Kontrola logu - BetterSurf
Napsal: 31 led 2014 09:33
Zdravím, před pár dny na mě začali vyskakovat Pop-up okna, zobrazovat se reklamy "Ads by BetterSurf" a podtrhávat text, z kterého se dělají odkazy. Program jsem odinstaloval, ručně prohledal registry a smazal zbytky, také z logu poznáte, že jsem použil různé programy na odstranění havěti a stejně reklama nezmizela. Prosil bych tedy o kontrolu logu a radu, co dál.
- Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01
Ran by Jirka a Aneta (administrator) on JAHNOVI on 31-01-2014 09:24:12
Running from C:\Users\Jirka a Aneta\Desktop
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(ClanServers Hosting LLC) C:\Program Files (x86)\GameTracker\GSInGameService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ASUS) C:\Windows\AsScrPro.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Users\Jirka a Aneta\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Jirka a Aneta\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(APN LLC.) C:\Users\Jirka a Aneta\AppData\Local\VNT\vntldr.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Pandora.TV) C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Jirka a Aneta\Desktop\FRSTLauncher (2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-08-12] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.)
HKLM\...\Run: [EeeStorageBackup] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1732608 2009-11-26] ()
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-20] (ASUS)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [VNT] - C:\Program Files (x86)\VNT\vntldr.exe [195536 2014-01-06] (APN LLC.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [] - [x]
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [802136 2013-05-02] (BitTorrent Inc.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Jirka a Aneta\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Jirka a Aneta\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe -update plugin [839560 2013-12-12] (Adobe Systems Incorporated)
HKCU\...\Policies\Explorer\Run: [Piranha Games] - C:\Users\Jirka a Aneta\AppData\Roaming\A92E75\A92E75.exe [45128 2009-07-14] ( (Microsoft Corporation))
Startup: C:\Users\Tata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.alawarhry.cz
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {3FFD3656-3884-4FDB-8935-E6A1B83AFAC8} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {6D9B577E-0BA2-4CAA-9381-EBCEECD2F5F1} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {7988364B-E115-4FD2-9CB2-DC67042BDFC9} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {79CDD03F-56AA-4774-A4EF-E1EDD363ECAC} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {89E8D30F-1080-4466-8C8F-6D36A547102A} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {9051C4E3-9AC0-401A-980D-A14E0FBCCD41} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {EB931DF8-5051-4FAE-9110-42274C835AA7} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {EF2812D8-7E04-4D19-96A9-7F10F30BFBA5} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO-x32: No Name - {68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} - No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 02 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.132.12.33 10.132.12.1
FireFox:
========
FF ProfilePath: C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.jobego.com/search/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @ogplanet.com/npOGPPlugin - C:\Windows\system32\npOGPPlugin.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin HKCU: @facebook.com/FBPlugin,version=1.0.3 - C:\Users\Jirka a Aneta\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jirka a Aneta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\searchplugins\jobegocom.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Vagex Firefox Add-On - C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\Extensions\ffaddon@vagex.com [2013-03-29]
FF Extension: VideoFileDownload - Download YouTube Videos - C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\Extensions\plugin@videofiledownload.com [2012-07-06]
FF Extension: The Saloon Bar - C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\Extensions\saloonbar@ligny.org.uk [2011-02-18]
FF Extension: Seznam lištička - C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-05-17]
FF Extension: Illimitux - C:\Users\Jirka a Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\sz0rqy03.default\Extensions\illimitux@illimitux.net.xpi [2011-07-31]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-03-11]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-04-27]
FF HKLM-x32\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files (x86)\BetterSurf\ff
FF HKLM-x32\...\Firefox\Extensions: [12x3q@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha510.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha510\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta63.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta63\ff
FF Extension: Video Player - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta63\ff [2014-01-10]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha142.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha142\ff
FF Extension: Media Player - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha142\ff [2014-01-29]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: https://www.google.cz/?gws_rd=cr
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Windows Genuine Advantage) - C:\Program Files (x86)\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
CHR Plugin: (Unity Player) - C:\Users\Jirka a Aneta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Facebook Plugin) - C:\Users\Jirka a Aneta\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
CHR Extension: (Angry Birds) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2012-03-01]
CHR Extension: (YouTube) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19]
CHR Extension: (Media Player) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdmlifmcodeplijdlfnanamghkiidoij [2014-01-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (AdBlock) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-06-15]
CHR Extension: (Peněženka Google) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Battlefield Play4Free) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2013-04-21]
CHR Extension: (Video Player) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfekkhdmhmddhjhfmkmfhojbjlihbopc [2014-01-10]
CHR Extension: (Gmail) - C:\Users\Jirka a Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR HKCU\...\Chrome\Extension: [bdkdmpigoicnmdhmhiafmpcfnfgpfnol] - C:\Users\Jirka a Aneta\AppData\Local\CRE\bdkdmpigoicnmdhmhiafmpcfnfgpfnol.crx [2011-12-19]
CHR HKLM-x32\...\Chrome\Extension: [aaaajfocmnnhjaajccaelhippajhaeod] - C:\ProgramData\AskPartnerNetwork\Toolbar\ATU4-V7\CRX\ToolbarCR.crx [2014-01-06]
CHR HKLM-x32\...\Chrome\Extension: [bdkdmpigoicnmdhmhiafmpcfnfgpfnol] - C:\Users\Jirka a Aneta\AppData\Local\CRE\bdkdmpigoicnmdhmhiafmpcfnfgpfnol.crx [2014-01-06]
CHR HKLM-x32\...\Chrome\Extension: [egnimkioipookhfihpljiedpgjffibpa] - C:\Program Files (x86)\MyBrowserCash\MBC_chrome.crx [2014-01-06]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
CHR HKLM-x32\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Users\JIRKAA~1\AppData\Local\Temp\crxE74B.tmp [2013-10-09]
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx [2013-10-09]
CHR HKLM-x32\...\Chrome\Extension: [pfekkhdmhmddhjhfmkmfhojbjlihbopc] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta63\ch\VideoPlayerV3beta63.crx [2014-01-07]
CHR HKLM-x32\...\Chrome\Extension: [pjbnadgnhhkoohnkddbceoldfibijgpk] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha510\ch\WebexpEnhancedV1alpha510.crx [2014-01-07]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [2014-01-07]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-11] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-01-06] (APN LLC.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3849720 2012-09-02] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-09] ()
S3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [x]
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{94b33d1b-8557-37a1-49e7-1f0e14014fb9}\ \...\???\{94b33d1b-8557-37a1-49e7-1f0e14014fb9}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-07-17] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-11] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-05-31] (DT Soft Ltd)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-07-17] ()
S3 M1000Srv; C:\Windows\System32\Drivers\M1000KNT.sys [506496 2012-03-05] ()
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-03] (INCA Internet Co., Ltd.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-05-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-01-23] ()
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
S3 TS_AR5416; C:\Windows\System32\DRIVERS\ts_athwx.sys [2156872 2011-09-05] (TamoSoft)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S3 ALSysIO; \??\C:\Users\JIRKAA~1\AppData\Local\Temp\ALSysIO64.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 dump_wmimmc; \??\D:\Jirka\GamesCampus\DriftCity\GameGuard\dump_wmimmc.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42840 2009-06-10] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;
S3 usbbus; system32\DRIVERS\lgx64bus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [x]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [x]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-31 09:24 - 2014-01-31 09:24 - 00029833 _____ C:\Users\Jirka a Aneta\Desktop\FRST.txt
2014-01-31 09:24 - 2014-01-31 09:24 - 00000000 ____D C:\FRST
2014-01-31 09:20 - 2014-01-31 09:20 - 00030014 _____ C:\Users\Jirka a Aneta\Desktop\Stargate-Universe-S01E11(0000152882).srt
2014-01-31 09:19 - 2014-01-31 09:19 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka a Aneta\Desktop\FRSTLauncher (2).exe
2014-01-31 09:17 - 2014-01-31 09:18 - 02079744 _____ (Farbar) C:\Users\Jirka a Aneta\Desktop\FRST64.exe
2014-01-30 23:48 - 2014-01-30 23:48 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-30 23:48 - 2014-01-30 23:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 23:48 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-30 23:43 - 2014-01-30 23:43 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jirka a Aneta\Desktop\mbam-setup-1.75.0.1300.exe
2014-01-30 15:33 - 2014-01-30 15:33 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2014-01-30 15:33 - 2014-01-30 15:33 - 00000764 _____ C:\Windows\system32\bootdelete.lst
2014-01-30 15:18 - 2014-01-30 15:34 - 00000000 ____D C:\ProgramData\HitmanPro
2014-01-30 14:51 - 2014-01-30 14:51 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Malwarebytes
2014-01-30 14:50 - 2014-01-30 14:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-30 14:39 - 2014-01-30 14:39 - 00000000 ____D C:\Windows\ERUNT
2014-01-30 14:27 - 2014-01-30 14:31 - 00000000 ____D C:\AdwCleaner
2014-01-29 23:48 - 2014-01-29 23:48 - 00000270 __RSH C:\ProgramData\ntuser.pol
2014-01-29 23:48 - 2014-01-29 23:48 - 00000000 ____D C:\Program Files (x86)\MediaPlayerV1
2014-01-26 09:35 - 2014-01-26 19:01 - 00000000 ____D C:\Users\Jirka a Aneta\Documents\ArcaniA - Gothic 4
2014-01-26 09:35 - 2014-01-26 09:35 - 00000000 __SHD C:\ProgramData\SecuROM
2014-01-24 21:59 - 2014-01-24 21:59 - 00000221 _____ C:\Users\Jirka a Aneta\Desktop\ArcaniA Gothic 4.url
2014-01-23 21:45 - 2014-01-23 21:45 - 00001135 _____ C:\Users\Jirka a Aneta\Desktop\Nový textový dokument.TXT
2014-01-19 16:16 - 2014-01-19 16:16 - 00000000 _____ C:\Windows\WindowsUpdate.log
2014-01-18 18:08 - 2014-01-18 18:08 - 00000221 _____ C:\Users\Jirka a Aneta\Desktop\Arma 2.url
2014-01-14 18:01 - 2014-01-14 18:01 - 00001016 _____ C:\Users\Public\Desktop\Mumble.lnk
2014-01-13 18:46 - 2014-01-13 18:46 - 00001238 _____ C:\Users\Jirka a Aneta\Desktop\TeamSpeak 3 Client.lnk
2014-01-13 18:46 - 2014-01-13 18:46 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-01-13 18:46 - 2014-01-13 18:46 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\TeamSpeak 3 Client
2014-01-13 16:48 - 2014-01-13 17:22 - 590753870 _____ C:\Users\Jirka a Aneta\Desktop\Quiet-Rage---The-Stanford-Prison-Experiment.mov
2014-01-11 14:50 - 2014-01-11 14:50 - 00000000 ____D C:\Users\Jirka a Aneta\Desktop\AS51
2014-01-10 20:36 - 2014-01-10 20:36 - 00002996 _____ C:\Windows\System32\Tasks\{6F1413CC-D5A1-40D3-93F3-D4B4CADEB814}
2014-01-10 20:35 - 2014-01-10 20:35 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\com.immersyve.Paladin.live
2014-01-10 18:48 - 2014-01-10 18:48 - 00000000 ____D C:\Program Files (x86)\VideoPlayerV3
2014-01-10 08:28 - 2014-01-10 08:28 - 00001082 _____ C:\Users\Jirka a Aneta\Desktop\Wow – zástupce.lnk
2014-01-08 19:30 - 2014-01-30 15:09 - 00004652 _____ C:\Windows\PFRO.log
2014-01-05 14:18 - 2014-01-05 14:18 - 00000770 _____ C:\Users\Public\Desktop\Game Dev Tycoon.lnk
2014-01-01 14:40 - 2014-01-01 14:40 - 00000000 ____D C:\Users\Jirka a Aneta\Documents\SavedGames
==================== One Month Modified Files and Folders =======
2014-01-31 09:24 - 2014-01-31 09:24 - 00029833 _____ C:\Users\Jirka a Aneta\Desktop\FRST.txt
2014-01-31 09:24 - 2014-01-31 09:24 - 00000000 ____D C:\FRST
2014-01-31 09:23 - 2010-02-02 17:52 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Skype
2014-01-31 09:20 - 2014-01-31 09:20 - 00030014 _____ C:\Users\Jirka a Aneta\Desktop\Stargate-Universe-S01E11(0000152882).srt
2014-01-31 09:19 - 2014-01-31 09:19 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka a Aneta\Desktop\FRSTLauncher (2).exe
2014-01-31 09:18 - 2014-01-31 09:17 - 02079744 _____ (Farbar) C:\Users\Jirka a Aneta\Desktop\FRST64.exe
2014-01-31 09:00 - 2011-03-15 19:04 - 00000966 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-31 08:59 - 2013-02-23 09:52 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-31 01:23 - 2012-08-23 21:20 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\uTorrent
2014-01-30 23:48 - 2014-01-30 23:48 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-30 23:48 - 2014-01-30 23:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 23:43 - 2014-01-30 23:43 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jirka a Aneta\Desktop\mbam-setup-1.75.0.1300.exe
2014-01-30 18:53 - 2012-02-10 08:29 - 00000000 ____D C:\Program Files (x86)\Steam
2014-01-30 15:46 - 2011-03-15 19:04 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-30 15:34 - 2014-01-30 15:18 - 00000000 ____D C:\ProgramData\HitmanPro
2014-01-30 15:33 - 2014-01-30 15:33 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2014-01-30 15:33 - 2014-01-30 15:33 - 00000764 _____ C:\Windows\system32\bootdelete.lst
2014-01-30 15:19 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-30 15:19 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-30 15:16 - 2013-05-17 11:26 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Seznam.cz
2014-01-30 15:09 - 2014-01-08 19:30 - 00004652 _____ C:\Windows\PFRO.log
2014-01-30 15:09 - 2013-12-14 14:35 - 00004514 _____ C:\Windows\setupact.log
2014-01-30 15:09 - 2009-12-26 21:30 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-30 15:09 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-30 15:08 - 2013-10-07 18:14 - 00000000 __SHD C:\Users\Jirka a Aneta\fxiuy
2014-01-30 14:51 - 2014-01-30 14:51 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Malwarebytes
2014-01-30 14:50 - 2014-01-30 14:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-30 14:39 - 2014-01-30 14:39 - 00000000 ____D C:\Windows\ERUNT
2014-01-30 14:31 - 2014-01-30 14:27 - 00000000 ____D C:\AdwCleaner
2014-01-30 14:29 - 2010-01-23 14:31 - 00000000 ____D C:\ProgramData\ICQ
2014-01-29 23:48 - 2014-01-29 23:48 - 00000270 __RSH C:\ProgramData\ntuser.pol
2014-01-29 23:48 - 2014-01-29 23:48 - 00000000 ____D C:\Program Files (x86)\MediaPlayerV1
2014-01-29 23:48 - 2010-01-21 18:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-29 23:48 - 2009-07-14 04:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2014-01-29 23:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2014-01-29 15:20 - 2012-10-05 12:22 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\PMB Files
2014-01-28 23:31 - 2013-04-03 18:27 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\CrashDumps
2014-01-28 13:25 - 2013-08-29 11:13 - 00000000 ____D C:\Users\Jirka a Aneta\Desktop\Přidat
2014-01-26 19:01 - 2014-01-26 09:35 - 00000000 ____D C:\Users\Jirka a Aneta\Documents\ArcaniA - Gothic 4
2014-01-26 09:35 - 2014-01-26 09:35 - 00000000 __SHD C:\ProgramData\SecuROM
2014-01-26 09:34 - 2013-12-21 17:40 - 00052881 _____ C:\Windows\DirectX.log
2014-01-24 21:59 - 2014-01-24 21:59 - 00000221 _____ C:\Users\Jirka a Aneta\Desktop\ArcaniA Gothic 4.url
2014-01-24 21:02 - 2009-08-03 21:00 - 00672386 _____ C:\Windows\system32\perfh005.dat
2014-01-24 21:02 - 2009-08-03 21:00 - 00142950 _____ C:\Windows\system32\perfc005.dat
2014-01-24 21:02 - 2009-07-14 06:13 - 01592850 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-23 21:45 - 2014-01-23 21:45 - 00001135 _____ C:\Users\Jirka a Aneta\Desktop\Nový textový dokument.TXT
2014-01-22 19:49 - 2012-01-16 16:38 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\TS3Client
2014-01-19 16:16 - 2014-01-19 16:16 - 00000000 _____ C:\Windows\WindowsUpdate.log
2014-01-18 18:08 - 2014-01-18 18:08 - 00000221 _____ C:\Users\Jirka a Aneta\Desktop\Arma 2.url
2014-01-16 18:49 - 2010-02-02 12:26 - 00000600 _____ C:\Users\Jirka a Aneta\AppData\Roaming\winscp.rnd
2014-01-15 18:39 - 2011-05-26 17:20 - 06942208 ___SH C:\Users\Jirka a Aneta\Desktop\Thumbs.db
2014-01-14 18:01 - 2014-01-14 18:01 - 00001016 _____ C:\Users\Public\Desktop\Mumble.lnk
2014-01-14 18:01 - 2012-01-12 17:40 - 00000000 ____D C:\Program Files (x86)\Mumble
2014-01-13 18:46 - 2014-01-13 18:46 - 00001238 _____ C:\Users\Jirka a Aneta\Desktop\TeamSpeak 3 Client.lnk
2014-01-13 18:46 - 2014-01-13 18:46 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-01-13 18:46 - 2014-01-13 18:46 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\TeamSpeak 3 Client
2014-01-13 17:22 - 2014-01-13 16:48 - 590753870 _____ C:\Users\Jirka a Aneta\Desktop\Quiet-Rage---The-Stanford-Prison-Experiment.mov
2014-01-11 14:50 - 2014-01-11 14:50 - 00000000 ____D C:\Users\Jirka a Aneta\Desktop\AS51
2014-01-10 20:57 - 2013-10-07 19:15 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2014-01-10 20:36 - 2014-01-10 20:36 - 00002996 _____ C:\Windows\System32\Tasks\{6F1413CC-D5A1-40D3-93F3-D4B4CADEB814}
2014-01-10 20:35 - 2014-01-10 20:35 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Roaming\com.immersyve.Paladin.live
2014-01-10 20:11 - 2012-11-21 15:24 - 00000000 __SHD C:\Users\Jirka a Aneta\Userdata
2014-01-10 18:48 - 2014-01-10 18:48 - 00000000 ____D C:\Program Files (x86)\VideoPlayerV3
2014-01-10 08:28 - 2014-01-10 08:28 - 00001082 _____ C:\Users\Jirka a Aneta\Desktop\Wow – zástupce.lnk
2014-01-09 21:18 - 2013-05-17 11:42 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\Game Dev Tycoon
2014-01-09 17:21 - 2013-07-23 16:58 - 00000000 ____D C:\Users\Jirka a Aneta\Desktop\Anet
2014-01-09 17:19 - 2011-01-11 14:31 - 00000000 ___RD C:\Users\Jirka a Aneta\Desktop\Jjohny
2014-01-06 14:11 - 2013-11-08 14:44 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\VNT
2014-01-06 14:10 - 2013-11-08 14:44 - 00000000 ____D C:\Program Files (x86)\VNT
2014-01-05 14:18 - 2014-01-05 14:18 - 00000770 _____ C:\Users\Public\Desktop\Game Dev Tycoon.lnk
2014-01-01 20:47 - 2012-08-26 08:39 - 00000000 ____D C:\Users\Jirka a Aneta\AppData\Local\FalloutNV
2014-01-01 14:40 - 2014-01-01 14:40 - 00000000 ____D C:\Users\Jirka a Aneta\Documents\SavedGames
ZeroAccess:
C:\Users\Jirka a Aneta\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install
Some content of TEMP:
====================
C:\Users\Aňula\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jirka a Aneta\AppData\Local\Temp\avgnt.exe
C:\Users\Jirka a Aneta\AppData\Local\Temp\HitmanPro.exe
C:\Users\Jirka a Aneta\AppData\Local\Temp\Quarantine.exe
C:\Users\Tata\AppData\Local\Temp\avgnt.exe
C:\Users\Tata\AppData\Local\Temp\NOSEventMessages.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-19 09:33
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (OS) (Fixed) (Total:116.44 GB) (Free:13.81 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:334.67 GB) (Free:56.03 GB) NTFS
Available physical RAM: 1746.97 MB
Total physical RAM: 4095.27 MB
Percentage of memory in use: 57%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 76692CA8)
Partition 1: (Not Active) - (Size=15 GB) - (Type=1C)
Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=335 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows\System32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
AlternateDataStreams: C:\ProgramData\Temp:07F6D9E4
AlternateDataStreams: C:\ProgramData\Temp:15024E60
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:596E2371
AlternateDataStreams: C:\ProgramData\Temp:68C295D4
AlternateDataStreams: C:\ProgramData\Temp:734E442A
AlternateDataStreams: C:\ProgramData\Temp:75D366A3
AlternateDataStreams: C:\ProgramData\Temp:A724744F
AlternateDataStreams: C:\ProgramData\Temp:A8ADE5D8
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:B88E99C8
AlternateDataStreams: C:\ProgramData\Temp:BB24555F
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
==================== Security Center ==================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka a Aneta\Desktop" je 4655 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector
C:\Windows\AsScrPro.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_Plugin.exe -update plugin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU
C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Soluto
c:\program files\soluto\soluto.exe /init [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files (x86)\Steam\steam.exe" -silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
"C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ JCC - AutoClickerBot.lnk
C:\JCC-AU~1\JCC-AU~1.EXE
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================