Vir z Facebook
Napsal: 12 úno 2014 22:33
Dobrý den , někdo mi poslal na facebooku nějaký odkaz (je to asi vir nebo červ či co) , Eset Smart security mi hlásí toto : 21:30:21 Kontrola při startu soubor Operační paměť » C:\Windows\SysWOW64\notepad.exe varianta infiltrace Win32/Agent.NNF červ nelze léčit. Eset mám Zkušební verzi (plánuji koupit po uplynutí TRIAL verze). Myslím si že zde měl stejný problém jako já : http://forum.viry.cz/viewtopic.php?f=13&t=135768 Tak jsem udělal log z FRST (nevím jestli jsem to udělal dobře ale snažil jsem se řídit podle návodu)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2014
Ran by Šejpák (administrator) on SEJPAKPC on 12-02-2014 22:19:45
Running from C:\Users\Šejpák\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(LogMeIn Inc.) D:\Data\Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Data\Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-12-25] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [OODefragTray] - C:\Program Files\OO Software\Defrag\oodtray.exe [4464936 2014-01-24] (O&O Software GmbH)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
AppInit_DLLs: => File Not Found
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Extension: (Disk Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-24]
CHR Extension: (YouTube) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-24]
CHR Extension: (Peněženka Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-24]
CHR Extension: (Gmail) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-24]
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 Hamachi2Svc; D:\Data\Hamachi\hamachi-2.exe [2221904 2014-01-23] (LogMeIn Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1657128 2014-01-24] (O&O Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-15] ()
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros)
==================== Drivers (Whitelisted) ====================
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-25] (Intel Corporation)
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2013-12-25] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8244312 2013-12-25] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-12-25] (Synaptics Incorporated)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va016; \??\C:\Windows\SysWOW64\Drivers\X6va016 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-12 22:19 - 2014-02-12 22:19 - 00009285 _____ () C:\Users\Šejpák\Desktop\FRST.txt
2014-02-12 22:17 - 2014-02-12 22:17 - 00112640 _____ (forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
2014-02-12 22:02 - 2014-02-12 21:53 - 02152448 _____ (Farbar) C:\Users\Šejpák\Desktop\FRST64.exe
2014-02-12 21:53 - 2014-02-12 22:19 - 00000000 ____D () C:\FRST
2014-02-12 18:55 - 2014-02-12 18:55 - 00108816 _____ () C:\Users\Šejpák\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-12 18:41 - 2014-02-12 18:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\{9620c625-c254-6b6a-3461-87549620c625}
2014-02-12 16:37 - 2014-02-12 16:37 - 00002005 _____ () C:\Users\Šejpák\Desktop\ESET Smart Security.lnk
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\ProgramData\ESET
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\Program Files\ESET
2014-02-12 14:51 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-12 14:51 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-12 14:51 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-12 14:51 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-12 14:51 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-12 14:51 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-12 14:51 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-12 14:51 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-12 14:51 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-12 14:51 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-12 14:51 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-12 14:51 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-12 14:51 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-12 14:51 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-12 14:51 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-12 14:51 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-12 14:51 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-12 14:51 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-12 14:51 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-12 14:51 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-12 14:51 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-12 14:51 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-12 14:51 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-12 14:51 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-12 14:51 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-12 14:51 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-12 14:51 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-12 14:51 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-12 14:51 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-12 14:51 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-12 14:51 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-12 14:51 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-12 14:51 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-12 14:51 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-12 14:51 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-12 14:51 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-12 14:51 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-12 14:51 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-12 14:51 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-12 14:51 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 14:51 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 14:50 - 2014-02-11 14:53 - 01703936 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Multiplayer.exe
2014-02-12 14:23 - 2014-02-12 14:29 - 2382292992 _____ () C:\Users\Šejpák\Downloads\Crysis 3.iso
2014-02-12 14:11 - 2014-02-12 14:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashRpt
2014-02-12 07:57 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-12 07:57 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 07:57 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 07:57 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 07:57 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 07:57 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 07:57 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 07:57 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 07:57 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 07:57 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 07:57 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-12 07:57 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-12 07:57 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-12 07:57 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 07:57 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 19:08 - 2014-02-11 19:08 - 00000877 _____ () C:\Users\Šejpák\Desktop\sims.txt
2014-02-11 16:12 - 2014-02-11 16:12 - 00000646 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Singleplayer.lnk
2014-02-11 14:47 - 2014-02-11 14:47 - 00000256 _____ () C:\Windows\game.ini
2014-02-01 17:05 - 2014-02-01 17:05 - 00000132 _____ () C:\Users\Šejpák\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-02-01 16:44 - 2014-02-01 17:03 - 00001100 _____ () C:\Users\Šejpák\Desktop\Adobe Photoshop CC (64 Bit).lnk
2014-02-01 16:36 - 2014-02-01 16:36 - 00003504 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-SejpakPC-Šejpák
2014-02-01 16:36 - 2014-02-01 16:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\PDAppFlex
2014-02-01 16:27 - 2014-02-01 16:32 - 00000000 ____D () C:\Program Files\Adobe
2014-02-01 16:11 - 2014-02-01 16:11 - 00001074 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-01-30 19:03 - 2014-01-30 19:03 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft Games
2014-01-30 19:01 - 2014-01-30 19:01 - 00002155 _____ () C:\Users\Public\Desktop\Rise of Nations Gold.lnk
2014-01-30 19:00 - 2014-01-30 19:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-01-24 14:32 - 2014-01-24 14:32 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr
2014-01-24 14:32 - 2014-01-24 14:32 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll
2014-01-24 14:32 - 2014-01-24 14:32 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe
2014-01-24 14:32 - 2014-01-24 14:32 - 00010536 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll
2014-01-23 15:36 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-23 15:36 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-21 07:28 - 2014-01-21 07:28 - 00000625 _____ () C:\Users\Public\Desktop\4Story.lnk
2014-01-20 22:38 - 2014-01-20 22:38 - 00000000 ____D () C:\Users\Šejpák\Documents\RtsCam
2014-01-20 19:30 - 2014-01-20 19:30 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-01-18 10:57 - 2014-01-18 10:57 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Publish Providers
2014-01-16 13:12 - 2014-01-16 15:42 - 00000222 _____ () C:\Users\Šejpák\Desktop\Total War ROME II.url
2014-01-16 13:12 - 2014-01-16 13:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-01-15 23:31 - 2014-01-20 21:11 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-01-15 23:31 - 2014-01-15 23:31 - 00000779 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-01-15 23:31 - 2014-01-15 23:31 - 00000763 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-01-15 21:05 - 2014-02-12 14:32 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-01-15 21:05 - 2014-01-15 21:05 - 00000967 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-01-15 06:21 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 06:21 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 06:21 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
2014-02-12 22:19 - 2014-02-12 22:19 - 00009285 _____ () C:\Users\Šejpák\Desktop\FRST.txt
2014-02-12 22:19 - 2014-02-12 21:53 - 00000000 ____D () C:\FRST
2014-02-12 22:17 - 2014-02-12 22:17 - 00112640 _____ (forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
2014-02-12 21:54 - 2013-12-24 19:36 - 00000000 ___RD () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-12 21:53 - 2014-02-12 22:02 - 02152448 _____ (Farbar) C:\Users\Šejpák\Desktop\FRST64.exe
2014-02-12 21:36 - 2014-01-04 19:52 - 01354116 _____ () C:\Windows\WindowsUpdate.log
2014-02-12 21:26 - 2013-12-25 01:27 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-12 19:59 - 2013-12-25 01:40 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Skype
2014-02-12 18:55 - 2014-02-12 18:55 - 00108816 _____ () C:\Users\Šejpák\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-12 18:44 - 2013-12-24 23:58 - 00000342 _____ () C:\Windows\Tasks\dsmonitor.job
2014-02-12 18:41 - 2014-02-12 18:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\{9620c625-c254-6b6a-3461-87549620c625}
2014-02-12 18:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-12 16:37 - 2014-02-12 16:37 - 00002005 _____ () C:\Users\Šejpák\Desktop\ESET Smart Security.lnk
2014-02-12 16:09 - 2009-07-14 05:45 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:09 - 2009-07-14 05:45 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:08 - 2010-11-21 10:27 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-02-12 16:08 - 2010-11-21 10:27 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-02-12 16:08 - 2009-07-14 06:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\ProgramData\ESET
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\Program Files\ESET
2014-02-12 16:02 - 2013-12-24 20:21 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-12 16:02 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-12 14:55 - 2013-12-25 00:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-12 14:52 - 2013-12-24 20:20 - 01559268 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-12 14:52 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2014-02-12 14:32 - 2014-01-15 21:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-12 14:30 - 2013-12-24 19:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\VirtualStore
2014-02-12 14:29 - 2014-02-12 14:23 - 2382292992 _____ () C:\Users\Šejpák\Downloads\Crysis 3.iso
2014-02-12 14:11 - 2014-02-12 14:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashRpt
2014-02-12 14:11 - 2013-12-24 23:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-12 14:11 - 2013-12-24 23:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-12 07:17 - 2013-12-25 01:27 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\Adobe
2014-02-11 19:08 - 2014-02-11 19:08 - 00000877 _____ () C:\Users\Šejpák\Desktop\sims.txt
2014-02-11 16:12 - 2014-02-11 16:12 - 00000646 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Singleplayer.lnk
2014-02-11 14:53 - 2014-02-12 14:50 - 01703936 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Multiplayer.exe
2014-02-11 14:51 - 2013-12-24 20:11 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-11 14:47 - 2014-02-11 14:47 - 00000256 _____ () C:\Windows\game.ini
2014-02-10 14:06 - 2013-12-25 00:00 - 00002497 _____ () C:\Users\Public\Desktop\O&O Defrag.lnk
2014-02-07 19:16 - 2014-01-10 19:09 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-02-06 13:16 - 2014-02-12 14:51 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-12 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-12 14:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-12 14:51 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-12 14:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-12 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-12 14:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-12 14:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-12 14:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-12 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-12 14:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-12 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-12 14:51 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-12 14:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-12 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-12 14:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-12 14:51 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-12 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-12 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-12 14:51 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-12 14:51 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-12 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-12 14:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-12 14:51 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-12 14:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-12 14:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-12 14:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-12 14:51 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-12 14:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-12 14:51 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-12 14:51 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-12 14:51 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-12 14:51 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-12 14:51 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-12 14:51 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-12 14:51 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-12 14:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-12 14:51 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-12 14:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 18:29 - 2013-12-25 20:53 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-05 17:59 - 2013-12-25 20:53 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-05 17:50 - 2013-12-25 20:10 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-02-04 22:26 - 2013-12-25 01:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-04 22:26 - 2013-12-25 01:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-04 22:26 - 2013-12-25 01:27 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-04 13:13 - 2013-12-24 23:00 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-02 20:24 - 2013-12-28 17:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\TS3Client
2014-02-01 23:03 - 2013-12-26 01:13 - 00001198 _____ () C:\Windows\system32\RTCM_Config.ini
2014-02-01 18:40 - 2013-12-25 02:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashDumps
2014-02-01 17:05 - 2014-02-01 17:05 - 00000132 _____ () C:\Users\Šejpák\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-02-01 17:03 - 2014-02-01 16:44 - 00001100 _____ () C:\Users\Šejpák\Desktop\Adobe Photoshop CC (64 Bit).lnk
2014-02-01 16:36 - 2014-02-01 16:36 - 00003504 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-SejpakPC-Šejpák
2014-02-01 16:36 - 2014-02-01 16:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\PDAppFlex
2014-02-01 16:32 - 2014-02-01 16:27 - 00000000 ____D () C:\Program Files\Adobe
2014-02-01 16:31 - 2013-12-27 00:11 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-01 16:31 - 2013-12-25 01:29 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-01 16:26 - 2013-12-24 19:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Adobe
2014-02-01 16:25 - 2013-12-25 01:29 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-01 16:11 - 2014-02-01 16:11 - 00001074 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-02-01 12:48 - 2014-01-10 17:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\LogMeIn Hamachi
2014-02-01 12:46 - 2013-12-25 21:49 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-01 12:46 - 2013-12-25 21:49 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-31 17:04 - 2013-12-25 20:10 - 00000000 ____D () C:\ProgramData\Origin
2014-01-30 19:19 - 2014-01-10 17:41 - 00000606 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-01-30 19:15 - 2013-12-25 02:21 - 00000000 ____D () C:\Users\Šejpák\Documents\My Games
2014-01-30 19:03 - 2014-01-30 19:03 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft Games
2014-01-30 19:01 - 2014-01-30 19:01 - 00002155 _____ () C:\Users\Public\Desktop\Rise of Nations Gold.lnk
2014-01-30 19:00 - 2014-01-30 19:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-01-26 08:50 - 2009-07-14 06:08 - 00032544 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-24 14:32 - 2014-01-24 14:32 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr
2014-01-24 14:32 - 2014-01-24 14:32 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll
2014-01-24 14:32 - 2014-01-24 14:32 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe
2014-01-24 14:32 - 2014-01-24 14:32 - 00010536 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll
2014-01-23 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-23 15:36 - 2013-12-24 20:21 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-01-21 07:28 - 2014-01-21 07:28 - 00000625 _____ () C:\Users\Public\Desktop\4Story.lnk
2014-01-21 03:53 - 2013-12-24 20:21 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-01-21 03:53 - 2013-12-24 20:21 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-01-20 22:38 - 2014-01-20 22:38 - 00000000 ____D () C:\Users\Šejpák\Documents\RtsCam
2014-01-20 21:11 - 2014-01-15 23:31 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-01-20 20:29 - 2013-12-25 20:10 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-01-20 19:30 - 2014-01-20 19:30 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-01-19 23:28 - 2013-12-27 03:48 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Sony
2014-01-19 22:58 - 2013-12-25 01:26 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-18 10:57 - 2014-01-18 10:57 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Publish Providers
2014-01-18 10:51 - 2014-01-12 21:47 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\TeamViewer
2014-01-18 10:34 - 2013-12-24 23:55 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-01-16 15:42 - 2014-01-16 13:12 - 00000222 _____ () C:\Users\Šejpák\Desktop\Total War ROME II.url
2014-01-16 13:12 - 2014-01-16 13:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-01-15 23:31 - 2014-01-15 23:31 - 00000779 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-01-15 23:31 - 2014-01-15 23:31 - 00000763 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-01-15 23:31 - 2013-12-25 20:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-01-15 21:05 - 2014-01-15 21:05 - 00000967 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-01-15 07:37 - 2013-12-24 22:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 07:36 - 2013-12-24 22:34 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-13 21:18 - 2013-12-27 02:23 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-13 16:20 - 2013-12-27 02:21 - 00000000 ____D () C:\Users\Šejpák\Documents\Assassin's Creed IV Black Flag
Some content of TEMP:
====================
C:\Users\Šejpák\AppData\Local\Temp\InstHelper.exe
C:\Users\Šejpák\AppData\Local\Temp\speeditupfree-knowledge.exe
C:\Users\Šejpák\AppData\Local\Temp\ytdownloader_ww_setup_20140203.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 00:45
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:111.69 GB) (Free:46.17 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:783.05 GB) NTFS
Available physical RAM: 5927.44 MB
Total physical RAM: 8136.01 MB
Percentage of memory in use: 27%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: E291D752)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E291D72F)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\dsmonitor.job => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\Users\All Users:NT
AlternateDataStreams: C:\ProgramData\Application Data:NT
AlternateDataStreams: C:\ProgramData\Data aplikací:NT
AlternateDataStreams: C:\Users\Šejpák\Data aplikací:NT
AlternateDataStreams: C:\Users\Šejpák\AppData\Roaming:NT
==================== Security Center ==================
AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\�ejp�k\Desktop" je 3 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4StoryPrePatch
D:\Hry\4Story_CZ\PrePatch.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager
"C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bloody2
"C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cm108Sound
C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"D:\Data\Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskqcnisSrv
C:\Windows\inf\mskqcnis.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssiplSrv
"C:\Windows\system32\mssipl.vbe" mshfhcgi msbfbde [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswwkgSrv
C:\Windows\inf\mswwkg.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray
C:\Program Files\OO Software\Defrag\oodtray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printsrv
c:\Windows\System32\Printing_Admin_Scripts\en-US\pubpr.vbs [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Killer Network Manager.lnk
C:\Windows\Installer\{4E08CC97-912D-458B-8705-9A14C325532F}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe -minimize [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk
C:\Windows\Installer\{F17BA1CA-0FAF-40BF-A5FD-BF1B727D855E}\app_icon.ico [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Qualcomm Atheros Killer Network Manager.lnk
C:\PROGRA~1\QUALCO~1\KILLER~1\KILLER~1.EXE -minimized [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2014
Ran by Šejpák (administrator) on SEJPAKPC on 12-02-2014 22:19:45
Running from C:\Users\Šejpák\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(LogMeIn Inc.) D:\Data\Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Data\Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-12-25] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [OODefragTray] - C:\Program Files\OO Software\Defrag\oodtray.exe [4464936 2014-01-24] (O&O Software GmbH)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
AppInit_DLLs: => File Not Found
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Extension: (Disk Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-24]
CHR Extension: (YouTube) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-24]
CHR Extension: (Peněženka Google) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-24]
CHR Extension: (Gmail) - C:\Users\Šejpák\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-24]
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 Hamachi2Svc; D:\Data\Hamachi\hamachi-2.exe [2221904 2014-01-23] (LogMeIn Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1657128 2014-01-24] (O&O Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-15] ()
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros)
==================== Drivers (Whitelisted) ====================
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-25] (Intel Corporation)
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2013-12-25] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8244312 2013-12-25] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-12-25] (Synaptics Incorporated)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va016; \??\C:\Windows\SysWOW64\Drivers\X6va016 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-12 22:19 - 2014-02-12 22:19 - 00009285 _____ () C:\Users\Šejpák\Desktop\FRST.txt
2014-02-12 22:17 - 2014-02-12 22:17 - 00112640 _____ (forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
2014-02-12 22:02 - 2014-02-12 21:53 - 02152448 _____ (Farbar) C:\Users\Šejpák\Desktop\FRST64.exe
2014-02-12 21:53 - 2014-02-12 22:19 - 00000000 ____D () C:\FRST
2014-02-12 18:55 - 2014-02-12 18:55 - 00108816 _____ () C:\Users\Šejpák\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-12 18:41 - 2014-02-12 18:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\{9620c625-c254-6b6a-3461-87549620c625}
2014-02-12 16:37 - 2014-02-12 16:37 - 00002005 _____ () C:\Users\Šejpák\Desktop\ESET Smart Security.lnk
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\ProgramData\ESET
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\Program Files\ESET
2014-02-12 14:51 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-12 14:51 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-12 14:51 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-12 14:51 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-12 14:51 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-12 14:51 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-12 14:51 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-12 14:51 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-12 14:51 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-12 14:51 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-12 14:51 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-12 14:51 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-12 14:51 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-12 14:51 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-12 14:51 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-12 14:51 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-12 14:51 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-12 14:51 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-12 14:51 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-12 14:51 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-12 14:51 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-12 14:51 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-12 14:51 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-12 14:51 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-12 14:51 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-12 14:51 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-12 14:51 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-12 14:51 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-12 14:51 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-12 14:51 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-12 14:51 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-12 14:51 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-12 14:51 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-12 14:51 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-12 14:51 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-12 14:51 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-12 14:51 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-12 14:51 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-12 14:51 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-12 14:51 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 14:51 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 14:50 - 2014-02-11 14:53 - 01703936 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Multiplayer.exe
2014-02-12 14:23 - 2014-02-12 14:29 - 2382292992 _____ () C:\Users\Šejpák\Downloads\Crysis 3.iso
2014-02-12 14:11 - 2014-02-12 14:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashRpt
2014-02-12 07:57 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-12 07:57 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 07:57 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 07:57 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 07:57 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 07:57 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 07:57 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 07:57 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 07:57 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 07:57 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 07:57 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 07:57 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 07:57 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-12 07:57 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-12 07:57 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-12 07:57 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-12 07:57 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-12 07:57 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 07:57 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 19:08 - 2014-02-11 19:08 - 00000877 _____ () C:\Users\Šejpák\Desktop\sims.txt
2014-02-11 16:12 - 2014-02-11 16:12 - 00000646 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Singleplayer.lnk
2014-02-11 14:47 - 2014-02-11 14:47 - 00000256 _____ () C:\Windows\game.ini
2014-02-01 17:05 - 2014-02-01 17:05 - 00000132 _____ () C:\Users\Šejpák\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-02-01 16:44 - 2014-02-01 17:03 - 00001100 _____ () C:\Users\Šejpák\Desktop\Adobe Photoshop CC (64 Bit).lnk
2014-02-01 16:36 - 2014-02-01 16:36 - 00003504 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-SejpakPC-Šejpák
2014-02-01 16:36 - 2014-02-01 16:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\PDAppFlex
2014-02-01 16:27 - 2014-02-01 16:32 - 00000000 ____D () C:\Program Files\Adobe
2014-02-01 16:11 - 2014-02-01 16:11 - 00001074 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-01-30 19:03 - 2014-01-30 19:03 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft Games
2014-01-30 19:01 - 2014-01-30 19:01 - 00002155 _____ () C:\Users\Public\Desktop\Rise of Nations Gold.lnk
2014-01-30 19:00 - 2014-01-30 19:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-01-24 14:32 - 2014-01-24 14:32 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr
2014-01-24 14:32 - 2014-01-24 14:32 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll
2014-01-24 14:32 - 2014-01-24 14:32 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe
2014-01-24 14:32 - 2014-01-24 14:32 - 00010536 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll
2014-01-23 15:36 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-23 15:36 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-21 07:28 - 2014-01-21 07:28 - 00000625 _____ () C:\Users\Public\Desktop\4Story.lnk
2014-01-20 22:38 - 2014-01-20 22:38 - 00000000 ____D () C:\Users\Šejpák\Documents\RtsCam
2014-01-20 19:30 - 2014-01-20 19:30 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-01-18 10:57 - 2014-01-18 10:57 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Publish Providers
2014-01-16 13:12 - 2014-01-16 15:42 - 00000222 _____ () C:\Users\Šejpák\Desktop\Total War ROME II.url
2014-01-16 13:12 - 2014-01-16 13:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-01-15 23:31 - 2014-01-20 21:11 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-01-15 23:31 - 2014-01-15 23:31 - 00000779 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-01-15 23:31 - 2014-01-15 23:31 - 00000763 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-01-15 21:05 - 2014-02-12 14:32 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-01-15 21:05 - 2014-01-15 21:05 - 00000967 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-01-15 06:21 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 06:21 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 06:21 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 06:21 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
2014-02-12 22:19 - 2014-02-12 22:19 - 00009285 _____ () C:\Users\Šejpák\Desktop\FRST.txt
2014-02-12 22:19 - 2014-02-12 21:53 - 00000000 ____D () C:\FRST
2014-02-12 22:17 - 2014-02-12 22:17 - 00112640 _____ (forum.viry.cz) C:\Users\Šejpák\Desktop\FRSTLauncher.exe
2014-02-12 21:54 - 2013-12-24 19:36 - 00000000 ___RD () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-12 21:53 - 2014-02-12 22:02 - 02152448 _____ (Farbar) C:\Users\Šejpák\Desktop\FRST64.exe
2014-02-12 21:36 - 2014-01-04 19:52 - 01354116 _____ () C:\Windows\WindowsUpdate.log
2014-02-12 21:26 - 2013-12-25 01:27 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-12 19:59 - 2013-12-25 01:40 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Skype
2014-02-12 18:55 - 2014-02-12 18:55 - 00108816 _____ () C:\Users\Šejpák\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-12 18:44 - 2013-12-24 23:58 - 00000342 _____ () C:\Windows\Tasks\dsmonitor.job
2014-02-12 18:41 - 2014-02-12 18:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\{9620c625-c254-6b6a-3461-87549620c625}
2014-02-12 18:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-12 16:37 - 2014-02-12 16:37 - 00002005 _____ () C:\Users\Šejpák\Desktop\ESET Smart Security.lnk
2014-02-12 16:09 - 2009-07-14 05:45 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:09 - 2009-07-14 05:45 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:08 - 2010-11-21 10:27 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-02-12 16:08 - 2010-11-21 10:27 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-02-12 16:08 - 2009-07-14 06:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\ProgramData\ESET
2014-02-12 16:05 - 2014-02-12 16:05 - 00000000 ____D () C:\Program Files\ESET
2014-02-12 16:02 - 2013-12-24 20:21 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-12 16:02 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-12 14:55 - 2013-12-25 00:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-12 14:52 - 2013-12-24 20:20 - 01559268 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-12 14:52 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2014-02-12 14:32 - 2014-01-15 21:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-12 14:30 - 2013-12-24 19:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\VirtualStore
2014-02-12 14:29 - 2014-02-12 14:23 - 2382292992 _____ () C:\Users\Šejpák\Downloads\Crysis 3.iso
2014-02-12 14:11 - 2014-02-12 14:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashRpt
2014-02-12 14:11 - 2013-12-24 23:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-12 14:11 - 2013-12-24 23:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-12 07:17 - 2013-12-25 01:27 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\Adobe
2014-02-11 19:08 - 2014-02-11 19:08 - 00000877 _____ () C:\Users\Šejpák\Desktop\sims.txt
2014-02-11 16:12 - 2014-02-11 16:12 - 00000646 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Singleplayer.lnk
2014-02-11 14:53 - 2014-02-12 14:50 - 01703936 _____ () C:\Users\Šejpák\Desktop\Call of Duty(R) 2 Multiplayer.exe
2014-02-11 14:51 - 2013-12-24 20:11 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-11 14:47 - 2014-02-11 14:47 - 00000256 _____ () C:\Windows\game.ini
2014-02-10 14:06 - 2013-12-25 00:00 - 00002497 _____ () C:\Users\Public\Desktop\O&O Defrag.lnk
2014-02-07 19:16 - 2014-01-10 19:09 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-02-06 13:16 - 2014-02-12 14:51 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-12 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-12 14:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-12 14:51 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-12 14:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-12 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-12 14:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-12 14:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-12 14:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-12 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-12 14:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-12 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-12 14:51 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-12 14:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-12 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-12 14:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-12 14:51 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-12 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-12 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-12 14:51 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-12 14:51 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-12 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-12 14:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-12 14:51 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-12 14:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-12 14:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-12 14:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-12 14:51 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-12 14:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-12 14:51 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-12 14:51 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-12 14:51 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-12 14:51 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-12 14:51 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-12 14:51 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-12 14:51 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-12 14:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-12 14:51 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-12 14:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 18:29 - 2013-12-25 20:53 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-05 17:59 - 2013-12-25 20:53 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-05 17:50 - 2013-12-25 20:10 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-02-04 22:26 - 2013-12-25 01:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-04 22:26 - 2013-12-25 01:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-04 22:26 - 2013-12-25 01:27 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-04 13:13 - 2013-12-24 23:00 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-02 20:24 - 2013-12-28 17:11 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\TS3Client
2014-02-01 23:03 - 2013-12-26 01:13 - 00001198 _____ () C:\Windows\system32\RTCM_Config.ini
2014-02-01 18:40 - 2013-12-25 02:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\CrashDumps
2014-02-01 17:05 - 2014-02-01 17:05 - 00000132 _____ () C:\Users\Šejpák\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-02-01 17:03 - 2014-02-01 16:44 - 00001100 _____ () C:\Users\Šejpák\Desktop\Adobe Photoshop CC (64 Bit).lnk
2014-02-01 16:36 - 2014-02-01 16:36 - 00003504 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-SejpakPC-Šejpák
2014-02-01 16:36 - 2014-02-01 16:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\PDAppFlex
2014-02-01 16:32 - 2014-02-01 16:27 - 00000000 ____D () C:\Program Files\Adobe
2014-02-01 16:31 - 2013-12-27 00:11 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-01 16:31 - 2013-12-25 01:29 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-01 16:26 - 2013-12-24 19:36 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Adobe
2014-02-01 16:25 - 2013-12-25 01:29 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-01 16:11 - 2014-02-01 16:11 - 00001074 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-02-01 12:48 - 2014-01-10 17:41 - 00000000 ____D () C:\Users\Šejpák\AppData\Local\LogMeIn Hamachi
2014-02-01 12:46 - 2013-12-25 21:49 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-01 12:46 - 2013-12-25 21:49 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-31 17:04 - 2013-12-25 20:10 - 00000000 ____D () C:\ProgramData\Origin
2014-01-30 19:19 - 2014-01-10 17:41 - 00000606 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-01-30 19:15 - 2013-12-25 02:21 - 00000000 ____D () C:\Users\Šejpák\Documents\My Games
2014-01-30 19:03 - 2014-01-30 19:03 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft Games
2014-01-30 19:01 - 2014-01-30 19:01 - 00002155 _____ () C:\Users\Public\Desktop\Rise of Nations Gold.lnk
2014-01-30 19:00 - 2014-01-30 19:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-01-26 08:50 - 2009-07-14 06:08 - 00032544 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-24 14:32 - 2014-01-24 14:32 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr
2014-01-24 14:32 - 2014-01-24 14:32 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll
2014-01-24 14:32 - 2014-01-24 14:32 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe
2014-01-24 14:32 - 2014-01-24 14:32 - 00010536 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll
2014-01-23 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-23 15:36 - 2013-12-24 20:21 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-01-21 07:28 - 2014-01-21 07:28 - 00000625 _____ () C:\Users\Public\Desktop\4Story.lnk
2014-01-21 03:53 - 2013-12-24 20:21 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-01-21 03:53 - 2013-12-24 20:21 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-01-20 22:38 - 2014-01-20 22:38 - 00000000 ____D () C:\Users\Šejpák\Documents\RtsCam
2014-01-20 21:11 - 2014-01-15 23:31 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-01-20 20:29 - 2013-12-25 20:10 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-01-20 19:30 - 2014-01-20 19:30 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-01-19 23:28 - 2013-12-27 03:48 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Sony
2014-01-19 22:58 - 2013-12-25 01:26 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-18 10:57 - 2014-01-18 10:57 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Publish Providers
2014-01-18 10:51 - 2014-01-12 21:47 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\TeamViewer
2014-01-18 10:34 - 2013-12-24 23:55 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-01-16 15:42 - 2014-01-16 13:12 - 00000222 _____ () C:\Users\Šejpák\Desktop\Total War ROME II.url
2014-01-16 13:12 - 2014-01-16 13:12 - 00000000 ____D () C:\Users\Šejpák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-01-15 23:31 - 2014-01-15 23:31 - 00000779 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-01-15 23:31 - 2014-01-15 23:31 - 00000763 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-01-15 23:31 - 2013-12-25 20:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-01-15 21:05 - 2014-01-15 21:05 - 00000967 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-01-15 07:37 - 2013-12-24 22:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 07:36 - 2013-12-24 22:34 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-13 21:18 - 2013-12-27 02:23 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-13 16:20 - 2013-12-27 02:21 - 00000000 ____D () C:\Users\Šejpák\Documents\Assassin's Creed IV Black Flag
Some content of TEMP:
====================
C:\Users\Šejpák\AppData\Local\Temp\InstHelper.exe
C:\Users\Šejpák\AppData\Local\Temp\speeditupfree-knowledge.exe
C:\Users\Šejpák\AppData\Local\Temp\ytdownloader_ww_setup_20140203.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 00:45
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:111.69 GB) (Free:46.17 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:783.05 GB) NTFS
Available physical RAM: 5927.44 MB
Total physical RAM: 8136.01 MB
Percentage of memory in use: 27%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: E291D752)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E291D72F)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\dsmonitor.job => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\Users\All Users:NT
AlternateDataStreams: C:\ProgramData\Application Data:NT
AlternateDataStreams: C:\ProgramData\Data aplikací:NT
AlternateDataStreams: C:\Users\Šejpák\Data aplikací:NT
AlternateDataStreams: C:\Users\Šejpák\AppData\Roaming:NT
==================== Security Center ==================
AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\�ejp�k\Desktop" je 3 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4StoryPrePatch
D:\Hry\4Story_CZ\PrePatch.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager
"C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bloody2
"C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cm108Sound
C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"D:\Data\Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskqcnisSrv
C:\Windows\inf\mskqcnis.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssiplSrv
"C:\Windows\system32\mssipl.vbe" mshfhcgi msbfbde [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswwkgSrv
C:\Windows\inf\mswwkg.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray
C:\Program Files\OO Software\Defrag\oodtray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printsrv
c:\Windows\System32\Printing_Admin_Scripts\en-US\pubpr.vbs [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Killer Network Manager.lnk
C:\Windows\Installer\{4E08CC97-912D-458B-8705-9A14C325532F}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe -minimize [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk
C:\Windows\Installer\{F17BA1CA-0FAF-40BF-A5FD-BF1B727D855E}\app_icon.ico [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Qualcomm Atheros Killer Network Manager.lnk
C:\PROGRA~1\QUALCO~1\KILLER~1\KILLER~1.EXE -minimized [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================