přesměrovávání na linkbucks.com - podruhé
Napsal: 26 led 2014 20:49
Mám zase problém, jediná nestandartní operace je že jsem připojil mobilní telefon - android, kvůli nabíjení přes usb
zda se projevilo ihned nebo později nevím
s dovolením postupuji jak minule
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-01-2014 02
Ran by hp-doma (administrator) on HP-DOMA-PC on 26-01-2014 20:41:50
Running from C:\Users\hp-doma\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe
(WDC) C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [16395880 2009-11-28] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2837768 2010-02-26] (ESET)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [HPCam_Menu] - c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [322104 2009-08-20] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe -update activex [531336 2013-12-10] (Adobe Systems Incorporated)
HKU\Katka\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/s ... wflash.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/produ ... wsdc32.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {BF3CD111-6278-11D2-9EA3-00A0C9251384} http://www.o2c.de/download/O2CPlayer.CAB
Handler: ipp - No CLSID Value -
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp - No CLSID Value -
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A80D1E02-25E2-4C5D-861A-FA3AD7FC44ED}: [NameServer]8.8.8.8
Chrome:
=======
CHR Extension: (Peněženka Google) - C:\Users\hp-doma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR HKLM-x32\...\Chrome\Extension: [aaaaimdcedbpbcjjbbnfcbbjcngmomic] - C:\Users\hp-doma\AppData\Local\somotomoviestoolbar1\GC\toolbar.crx [2013-08-31]
CHR HKLM-x32\...\Chrome\Extension: [malebckkmhhonigohmeacppccacdpkjm] - C:\Users\hp-doma\AppData\Local\CRE\malebckkmhhonigohmeacppccacdpkjm.crx [2013-08-31]
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42336 2010-02-26] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810120 2010-02-26] (ESET)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [341296 2011-06-21] (Nitro PDF Software)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
R2 TVCapSvc; c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [296360 2009-10-06] ()
R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [317328 2011-08-01] (WDC)
S4 WDFMEService; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [1978256 2011-08-01] (Western Digital )
R2 WDRulesService; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [1338256 2011-08-01] (Western Digital )
==================== Drivers (Whitelisted) ====================
R3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [311424 2009-05-22] (AVerMedia TECHNOLOGIES, Inc.)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163888 2010-02-26] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-02-26] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-02-26] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-02-26] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-02-26] (ESET)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
S3 s1039bus; C:\Windows\System32\DRIVERS\s1039bus.sys [127600 2010-03-15] (MCCI Corporation)
S3 s1039mdfl; C:\Windows\System32\DRIVERS\s1039mdfl.sys [19568 2010-03-15] (MCCI Corporation)
S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [161904 2010-03-15] (MCCI Corporation)
S3 s1039mgmt; C:\Windows\System32\DRIVERS\s1039mgmt.sys [141424 2010-03-15] (MCCI Corporation)
S3 s1039nd5; C:\Windows\System32\DRIVERS\s1039nd5.sys [34416 2010-03-15] (MCCI Corporation)
S3 s1039obex; C:\Windows\System32\DRIVERS\s1039obex.sys [137328 2010-03-15] (MCCI Corporation)
S3 s1039unic; C:\Windows\System32\DRIVERS\s1039unic.sys [158320 2010-03-15] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2010-08-16] (Sony Ericsson Mobile Communications)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
U2 ezSharedSvc;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-26 20:41 - 2014-01-26 20:43 - 00014238 _____ C:\Users\hp-doma\Downloads\FRST.txt
2014-01-26 20:41 - 2014-01-26 20:41 - 02078208 _____ (Farbar) C:\Users\hp-doma\Downloads\FRST64.exe
2014-01-26 20:41 - 2014-01-26 20:41 - 00000000 ____D C:\FRST
2014-01-26 20:40 - 2014-01-26 20:40 - 00112640 _____ (forum.viry.cz) C:\Users\hp-doma\Downloads\Nepotvrzeno 172706.crdownload
2014-01-26 13:36 - 2014-01-26 13:36 - 00001888 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2014-01-25 20:34 - 2014-01-26 13:31 - 00000914 _____ C:\Windows\setupact.log
2014-01-25 20:34 - 2014-01-25 20:34 - 00000000 _____ C:\Windows\setuperr.log
2014-01-20 17:42 - 2014-01-21 13:26 - 00000000 ____D C:\Users\hp-doma\Desktop\KATKA
2014-01-15 21:34 - 2014-01-15 22:15 - 00000000 ____D C:\Users\hp-doma\Downloads\5_Interphone
2014-01-15 21:33 - 2014-01-15 21:33 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone (1).zip
2014-01-15 21:31 - 2014-01-15 21:31 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone.zip
2014-01-15 21:28 - 2014-01-15 21:28 - 00002023 _____ C:\Users\hp-doma\Documents\katka.txt
2014-01-15 21:27 - 2014-01-15 21:32 - 00000000 ____D C:\Users\hp-doma\Downloads\5_CellularLine
2014-01-15 21:26 - 2014-01-15 21:26 - 00054088 _____ C:\Users\hp-doma\Downloads\5_CellularLine.zip
2014-01-15 21:26 - 2014-01-15 21:26 - 00017120 _____ C:\Users\hp-doma\Downloads\5_Kitvision.zip
2014-01-15 17:44 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 17:44 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 17:44 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 21:39 - 2014-01-14 21:39 - 00233472 _____ C:\Users\hp-doma\Downloads\spolecny_cenik_KMBETA.xls
2014-01-14 14:59 - 2014-01-26 14:59 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForhp-doma.job
2014-01-12 14:09 - 2014-01-12 14:09 - 00000000 ____D C:\Users\hp-doma\Documents\My PSP Files
2014-01-12 13:22 - 2014-01-12 13:22 - 00002776 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-12 13:22 - 2014-01-12 13:22 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-12 13:22 - 2014-01-12 13:22 - 00000000 ____D C:\Program Files\CCleaner
2014-01-12 13:21 - 2014-01-12 13:21 - 04645232 _____ (Piriform Ltd) C:\Users\hp-doma\Downloads\ccsetup409.exe
2014-01-11 09:40 - 2014-01-11 09:40 - 00000000 ____D C:\Users\hp-doma\Desktop\FRST-OlderVersion
2014-01-10 22:33 - 2014-01-10 22:33 - 00015327 _____ C:\Users\hp-doma\Desktop\LM.bat
2014-01-10 19:08 - 2014-01-10 19:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-10 19:08 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-10 18:32 - 2014-01-12 13:01 - 00000000 ____D C:\AdwCleaner
2014-01-09 15:45 - 2014-01-12 13:00 - 00000000 ____D C:\Qoobox
2014-01-08 21:09 - 2014-01-08 21:09 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung (1).wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 02479456 _____ C:\Users\hp-doma\Downloads\toboganes.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01615876 _____ C:\Users\hp-doma\Downloads\der_ast.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01180964 _____ C:\Users\hp-doma\Downloads\serveuse_du_mois.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00812092 _____ C:\Users\hp-doma\Downloads\Lavage_Du_Congelateur.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1 (1).wmv
2014-01-08 21:04 - 2014-01-08 21:04 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung.wmv
2014-01-08 21:02 - 2014-01-08 21:02 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1 (1).WMV
2014-01-08 21:02 - 2014-01-08 21:02 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1.wmv
2014-01-08 21:01 - 2014-01-08 21:01 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1.WMV
2014-01-08 20:08 - 2014-01-08 20:09 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (3).exe
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Malwarebytes
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-08 18:13 - 2014-01-08 18:14 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (2).exe
2014-01-08 09:17 - 2014-01-08 09:18 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Desktop\ESET_Vzdalena_Pomoc (1).exe
2014-01-07 18:50 - 2014-01-07 18:51 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc.exe
2014-01-04 22:58 - 2014-01-04 22:58 - 00021527 _____ C:\Users\hp-doma\Desktop\ob-podminky-nejstavebniny.odt
2014-01-04 20:29 - 2014-01-04 20:30 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\eCyber
2014-01-04 20:29 - 2014-01-04 20:29 - 00000000 ____D C:\Windows\system32\log
2014-01-04 20:27 - 2014-01-04 20:29 - 09366896 _____ C:\Users\hp-doma\Downloads\yet_another_cleaner.exe
2014-01-04 19:04 - 2014-01-04 19:06 - 25098032 _____ C:\Users\hp-doma\Downloads\600_3D_Icons_PNG.rar
2014-01-04 17:38 - 2014-01-04 17:39 - 03280896 _____ C:\Users\hp-doma\Downloads\Mail.exe
2014-01-03 18:49 - 2014-01-03 18:49 - 00012493 _____ C:\Users\hp-doma\Downloads\1-organizace.odt
2014-01-02 21:23 - 2014-01-02 21:23 - 00001912 _____ C:\Windows\epplauncher.mif
2014-01-02 21:23 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2014-01-02 21:22 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files\Microsoft Security Client
2014-01-02 21:21 - 2014-01-02 21:21 - 13693624 _____ (Microsoft Corporation) C:\Users\hp-doma\Downloads\mseinstall.exe
2014-01-02 21:00 - 2014-01-02 21:00 - 00000892 _____ C:\Users\hp-doma\Documents\posrany netdevelo.txt
==================== One Month Modified Files and Folders =======
2014-01-26 20:43 - 2014-01-26 20:41 - 00014238 _____ C:\Users\hp-doma\Downloads\FRST.txt
2014-01-26 20:41 - 2014-01-26 20:41 - 02078208 _____ (Farbar) C:\Users\hp-doma\Downloads\FRST64.exe
2014-01-26 20:41 - 2014-01-26 20:41 - 00000000 ____D C:\FRST
2014-01-26 20:40 - 2014-01-26 20:40 - 00112640 _____ (forum.viry.cz) C:\Users\hp-doma\Downloads\Nepotvrzeno 172706.crdownload
2014-01-26 14:59 - 2014-01-14 14:59 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForhp-doma.job
2014-01-26 14:59 - 2013-04-01 19:38 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForhp-doma
2014-01-26 14:09 - 2012-08-18 15:10 - 00000000 ___RD C:\Users\hp-doma\Desktop\karaoke
2014-01-26 13:40 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-26 13:40 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-26 13:39 - 2011-11-03 11:38 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Nitro PDF
2014-01-26 13:37 - 2013-05-17 20:59 - 00000000 ____D C:\ProgramData\Package Cache
2014-01-26 13:37 - 2010-01-09 06:55 - 00631526 _____ C:\Windows\system32\perfh005.dat
2014-01-26 13:37 - 2010-01-09 06:55 - 00122148 _____ C:\Windows\system32\perfc005.dat
2014-01-26 13:37 - 2009-07-14 06:13 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-26 13:36 - 2014-01-26 13:36 - 00001888 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2014-01-26 13:36 - 2011-07-29 16:01 - 00000000 ____D C:\ProgramData\Garmin
2014-01-26 13:36 - 2011-07-29 15:56 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-26 13:36 - 2010-12-26 20:44 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\GARMIN
2014-01-26 13:36 - 2010-02-05 01:21 - 01869101 _____ C:\Windows\WindowsUpdate.log
2014-01-26 13:31 - 2014-01-25 20:34 - 00000914 _____ C:\Windows\setupact.log
2014-01-26 13:31 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-25 20:34 - 2014-01-25 20:34 - 00000000 _____ C:\Windows\setuperr.log
2014-01-24 23:06 - 2010-04-03 19:54 - 00000000 ____D C:\!!!!DIGIFOTO
2014-01-21 13:26 - 2014-01-20 17:42 - 00000000 ____D C:\Users\hp-doma\Desktop\KATKA
2014-01-20 21:10 - 2010-03-16 20:53 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Skype
2014-01-19 08:33 - 2010-03-15 16:59 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-16 21:05 - 2010-12-27 13:02 - 00002380 _____ C:\Users\hp-doma\Desktop\Google Chrome.lnk
2014-01-16 10:55 - 2010-03-15 16:27 - 00102320 _____ C:\Users\hp-doma\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-16 10:48 - 2009-07-14 06:08 - 00032600 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-16 10:48 - 2009-07-14 05:45 - 00398576 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:13 - 2013-07-18 08:04 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 23:10 - 2010-03-27 17:49 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 22:15 - 2014-01-15 21:34 - 00000000 ____D C:\Users\hp-doma\Downloads\5_Interphone
2014-01-15 21:33 - 2014-01-15 21:33 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone (1).zip
2014-01-15 21:32 - 2014-01-15 21:27 - 00000000 ____D C:\Users\hp-doma\Downloads\5_CellularLine
2014-01-15 21:31 - 2014-01-15 21:31 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone.zip
2014-01-15 21:28 - 2014-01-15 21:28 - 00002023 _____ C:\Users\hp-doma\Documents\katka.txt
2014-01-15 21:26 - 2014-01-15 21:26 - 00054088 _____ C:\Users\hp-doma\Downloads\5_CellularLine.zip
2014-01-15 21:26 - 2014-01-15 21:26 - 00017120 _____ C:\Users\hp-doma\Downloads\5_Kitvision.zip
2014-01-14 21:59 - 2010-04-13 17:14 - 00002004 ____H C:\Users\hp-doma\Documents\Default.rdp
2014-01-14 21:59 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2014-01-14 21:39 - 2014-01-14 21:39 - 00233472 _____ C:\Users\hp-doma\Downloads\spolecny_cenik_KMBETA.xls
2014-01-12 17:01 - 2010-08-16 17:57 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Ericsson
2014-01-12 17:01 - 2010-08-16 17:43 - 00000000 ____D C:\Program Files (x86)\Sony Ericsson
2014-01-12 17:00 - 2011-10-09 12:04 - 00000000 ____D C:\Users\hp-doma\Documents\Room Arranger
2014-01-12 16:57 - 2010-08-16 17:43 - 00000000 ____D C:\ProgramData\Sony Ericsson
2014-01-12 16:57 - 2010-01-08 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-12 16:35 - 2012-10-28 16:14 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hry.cz
2014-01-12 16:35 - 2012-10-28 16:14 - 00000000 ____D C:\Program Files (x86)\Hry.cz
2014-01-12 16:20 - 2010-01-08 22:40 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-12 16:19 - 2010-01-08 22:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2014-01-12 16:19 - 2010-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2014-01-12 16:16 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2014-01-12 16:02 - 2010-03-16 19:52 - 00000013 _____ C:\Windows\vbaddin.ini
2014-01-12 16:02 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media
2014-01-12 14:11 - 2010-03-25 19:42 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Corel
2014-01-12 14:11 - 2010-02-05 01:31 - 00000000 ____D C:\Program Files (x86)\Corel
2014-01-12 14:11 - 2010-01-08 23:05 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com
2014-01-12 14:09 - 2014-01-12 14:09 - 00000000 ____D C:\Users\hp-doma\Documents\My PSP Files
2014-01-12 13:22 - 2014-01-12 13:22 - 00002776 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-12 13:22 - 2014-01-12 13:22 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-12 13:22 - 2014-01-12 13:22 - 00000000 ____D C:\Program Files\CCleaner
2014-01-12 13:21 - 2014-01-12 13:21 - 04645232 _____ (Piriform Ltd) C:\Users\hp-doma\Downloads\ccsetup409.exe
2014-01-12 13:01 - 2014-01-10 18:32 - 00000000 ____D C:\AdwCleaner
2014-01-12 13:01 - 2010-03-15 16:23 - 00000000 ____D C:\Users\hp-doma
2014-01-12 13:00 - 2014-01-09 15:45 - 00000000 ____D C:\Qoobox
2014-01-11 09:40 - 2014-01-11 09:40 - 00000000 ____D C:\Users\hp-doma\Desktop\FRST-OlderVersion
2014-01-11 09:40 - 2013-07-07 18:47 - 00000000 ____D C:\Users\hp-doma\AppData\Local\CRE
2014-01-10 22:33 - 2014-01-10 22:33 - 00015327 _____ C:\Users\hp-doma\Desktop\LM.bat
2014-01-10 19:08 - 2014-01-10 19:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-10 18:37 - 2013-10-15 19:03 - 00000601 _____ C:\Users\hp-doma\Desktop\Search.lnk
2014-01-10 18:37 - 2013-10-09 18:43 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2014-01-10 17:30 - 2012-10-05 21:16 - 00000000 ____D C:\Firefox
2014-01-10 17:27 - 2011-10-28 17:38 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Winamp
2014-01-10 17:26 - 2009-09-07 02:57 - 00000000 ____D C:\Windows\Panther
2014-01-09 17:46 - 2010-03-25 19:42 - 00000000 ____D C:\Users\Administrator
2014-01-09 17:46 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-09 17:41 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-09 16:00 - 2009-07-14 03:34 - 82051072 _____ C:\Windows\system32\config\software.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 25427968 _____ C:\Windows\system32\config\system.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00524288 _____ C:\Windows\system32\config\default.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2014-01-08 21:09 - 2014-01-08 21:09 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung (1).wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 02479456 _____ C:\Users\hp-doma\Downloads\toboganes.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01615876 _____ C:\Users\hp-doma\Downloads\der_ast.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01180964 _____ C:\Users\hp-doma\Downloads\serveuse_du_mois.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00812092 _____ C:\Users\hp-doma\Downloads\Lavage_Du_Congelateur.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1 (1).wmv
2014-01-08 21:04 - 2014-01-08 21:04 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung.wmv
2014-01-08 21:02 - 2014-01-08 21:02 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1 (1).WMV
2014-01-08 21:02 - 2014-01-08 21:02 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1.wmv
2014-01-08 21:01 - 2014-01-08 21:01 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1.WMV
2014-01-08 20:09 - 2014-01-08 20:08 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (3).exe
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Malwarebytes
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-08 18:14 - 2014-01-08 18:13 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (2).exe
2014-01-08 09:18 - 2014-01-08 09:17 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Desktop\ESET_Vzdalena_Pomoc (1).exe
2014-01-07 18:51 - 2014-01-07 18:50 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc.exe
2014-01-04 22:58 - 2014-01-04 22:58 - 00021527 _____ C:\Users\hp-doma\Desktop\ob-podminky-nejstavebniny.odt
2014-01-04 21:06 - 2010-10-27 08:50 - 00000000 ____D C:\Windows\Minidump
2014-01-04 20:30 - 2014-01-04 20:29 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\eCyber
2014-01-04 20:29 - 2014-01-04 20:29 - 00000000 ____D C:\Windows\system32\log
2014-01-04 20:29 - 2014-01-04 20:27 - 09366896 _____ C:\Users\hp-doma\Downloads\yet_another_cleaner.exe
2014-01-04 19:07 - 2013-10-21 20:10 - 00000000 ____D C:\Games
2014-01-04 19:06 - 2014-01-04 19:04 - 25098032 _____ C:\Users\hp-doma\Downloads\600_3D_Icons_PNG.rar
2014-01-04 17:39 - 2014-01-04 17:38 - 03280896 _____ C:\Users\hp-doma\Downloads\Mail.exe
2014-01-03 18:49 - 2014-01-03 18:49 - 00012493 _____ C:\Users\hp-doma\Downloads\1-organizace.odt
2014-01-02 21:23 - 2014-01-02 21:23 - 00001912 _____ C:\Windows\epplauncher.mif
2014-01-02 21:23 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2014-01-02 21:23 - 2014-01-02 21:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2014-01-02 21:21 - 2014-01-02 21:21 - 13693624 _____ (Microsoft Corporation) C:\Users\hp-doma\Downloads\mseinstall.exe
2014-01-02 21:00 - 2014-01-02 21:00 - 00000892 _____ C:\Users\hp-doma\Documents\posrany netdevelo.txt
2013-12-28 10:09 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
Some content of TEMP:
====================
C:\Users\hp-doma\AppData\Local\Temp\tmpC189.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-19 10:37
==================== End Of Log ============================
zda se projevilo ihned nebo později nevím
s dovolením postupuji jak minule
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-01-2014 02
Ran by hp-doma (administrator) on HP-DOMA-PC on 26-01-2014 20:41:50
Running from C:\Users\hp-doma\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe
(WDC) C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hp-doma\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [16395880 2009-11-28] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2837768 2010-02-26] (ESET)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [HPCam_Menu] - c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [322104 2009-08-20] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe -update activex [531336 2013-12-10] (Adobe Systems Incorporated)
HKU\Katka\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/s ... wflash.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/produ ... wsdc32.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {BF3CD111-6278-11D2-9EA3-00A0C9251384} http://www.o2c.de/download/O2CPlayer.CAB
Handler: ipp - No CLSID Value -
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp - No CLSID Value -
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A80D1E02-25E2-4C5D-861A-FA3AD7FC44ED}: [NameServer]8.8.8.8
Chrome:
=======
CHR Extension: (Peněženka Google) - C:\Users\hp-doma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR HKLM-x32\...\Chrome\Extension: [aaaaimdcedbpbcjjbbnfcbbjcngmomic] - C:\Users\hp-doma\AppData\Local\somotomoviestoolbar1\GC\toolbar.crx [2013-08-31]
CHR HKLM-x32\...\Chrome\Extension: [malebckkmhhonigohmeacppccacdpkjm] - C:\Users\hp-doma\AppData\Local\CRE\malebckkmhhonigohmeacppccacdpkjm.crx [2013-08-31]
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42336 2010-02-26] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810120 2010-02-26] (ESET)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [341296 2011-06-21] (Nitro PDF Software)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
R2 TVCapSvc; c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [296360 2009-10-06] ()
R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [317328 2011-08-01] (WDC)
S4 WDFMEService; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [1978256 2011-08-01] (Western Digital )
R2 WDRulesService; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [1338256 2011-08-01] (Western Digital )
==================== Drivers (Whitelisted) ====================
R3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [311424 2009-05-22] (AVerMedia TECHNOLOGIES, Inc.)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163888 2010-02-26] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-02-26] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-02-26] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-02-26] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-02-26] (ESET)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
S3 s1039bus; C:\Windows\System32\DRIVERS\s1039bus.sys [127600 2010-03-15] (MCCI Corporation)
S3 s1039mdfl; C:\Windows\System32\DRIVERS\s1039mdfl.sys [19568 2010-03-15] (MCCI Corporation)
S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [161904 2010-03-15] (MCCI Corporation)
S3 s1039mgmt; C:\Windows\System32\DRIVERS\s1039mgmt.sys [141424 2010-03-15] (MCCI Corporation)
S3 s1039nd5; C:\Windows\System32\DRIVERS\s1039nd5.sys [34416 2010-03-15] (MCCI Corporation)
S3 s1039obex; C:\Windows\System32\DRIVERS\s1039obex.sys [137328 2010-03-15] (MCCI Corporation)
S3 s1039unic; C:\Windows\System32\DRIVERS\s1039unic.sys [158320 2010-03-15] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2010-08-16] (Sony Ericsson Mobile Communications)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
U2 ezSharedSvc;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-26 20:41 - 2014-01-26 20:43 - 00014238 _____ C:\Users\hp-doma\Downloads\FRST.txt
2014-01-26 20:41 - 2014-01-26 20:41 - 02078208 _____ (Farbar) C:\Users\hp-doma\Downloads\FRST64.exe
2014-01-26 20:41 - 2014-01-26 20:41 - 00000000 ____D C:\FRST
2014-01-26 20:40 - 2014-01-26 20:40 - 00112640 _____ (forum.viry.cz) C:\Users\hp-doma\Downloads\Nepotvrzeno 172706.crdownload
2014-01-26 13:36 - 2014-01-26 13:36 - 00001888 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2014-01-25 20:34 - 2014-01-26 13:31 - 00000914 _____ C:\Windows\setupact.log
2014-01-25 20:34 - 2014-01-25 20:34 - 00000000 _____ C:\Windows\setuperr.log
2014-01-20 17:42 - 2014-01-21 13:26 - 00000000 ____D C:\Users\hp-doma\Desktop\KATKA
2014-01-15 21:34 - 2014-01-15 22:15 - 00000000 ____D C:\Users\hp-doma\Downloads\5_Interphone
2014-01-15 21:33 - 2014-01-15 21:33 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone (1).zip
2014-01-15 21:31 - 2014-01-15 21:31 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone.zip
2014-01-15 21:28 - 2014-01-15 21:28 - 00002023 _____ C:\Users\hp-doma\Documents\katka.txt
2014-01-15 21:27 - 2014-01-15 21:32 - 00000000 ____D C:\Users\hp-doma\Downloads\5_CellularLine
2014-01-15 21:26 - 2014-01-15 21:26 - 00054088 _____ C:\Users\hp-doma\Downloads\5_CellularLine.zip
2014-01-15 21:26 - 2014-01-15 21:26 - 00017120 _____ C:\Users\hp-doma\Downloads\5_Kitvision.zip
2014-01-15 17:44 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 17:44 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 17:44 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 17:44 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 21:39 - 2014-01-14 21:39 - 00233472 _____ C:\Users\hp-doma\Downloads\spolecny_cenik_KMBETA.xls
2014-01-14 14:59 - 2014-01-26 14:59 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForhp-doma.job
2014-01-12 14:09 - 2014-01-12 14:09 - 00000000 ____D C:\Users\hp-doma\Documents\My PSP Files
2014-01-12 13:22 - 2014-01-12 13:22 - 00002776 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-12 13:22 - 2014-01-12 13:22 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-12 13:22 - 2014-01-12 13:22 - 00000000 ____D C:\Program Files\CCleaner
2014-01-12 13:21 - 2014-01-12 13:21 - 04645232 _____ (Piriform Ltd) C:\Users\hp-doma\Downloads\ccsetup409.exe
2014-01-11 09:40 - 2014-01-11 09:40 - 00000000 ____D C:\Users\hp-doma\Desktop\FRST-OlderVersion
2014-01-10 22:33 - 2014-01-10 22:33 - 00015327 _____ C:\Users\hp-doma\Desktop\LM.bat
2014-01-10 19:08 - 2014-01-10 19:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-10 19:08 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-10 18:32 - 2014-01-12 13:01 - 00000000 ____D C:\AdwCleaner
2014-01-09 15:45 - 2014-01-12 13:00 - 00000000 ____D C:\Qoobox
2014-01-08 21:09 - 2014-01-08 21:09 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung (1).wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 02479456 _____ C:\Users\hp-doma\Downloads\toboganes.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01615876 _____ C:\Users\hp-doma\Downloads\der_ast.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01180964 _____ C:\Users\hp-doma\Downloads\serveuse_du_mois.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00812092 _____ C:\Users\hp-doma\Downloads\Lavage_Du_Congelateur.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1 (1).wmv
2014-01-08 21:04 - 2014-01-08 21:04 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung.wmv
2014-01-08 21:02 - 2014-01-08 21:02 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1 (1).WMV
2014-01-08 21:02 - 2014-01-08 21:02 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1.wmv
2014-01-08 21:01 - 2014-01-08 21:01 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1.WMV
2014-01-08 20:08 - 2014-01-08 20:09 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (3).exe
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Malwarebytes
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-08 18:13 - 2014-01-08 18:14 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (2).exe
2014-01-08 09:17 - 2014-01-08 09:18 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Desktop\ESET_Vzdalena_Pomoc (1).exe
2014-01-07 18:50 - 2014-01-07 18:51 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc.exe
2014-01-04 22:58 - 2014-01-04 22:58 - 00021527 _____ C:\Users\hp-doma\Desktop\ob-podminky-nejstavebniny.odt
2014-01-04 20:29 - 2014-01-04 20:30 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\eCyber
2014-01-04 20:29 - 2014-01-04 20:29 - 00000000 ____D C:\Windows\system32\log
2014-01-04 20:27 - 2014-01-04 20:29 - 09366896 _____ C:\Users\hp-doma\Downloads\yet_another_cleaner.exe
2014-01-04 19:04 - 2014-01-04 19:06 - 25098032 _____ C:\Users\hp-doma\Downloads\600_3D_Icons_PNG.rar
2014-01-04 17:38 - 2014-01-04 17:39 - 03280896 _____ C:\Users\hp-doma\Downloads\Mail.exe
2014-01-03 18:49 - 2014-01-03 18:49 - 00012493 _____ C:\Users\hp-doma\Downloads\1-organizace.odt
2014-01-02 21:23 - 2014-01-02 21:23 - 00001912 _____ C:\Windows\epplauncher.mif
2014-01-02 21:23 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2014-01-02 21:22 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files\Microsoft Security Client
2014-01-02 21:21 - 2014-01-02 21:21 - 13693624 _____ (Microsoft Corporation) C:\Users\hp-doma\Downloads\mseinstall.exe
2014-01-02 21:00 - 2014-01-02 21:00 - 00000892 _____ C:\Users\hp-doma\Documents\posrany netdevelo.txt
==================== One Month Modified Files and Folders =======
2014-01-26 20:43 - 2014-01-26 20:41 - 00014238 _____ C:\Users\hp-doma\Downloads\FRST.txt
2014-01-26 20:41 - 2014-01-26 20:41 - 02078208 _____ (Farbar) C:\Users\hp-doma\Downloads\FRST64.exe
2014-01-26 20:41 - 2014-01-26 20:41 - 00000000 ____D C:\FRST
2014-01-26 20:40 - 2014-01-26 20:40 - 00112640 _____ (forum.viry.cz) C:\Users\hp-doma\Downloads\Nepotvrzeno 172706.crdownload
2014-01-26 14:59 - 2014-01-14 14:59 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForhp-doma.job
2014-01-26 14:59 - 2013-04-01 19:38 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForhp-doma
2014-01-26 14:09 - 2012-08-18 15:10 - 00000000 ___RD C:\Users\hp-doma\Desktop\karaoke
2014-01-26 13:40 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-26 13:40 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-26 13:39 - 2011-11-03 11:38 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Nitro PDF
2014-01-26 13:37 - 2013-05-17 20:59 - 00000000 ____D C:\ProgramData\Package Cache
2014-01-26 13:37 - 2010-01-09 06:55 - 00631526 _____ C:\Windows\system32\perfh005.dat
2014-01-26 13:37 - 2010-01-09 06:55 - 00122148 _____ C:\Windows\system32\perfc005.dat
2014-01-26 13:37 - 2009-07-14 06:13 - 01470298 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-26 13:36 - 2014-01-26 13:36 - 00001888 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2014-01-26 13:36 - 2011-07-29 16:01 - 00000000 ____D C:\ProgramData\Garmin
2014-01-26 13:36 - 2011-07-29 15:56 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-26 13:36 - 2010-12-26 20:44 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\GARMIN
2014-01-26 13:36 - 2010-02-05 01:21 - 01869101 _____ C:\Windows\WindowsUpdate.log
2014-01-26 13:31 - 2014-01-25 20:34 - 00000914 _____ C:\Windows\setupact.log
2014-01-26 13:31 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-25 20:34 - 2014-01-25 20:34 - 00000000 _____ C:\Windows\setuperr.log
2014-01-24 23:06 - 2010-04-03 19:54 - 00000000 ____D C:\!!!!DIGIFOTO
2014-01-21 13:26 - 2014-01-20 17:42 - 00000000 ____D C:\Users\hp-doma\Desktop\KATKA
2014-01-20 21:10 - 2010-03-16 20:53 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Skype
2014-01-19 08:33 - 2010-03-15 16:59 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-16 21:05 - 2010-12-27 13:02 - 00002380 _____ C:\Users\hp-doma\Desktop\Google Chrome.lnk
2014-01-16 10:55 - 2010-03-15 16:27 - 00102320 _____ C:\Users\hp-doma\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-16 10:48 - 2009-07-14 06:08 - 00032600 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-16 10:48 - 2009-07-14 05:45 - 00398576 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:13 - 2013-07-18 08:04 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 23:10 - 2010-03-27 17:49 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 22:15 - 2014-01-15 21:34 - 00000000 ____D C:\Users\hp-doma\Downloads\5_Interphone
2014-01-15 21:33 - 2014-01-15 21:33 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone (1).zip
2014-01-15 21:32 - 2014-01-15 21:27 - 00000000 ____D C:\Users\hp-doma\Downloads\5_CellularLine
2014-01-15 21:31 - 2014-01-15 21:31 - 00025024 _____ C:\Users\hp-doma\Downloads\5_Interphone.zip
2014-01-15 21:28 - 2014-01-15 21:28 - 00002023 _____ C:\Users\hp-doma\Documents\katka.txt
2014-01-15 21:26 - 2014-01-15 21:26 - 00054088 _____ C:\Users\hp-doma\Downloads\5_CellularLine.zip
2014-01-15 21:26 - 2014-01-15 21:26 - 00017120 _____ C:\Users\hp-doma\Downloads\5_Kitvision.zip
2014-01-14 21:59 - 2010-04-13 17:14 - 00002004 ____H C:\Users\hp-doma\Documents\Default.rdp
2014-01-14 21:59 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2014-01-14 21:39 - 2014-01-14 21:39 - 00233472 _____ C:\Users\hp-doma\Downloads\spolecny_cenik_KMBETA.xls
2014-01-12 17:01 - 2010-08-16 17:57 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Ericsson
2014-01-12 17:01 - 2010-08-16 17:43 - 00000000 ____D C:\Program Files (x86)\Sony Ericsson
2014-01-12 17:00 - 2011-10-09 12:04 - 00000000 ____D C:\Users\hp-doma\Documents\Room Arranger
2014-01-12 16:57 - 2010-08-16 17:43 - 00000000 ____D C:\ProgramData\Sony Ericsson
2014-01-12 16:57 - 2010-01-08 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-12 16:35 - 2012-10-28 16:14 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hry.cz
2014-01-12 16:35 - 2012-10-28 16:14 - 00000000 ____D C:\Program Files (x86)\Hry.cz
2014-01-12 16:20 - 2010-01-08 22:40 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-12 16:19 - 2010-01-08 22:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2014-01-12 16:19 - 2010-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2014-01-12 16:16 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2014-01-12 16:02 - 2010-03-16 19:52 - 00000013 _____ C:\Windows\vbaddin.ini
2014-01-12 16:02 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media
2014-01-12 14:11 - 2010-03-25 19:42 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Corel
2014-01-12 14:11 - 2010-02-05 01:31 - 00000000 ____D C:\Program Files (x86)\Corel
2014-01-12 14:11 - 2010-01-08 23:05 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2014-01-12 14:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com
2014-01-12 14:09 - 2014-01-12 14:09 - 00000000 ____D C:\Users\hp-doma\Documents\My PSP Files
2014-01-12 13:22 - 2014-01-12 13:22 - 00002776 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-12 13:22 - 2014-01-12 13:22 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-12 13:22 - 2014-01-12 13:22 - 00000000 ____D C:\Program Files\CCleaner
2014-01-12 13:21 - 2014-01-12 13:21 - 04645232 _____ (Piriform Ltd) C:\Users\hp-doma\Downloads\ccsetup409.exe
2014-01-12 13:01 - 2014-01-10 18:32 - 00000000 ____D C:\AdwCleaner
2014-01-12 13:01 - 2010-03-15 16:23 - 00000000 ____D C:\Users\hp-doma
2014-01-12 13:00 - 2014-01-09 15:45 - 00000000 ____D C:\Qoobox
2014-01-11 09:40 - 2014-01-11 09:40 - 00000000 ____D C:\Users\hp-doma\Desktop\FRST-OlderVersion
2014-01-11 09:40 - 2013-07-07 18:47 - 00000000 ____D C:\Users\hp-doma\AppData\Local\CRE
2014-01-10 22:33 - 2014-01-10 22:33 - 00015327 _____ C:\Users\hp-doma\Desktop\LM.bat
2014-01-10 19:08 - 2014-01-10 19:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-10 18:37 - 2013-10-15 19:03 - 00000601 _____ C:\Users\hp-doma\Desktop\Search.lnk
2014-01-10 18:37 - 2013-10-09 18:43 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2014-01-10 17:30 - 2012-10-05 21:16 - 00000000 ____D C:\Firefox
2014-01-10 17:27 - 2011-10-28 17:38 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Winamp
2014-01-10 17:26 - 2009-09-07 02:57 - 00000000 ____D C:\Windows\Panther
2014-01-09 17:46 - 2010-03-25 19:42 - 00000000 ____D C:\Users\Administrator
2014-01-09 17:46 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-09 17:41 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-09 16:00 - 2009-07-14 03:34 - 82051072 _____ C:\Windows\system32\config\software.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 25427968 _____ C:\Windows\system32\config\system.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00524288 _____ C:\Windows\system32\config\default.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2014-01-09 16:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2014-01-08 21:09 - 2014-01-08 21:09 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung (1).wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 02479456 _____ C:\Users\hp-doma\Downloads\toboganes.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01615876 _____ C:\Users\hp-doma\Downloads\der_ast.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 01180964 _____ C:\Users\hp-doma\Downloads\serveuse_du_mois.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00812092 _____ C:\Users\hp-doma\Downloads\Lavage_Du_Congelateur.wmv
2014-01-08 21:06 - 2014-01-08 21:06 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1 (1).wmv
2014-01-08 21:04 - 2014-01-08 21:04 - 00613399 _____ C:\Users\hp-doma\Downloads\rasante_Besserung.wmv
2014-01-08 21:02 - 2014-01-08 21:02 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1 (1).WMV
2014-01-08 21:02 - 2014-01-08 21:02 - 00583082 _____ C:\Users\hp-doma\Downloads\klingel-eisen_1.wmv
2014-01-08 21:01 - 2014-01-08 21:01 - 00703840 _____ C:\Users\hp-doma\Downloads\GASOLI~1.WMV
2014-01-08 20:09 - 2014-01-08 20:08 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (3).exe
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\Malwarebytes
2014-01-08 19:00 - 2014-01-08 19:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-08 18:14 - 2014-01-08 18:13 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc (2).exe
2014-01-08 09:18 - 2014-01-08 09:17 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Desktop\ESET_Vzdalena_Pomoc (1).exe
2014-01-07 18:51 - 2014-01-07 18:50 - 03057648 _____ (TeamViewer) C:\Users\hp-doma\Downloads\ESET_Vzdalena_Pomoc.exe
2014-01-04 22:58 - 2014-01-04 22:58 - 00021527 _____ C:\Users\hp-doma\Desktop\ob-podminky-nejstavebniny.odt
2014-01-04 21:06 - 2010-10-27 08:50 - 00000000 ____D C:\Windows\Minidump
2014-01-04 20:30 - 2014-01-04 20:29 - 00000000 ____D C:\Users\hp-doma\AppData\Roaming\eCyber
2014-01-04 20:29 - 2014-01-04 20:29 - 00000000 ____D C:\Windows\system32\log
2014-01-04 20:29 - 2014-01-04 20:27 - 09366896 _____ C:\Users\hp-doma\Downloads\yet_another_cleaner.exe
2014-01-04 19:07 - 2013-10-21 20:10 - 00000000 ____D C:\Games
2014-01-04 19:06 - 2014-01-04 19:04 - 25098032 _____ C:\Users\hp-doma\Downloads\600_3D_Icons_PNG.rar
2014-01-04 17:39 - 2014-01-04 17:38 - 03280896 _____ C:\Users\hp-doma\Downloads\Mail.exe
2014-01-03 18:49 - 2014-01-03 18:49 - 00012493 _____ C:\Users\hp-doma\Downloads\1-organizace.odt
2014-01-02 21:23 - 2014-01-02 21:23 - 00001912 _____ C:\Windows\epplauncher.mif
2014-01-02 21:23 - 2014-01-02 21:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2014-01-02 21:23 - 2014-01-02 21:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2014-01-02 21:21 - 2014-01-02 21:21 - 13693624 _____ (Microsoft Corporation) C:\Users\hp-doma\Downloads\mseinstall.exe
2014-01-02 21:00 - 2014-01-02 21:00 - 00000892 _____ C:\Users\hp-doma\Documents\posrany netdevelo.txt
2013-12-28 10:09 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
Some content of TEMP:
====================
C:\Users\hp-doma\AppData\Local\Temp\tmpC189.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-19 10:37
==================== End Of Log ============================