:23 - 2011-04-06 12:49 - 00128254 _____ C:\Windows\PFRO.log
2014-01-22 01:25 - 2013-11-28 13:51 - 00000000 ____D C:\Users\Martin\AppData\Local\Aslwworks
2014-01-22 01:10 - 2013-08-20 19:03 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-22 00:01 - 2011-05-29 09:05 - 00000000 ____D C:\Users\Martin\AppData\Roaming\go
2014-01-21 21:46 - 2009-08-28 07:38 - 00000000 ____D C:\Users\Martin\AppData\Roaming\ICQ
2014-01-21 20:59 - 2009-09-02 08:22 - 00000000 ____D C:\Users\Martin\AppData\Local\Seznam.cz
2014-01-21 20:44 - 2009-10-02 08:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2014-01-21 20:44 - 2009-10-02 08:25 - 00000000 ___RD C:\Program Files\Skype
2014-01-21 20:44 - 2009-10-02 08:25 - 00000000 ____D C:\ProgramData\Skype
2014-01-21 20:26 - 2014-01-21 20:26 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 20:26 - 2014-01-21 20:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-16 22:03 - 2012-07-07 14:23 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-16 07:11 - 2009-07-14 05:33 - 02541008 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:06 - 2002-09-23 13:00 - 00000718 _____ C:\Windows\win.ini
2014-01-15 21:11 - 2013-08-06 04:56 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 21:08 - 2011-05-23 15:25 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 21:05 - 2009-08-11 20:25 - 00032582 _____ C:\Windows\SchedLgU.Txt
2014-01-13 13:01 - 2011-12-07 23:13 - 00000288 _____ C:\Windows\Tasks\Synology Data Replicator 3-VER-Martin.job
2014-01-09 20:24 - 2011-04-06 12:10 - 01690670 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-29 17:38 - 2009-08-15 10:49 - 00000000 ____D C:\DATA
2013-12-29 10:54 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-27 18:01 - 2013-12-27 18:01 - 00000000 ____D C:\ProgramData\Panasonic
2013-12-27 17:56 - 2009-08-13 17:26 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-27 17:50 - 2013-12-27 17:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Panasonic
2013-12-27 17:50 - 2011-04-06 22:33 - 00186616 _____ C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Panasonic
2013-12-27 17:49 - 2013-12-27 17:49 - 00000000 ____D C:\Program Files\Common Files\Panasonic
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-27 17:48 - 2013-12-27 17:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-27 17:48 - 2009-08-12 16:46 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
Files to move or delete:
====================
C:\Users\Martin\AppData\Roaming\settings.ini
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\ABD2BC~1.exe
C:\Users\Martin\AppData\Local\Temp\hRDUSLU.exe
C:\Users\Martin\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Martin\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Martin\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Martin\AppData\Local\Temp\Refresh.exe
C:\Users\Martin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Martin\AppData\Local\Temp\_is52D0.exe
C:\Users\Martin\AppData\Local\Temp\_isD5B.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-21 08:39
==================== End Of Log ============================