Stránka 1 z 1

Preventivka,dekuji.

Napsal: 15 úno 2014 15:33
od lost16
Logfile of random's system information tool 1.09 (written by random/random)
Run by Rodina at 2014-02-15 15:32:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 165 GB (45%) free of 367 GB
Total RAM: 3039 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:32:23, on 15.2.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Rodina\Downloads\RSIT.exe
C:\Program Files\trend micro\Rodina.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [mncqsvtnSrv] C:\Windows\inf\mncqsvtn.vbe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [NextLive] C:\Windows\system32\rundll32.exe "C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: SecureUpdate (SecureUpdateSvc) - Unknown owner - C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8180 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.srch.szn.cz "

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.44 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


C:\Program Files\Mozilla Firefox\components\
nsIBitCometAgent.xpt

C:\Program Files\Mozilla Firefox\plugins\
npBitCometAgent.dll
NPOFF12.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
yahoo.xml

C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\extensions\
speeddial@instair.net
WebSiteRecommendation@weliketheweb.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-01-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-01-29 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2014-02-12 3767096]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-11-02 152392]
"mobilegeni daemon"=C:\Program Files\Mobogenie\DaemonProcess.exe []
"MSStp"=C:\Windows\system32\msstp.vbe [2014-01-19 1419]
"mncqsvtnSrv"=C:\Windows\inf\mncqsvtn.vbe [2014-01-19 1342]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"NextLive"=C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll [2014-01-06 1283584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\20131121]
C:\Program Files\Alwil Software\Avast5\setup\emupdate\7701b66b-47da-460f-88f5-b714419b246d.exe [2013-11-23 180184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-06-16 499608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 6]
C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe /AutoStart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files\BlueStacks\HD-Agent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\Rodina\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Rodina\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2012-12-12 655360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7M\ICQ.exe [2013-04-07 127040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe /autostart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2013-11-02 152392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
C:\Program Files\Mobogenie\DaemonProcess.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [2013-04-19 1090912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spybot-S&D Cleaning]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2012-10-18 752736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~1\McAfee Security Scan\3.8.130\SSScheduler.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodina^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\Windows\system32\VESWinlogon.dll [2009-01-19 98304]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticetext"=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.siren"=sirenacm.dll
"VIDC.dvsd"=C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
"vidc.pDAD"=prodad-codec.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-02-15 14:33:53 ----D---- C:\Program Files\Plus500
2014-02-14 15:46:49 ----D---- C:\Program Files\Driver-Soft
2014-02-14 15:29:31 ----A---- C:\Windows\system32\drivers\DrvAgent32.sys
2014-02-14 15:17:35 ----D---- C:\Users\Rodina\AppData\Roaming\AVG
2014-02-14 15:16:23 ----D---- C:\ProgramData\AVG
2014-02-14 15:16:13 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-02-14 15:16:13 ----HD---- C:\ProgramData\Common Files
2014-02-14 15:14:25 ----D---- C:\Users\Rodina\AppData\Roaming\newnext.me
2014-02-14 15:14:15 ----D---- C:\DriverPack Solution
2014-02-14 15:12:09 ----D---- C:\Users\Rodina\AppData\Roaming\OpenCandy
2014-02-14 12:04:02 ----D---- C:\Program Files\VS Revo Group
2014-02-14 10:26:06 ----A---- C:\Windows\system32\ieui.dll
2014-02-14 10:26:06 ----A---- C:\Windows\system32\ie4uinit.exe
2014-02-14 10:26:05 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 10:26:04 ----A---- C:\Windows\system32\msrating.dll
2014-02-14 10:26:04 ----A---- C:\Windows\system32\jsproxy.dll
2014-02-14 10:26:04 ----A---- C:\Windows\system32\iesetup.dll
2014-02-14 10:26:04 ----A---- C:\Windows\system32\iernonce.dll
2014-02-14 10:26:03 ----A---- C:\Windows\system32\jscript9diag.dll
2014-02-14 10:26:03 ----A---- C:\Windows\system32\ieUnatt.exe
2014-02-14 10:26:03 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-02-14 10:26:03 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-02-14 10:26:02 ----A---- C:\Windows\system32\ieapfltr.dll
2014-02-14 10:26:01 ----A---- C:\Windows\system32\msfeeds.dll
2014-02-14 10:26:00 ----A---- C:\Windows\system32\iertutil.dll
2014-02-14 10:25:59 ----A---- C:\Windows\system32\wininet.dll
2014-02-14 10:25:59 ----A---- C:\Windows\system32\urlmon.dll
2014-02-14 10:25:57 ----A---- C:\Windows\system32\ieframe.dll
2014-02-14 10:25:56 ----A---- C:\Windows\system32\mshtml.dll
2014-02-14 10:25:56 ----A---- C:\Windows\system32\jscript9.dll
2014-02-14 10:08:30 ----A---- C:\Windows\system32\vbscript.dll
2014-02-13 21:05:07 ----A---- C:\Windows\system32\msxml3.dll
2014-02-13 21:05:06 ----A---- C:\Windows\system32\msxml3r.dll
2014-02-13 21:04:49 ----A---- C:\Windows\system32\d3d10warp.dll
2014-02-13 21:04:49 ----A---- C:\Windows\system32\d2d1.dll
2014-02-13 21:04:44 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-02-13 21:04:43 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 21:04:43 ----A---- C:\Windows\system32\RMActivate.exe
2014-02-13 21:04:42 ----A---- C:\Windows\system32\secproc_isv.dll
2014-02-13 21:04:42 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 21:04:41 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 21:04:41 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-02-13 21:04:41 ----A---- C:\Windows\system32\secproc.dll
2014-02-13 21:04:41 ----A---- C:\Windows\system32\msdrm.dll
2014-02-11 17:47:27 ----D---- C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)
2014-02-11 17:44:15 ----D---- C:\Program Files\PC Drivers HeadQuarters
2014-02-11 17:44:07 ----D---- C:\Users\Rodina\AppData\Roaming\PC Drivers HeadQuarters
2014-02-11 17:38:16 ----D---- C:\ProgramData\PC Drivers HeadQuarters
2014-02-10 21:05:53 ----D---- C:\Program Files\Gabest
2014-02-10 21:04:50 ----D---- C:\Program Files\AviSynth 2.5
2014-01-31 13:29:25 ----D---- C:\Users\Rodina\AppData\Roaming\abgx360
2014-01-31 13:27:41 ----D---- C:\Program Files\abgx360
2014-01-29 16:55:49 ----D---- C:\Program Files\Common Files\Java
2014-01-29 16:55:33 ----A---- C:\Windows\system32\javaws.exe
2014-01-29 16:55:23 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-01-29 16:55:23 ----A---- C:\Windows\system32\javaw.exe
2014-01-29 16:55:23 ----A---- C:\Windows\system32\java.exe

======List of files/folders modified in the last 1 month======

2014-02-15 15:32:22 ----D---- C:\Windows\Prefetch
2014-02-15 15:32:13 ----D---- C:\Windows\Temp
2014-02-15 15:32:13 ----D---- C:\Program Files\trend micro
2014-02-15 14:33:53 ----RD---- C:\Program Files
2014-02-15 14:17:43 ----D---- C:\Windows\system32\config
2014-02-14 18:00:28 ----D---- C:\Users\Rodina\AppData\Roaming\vlc
2014-02-14 15:55:02 ----SHD---- C:\Windows\Installer
2014-02-14 15:55:02 ----SHD---- C:\Config.Msi
2014-02-14 15:54:47 ----SHD---- C:\System Volume Information
2014-02-14 15:51:03 ----D---- C:\Windows\System32
2014-02-14 15:44:04 ----D---- C:\Windows\inf
2014-02-14 15:41:43 ----D---- C:\Program Files\Mobogenie
2014-02-14 15:29:31 ----D---- C:\Windows\system32\drivers
2014-02-14 15:26:24 ----D---- C:\Windows\system32\LogFiles
2014-02-14 15:18:08 ----D---- C:\Program Files\Windows Sidebar
2014-02-14 15:16:23 ----HD---- C:\ProgramData
2014-02-14 15:16:14 ----D---- C:\Windows
2014-02-14 15:13:04 ----D---- C:\Windows\system32\wbem
2014-02-14 12:18:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-02-14 12:08:02 ----D---- C:\Program Files\Common Files
2014-02-14 10:50:48 ----D---- C:\Windows\Microsoft.NET
2014-02-14 10:50:47 ----RSD---- C:\Windows\assembly
2014-02-14 10:29:40 ----D---- C:\Windows\winsxs
2014-02-14 10:26:49 ----D---- C:\Program Files\Internet Explorer
2014-02-14 10:26:41 ----D---- C:\Windows\system32\catroot
2014-02-14 10:26:15 ----D---- C:\Windows\system32\catroot2
2014-02-14 10:22:45 ----D---- C:\Windows\system32\MRT
2014-02-14 10:13:27 ----D---- C:\Windows\debug
2014-02-14 10:13:22 ----A---- C:\Windows\system32\MRT.exe
2014-02-14 10:07:53 ----D---- C:\Windows\system32\cs-CZ
2014-02-12 15:18:39 ----D---- C:\Windows\system32\Tasks
2014-02-12 15:18:32 ----A---- C:\Windows\system32\aswBoot.exe
2014-02-12 15:14:50 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-02-12 12:26:24 ----SD---- C:\ProgramData\Microsoft
2014-02-11 20:03:10 ----RSD---- C:\Windows\Media
2014-02-03 20:37:16 ----D---- C:\Windows\PCHEALTH
2014-02-02 16:39:45 ----D---- C:\Windows\SoftwareDistribution
2014-02-02 16:29:35 ----D---- C:\Program Files\CCleaner
2014-02-01 20:10:30 ----D---- C:\Users\Rodina\AppData\Roaming\Skype
2014-01-29 16:59:43 ----D---- C:\Program Files\Common Files\Adobe AIR
2014-01-29 16:56:08 ----D---- C:\ProgramData\Oracle
2014-01-20 15:57:13 ----D---- C:\Windows\InstDrvs
2014-01-19 13:19:31 ----D---- C:\ProgramData\BlueStacksSetup
2014-01-16 14:52:48 ----D---- C:\Windows\system32\DriverStore
2014-01-16 09:29:12 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-12-01 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-01-09 180248]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-04-22 312344]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2012-08-10 46096]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-03-09 466008]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-12-01 79720]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2014-02-12 775952]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2014-02-12 410784]
R1 DMICall;Sony DMI Call service; C:\Windows\system32\DRIVERS\DMICall.sys [2008-11-25 10216]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2014-02-12 67824]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-03-15 281760]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-03-15 25888]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2008-01-25 12672]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2008-10-23 68608]
R2 risdptsk;risdptsk; C:\Windows\system32\DRIVERS\risdptsk.sys [2008-10-23 46592]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 290304]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2014-02-12 64168]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-01-25 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-01-25 207360]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2013-03-29 2646088]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NETwNs32;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 32 Bit; C:\Windows\system32\DRIVERS\NETwNs32.sys [2012-01-23 7523840]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SFEP.sys [2008-11-19 9344]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-03-10 181560]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-01-25 659968]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 17920]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 84248]
S3 DrvAgent32;DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [2014-02-14 23456]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-07-31 25280]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2009-05-28 4233728]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-02-03 14848]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb.sys []
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SMARTMouseFilterx86;HID-compliant mouse; C:\Windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2008-07-30 11048]
S3 SMARTVHidMini2000x86;SMART HID Device; C:\Windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2008-07-30 14120]
S3 SMARTVTabletPCx86;SMART Virtual TabletPC; C:\Windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2008-07-30 16808]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-08-20 182680]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-02-03 49664]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2012-12-13 45056]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2012-10-26 104280]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-06-07 131000]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2014-02-12 50344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-05-21 874768]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 NSUService;NSUService; C:\Program Files\Sony\Network Utility\NSUService.exe [2008-12-22 303104]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-05-21 473360]
R2 uCamMonitor;CamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [2009-01-19 203624]
R2 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2008-12-19 415592]
R2 VCFw;VAIO Content Folder Watcher; C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-03-05 5189992]
R2 VzCdbSvc;VAIO Entertainment Database Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [2009-03-05 192512]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 553288]
R3 Vcsw;VAIO Entertainment UPnP Client Adapter; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [2009-03-05 313264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-10 136176]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SecureUpdateSvc;SecureUpdate; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2013-10-30 2473296]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-09-16 480624]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-12 257928]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-10 136176]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 108032]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-20 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2009-04-02 114688]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 SOHCImp;VAIO Media plus Content Importer; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-01-20 120104]
S3 SOHDBSvr;VAIO Media plus Database Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-01-20 70952]
S3 SOHDms;VAIO Media plus Digital Media Server; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-01-20 390440]
S3 SOHDs;VAIO Media plus Device Searcher; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-01-20 75048]
S3 SOHPlMgr;VAIO Media plus Playlist Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-01-20 91432]
S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [2009-03-05 69632]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-09-08 83312]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-20 1343400]

-----------------EOF-----------------

Re: Preventivka,dekuji.

Napsal: 15 úno 2014 16:41
od lost16
Ahoj,
pri spustení PC, vzdy 1)Avast hlasi, ze web. stit zachytil msdr64.com/mnrc.php 2) vyskoci hlaska mncqsvtn.exe prestal gungovat.

Re: Preventivka,dekuji.

Napsal: 15 úno 2014 17:29
od vyosek
Zdravim :)

:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: Preventivka,dekuji.

Napsal: 15 úno 2014 21:12
od lost16
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.11.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16518
Rodina :: FANDA-PC [administrátor]

15.2.2014 17:31:50
MBAM-log-2014-02-15 (21-11-20).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 436127
Uplynulý čas: 3 hodin, 38 minut, 22 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 1
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Data: C:\Windows\system32\rundll32.exe "C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MSStp (Malware.Trace) -> Data: C:\Windows\system32\msstp.vbe -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 7
C:\Users\Rodina\AppData\Roaming\OPENCANDY (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\788597FC5016479E916E191BF2FAF9DB (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\87C1B58BF8F04B4F827B2440E9169B87 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\bitstreams (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 28
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\$Recycle.Bin\S-1-5-21-3241783717-830924702-2248461599-1000\$R74ZP74.rar (PUP.Riskware.Patcher) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.2.0.zip (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Local\Temp\Rar$DR01.686\Driver Detective 9.0.0.23\Driver Detective 9.0.0.23\Patch\driver.detective.9.0.0.23-MPT.exe (PUP.Riskware.Patcher) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Local\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\OpenCandy\87C1B58BF8F04B4F827B2440E9169B87\Mobogenie_Setup_2.1.37_507.exe (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncfdby\mncfdby.exe (Trojan.BitMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\mncqsvtn.exe (Trojan.BitMiner) -> Nebyla provedena žádná instrukce.
C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)\driver.detective.9.0.0.23.exe (PUP.Riskware.Patcher) -> Nebyla provedena žádná instrukce.
C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)\DriverDetective PATCH\driver.detective.9.0.0.23.exe (PUP.Riskware.Patcher) -> Nebyla provedena žádná instrukce.
C:\Windows\System32\msstp.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\788597FC5016479E916E191BF2FAF9DB\avg_tuht_stf_cs_2014_206_CZ.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Rodina\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\diablo130302.cl (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\diakgcn121016.cl (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\libcurl-4.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\libeay32.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\libidn-11.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\librtmp.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\libssh2.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\phatk121016.cl (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\poclbm130302.cl (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\scrypt130511.cl (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\ssleay32.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\zlib1.dll (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\mncqsvtn\BITSTREAMS\fpgaminer_top_fixed7_197MHz.ncd (Trojan.Agent.BCM) -> Nebyla provedena žádná instrukce.

(konec)

Re: Preventivka,dekuji.

Napsal: 15 úno 2014 22:06
od vyosek
Nalezy MBAMu smazte, obejvi se log, ten rad uvidim

Re: Preventivka,dekuji.

Napsal: 15 úno 2014 22:14
od lost16
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.11.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16518
Rodina :: FANDA-PC [administrátor]

15.2.2014 17:31:50
mbam-log-2014-02-15 (17-31-50).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 436127
Uplynulý čas: 3 hodin, 38 minut, 22 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 1
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Bude smazán při restartu.

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Data: C:\Windows\system32\rundll32.exe "C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MSStp (Malware.Trace) -> Data: C:\Windows\system32\msstp.vbe -> Přesun do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 7
C:\Users\Rodina\AppData\Roaming\OPENCANDY (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\788597FC5016479E916E191BF2FAF9DB (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\87C1B58BF8F04B4F827B2440E9169B87 (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Bude smazán při restartu.
C:\Users\Rodina\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\bitstreams (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.

Nalezené soubory: 28
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Bude smazán při restartu.
C:\$Recycle.Bin\S-1-5-21-3241783717-830924702-2248461599-1000\$R74ZP74.rar (PUP.Riskware.Patcher) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.2.0.zip (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\nengine.dll (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Local\Temp\Rar$DR01.686\Driver Detective 9.0.0.23\Driver Detective 9.0.0.23\Patch\driver.detective.9.0.0.23-MPT.exe (PUP.Riskware.Patcher) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Local\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\OpenCandy\87C1B58BF8F04B4F827B2440E9169B87\Mobogenie_Setup_2.1.37_507.exe (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncfdby\mncfdby.exe (Trojan.BitMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\mncqsvtn.exe (Trojan.BitMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)\driver.detective.9.0.0.23.exe (PUP.Riskware.Patcher) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)\DriverDetective PATCH\driver.detective.9.0.0.23.exe (PUP.Riskware.Patcher) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\System32\msstp.vbe (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\OPENCANDY\788597FC5016479E916E191BF2FAF9DB\avg_tuht_stf_cs_2014_206_CZ.exe (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Rodina\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\diablo130302.cl (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\diakgcn121016.cl (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\libcurl-4.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\libeay32.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\libidn-11.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\librtmp.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\libssh2.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\phatk121016.cl (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\poclbm130302.cl (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\scrypt130511.cl (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\ssleay32.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\zlib1.dll (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\inf\mncqsvtn\BITSTREAMS\fpgaminer_top_fixed7_197MHz.ncd (Trojan.Agent.BCM) -> Přesun do karantény a smazání se zdařilo.

(konec)

Re: Preventivka,dekuji.

Napsal: 16 úno 2014 08:43
od vyosek
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Preventivka,dekuji.

Napsal: 16 úno 2014 12:04
od lost16
# AdwCleaner v3.018 - Report created 16/02/2014 at 11:32:33
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Rodina - FANDA-PC
# Running from : C:\Users\Rodina\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\driver-soft
Folder Deleted : C:\Users\Rodina\AppData\Local\eSupport.com
Folder Deleted : C:\Users\Rodina\AppData\Roaming\SimilarSites
File Deleted : C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\invalidprefs.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\Software\Conduit

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\prefs.js ]


-\\ Google Chrome v32.0.1700.107

[ File : C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Users\host\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3430 octets] - [11/10/2013 12:32:23]
AdwCleaner[R1].txt - [3490 octets] - [11/10/2013 12:35:31]
AdwCleaner[R2].txt - [3550 octets] - [12/10/2013 15:38:58]
AdwCleaner[R3].txt - [1011 octets] - [19/10/2013 15:46:54]
AdwCleaner[R4].txt - [1682 octets] - [16/02/2014 11:19:36]
AdwCleaner[S0].txt - [3646 octets] - [12/10/2013 15:39:37]
AdwCleaner[S1].txt - [1072 octets] - [19/10/2013 15:47:29]
AdwCleaner[S2].txt - [1621 octets] - [16/02/2014 11:32:33]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1681 octets] ##########

Re: Preventivka,dekuji.

Napsal: 16 úno 2014 12:04
od lost16
Zoek.exe v5.0.0.0 Updated 15-February-2014
Tool run by Rodina on ne 16.02.2014 at 11:40:37,60.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Rodina\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16.2.2014 11:42:47 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3241783717-830924702-2248461599-1000\Software\Microsoft\Internet Explorer\SearchScopes\{50C658B0-4E45-EE26-CB69-40ED846EB0C8} deleted successfully
HKEY_USERS\S-1-5-21-3241783717-830924702-2248461599-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5E00C86C-9578-4254-9664-EECA4F8199F5} deleted successfully
HKEY_USERS\S-1-5-21-3241783717-830924702-2248461599-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C86E4DA7-54AE-4399-9082-243F280CE800} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.srch.szn.cz ");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_16.02.2014_1153_.backup

==== Deleting Files \ Folders ======================

C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A} deleted
C:\Users\Rodina\AppData\Local\genienext deleted
C:\Program Files\Mobogenie deleted
C:\Program Files\Secure Speed Dial deleted
C:\Program Files\Wondershare deleted
C:\found.000 deleted
C:\Users\Rodina\AppData\Roaming\ICQ Search deleted
C:\ProgramData\__wdump.txt deleted
C:\ProgramData\ICQ deleted
C:\Users\Rodina\AppData\Local\FileTypeAssistant deleted
C:\Users\Rodina\AppData\Local\blekkotb_031 deleted
C:\Users\Rodina\AppData\Local\Mobogenie deleted
C:\Users\Rodina\AppData\Local\cache deleted
C:\Windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Users\Rodina\AppData\LocalLow\IObit Apps deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Users\wangzhisong deleted
C:\Users\Rodina\Documents\Mobogenie deleted
C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\extensions\speeddial@instair.net deleted
C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB} deleted
"C:\Users\Rodina\AppData\Roaming\Ahead" deleted
"C:\Users\Rodina\AppData\Roaming\GHISLER" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [18.03.2010 23:21]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default
- WebSite Recommendation - %ProfilePath%\extensions\WebSiteRecommendation@weliketheweb.com
- Seznam Admin Software - %ProfilePath%\extensions\SeznamAdmin@software.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default
FD6ACD9D85177259D442A0C4AC15F7B8 - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll - Shockwave Flash
A9C86900D2A61728C8326FE7147617C5 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll - Google Update
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
3220B1254AEF7A191187EC03F51B3D61 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
B2576571746839180833E048AC2CCA5C - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
9D4A0B314CB9CF134CA27E1E0217E51E - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector
BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In
A847F61BACFA2C4E3E0B0F9431BB5245 - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll - Nokia Suite Enabler Plugin
1BFD18699636B8F1AA26675BA43D2F8F - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll - Shockwave for Director / Shockwave for Director
E2318E8514ABF50E3ECEDAB9465A90A1 - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
B27CCB1168B1960AEC6E9D3E0E0F0D2A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrlui.dll - Microsoft® Silverlight


==== Deleted Firefox Extensions ======================

C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\extensions\WebSiteRecommendation@weliketheweb.com deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
hbcennhacfaagdopikcegfcobcadeocj - No path found[]
icdlfehblmklkikfigmjhbmmpmkmpooj - No path found[]
mhkaekfpcppmmioggniknbnbdbcigpkk - No path found[]
pfndaklgolladniicklehhancnlgocpp - No path found[]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.bing.com"
"Use Search Asst"="yes"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.bing.com"
"Use Search Asst"="no"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=i ... lz=1I7SNYT"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{8638BB4A-0AC5-4D55-B152-157B059FEE39} Google Url="http://www.google.co.uk/search?hl=en&q= ... rms}&meta="
{D57B7B40-D9D1-4489-B6FC-0267919913F9} Google Url="http://www.google.com/search?q={searchT ... 1I7SNYS_cs"

==== Reset Google Chrome ======================

C:\Users\host\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\host\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 6 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spybot-S&D Cleaning deleted successfully

==== Empty IE Cache ======================

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\host\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\host\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Rodina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Rodina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\UnMHT\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\host\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=4388 folders=455 273736143 bytes)

==== Empty Temp Folders ======================

C:\Users\host\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\Rodina\AppData\Local\Temp will be emptied at reboot
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Rodina\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on ne 16.02.2014 at 12:01:22,57 ======================

Re: Preventivka,dekuji.

Napsal: 17 úno 2014 15:06
od vyosek

Re: Preventivka,dekuji.

Napsal: 17 úno 2014 15:38
od lost16
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Rodina (administrator) on FANDA-PC on 17-02-2014 15:28:37
Running from C:\Users\Rodina\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Sony Corporation) C:\Program Files\Sony\Network Utility\NSUService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Rodina\Desktop\FRSTLauncher (1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [] - [X]
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3767096 2014-02-12] (AVAST Software)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation)
HKU\S-1-5-21-3241783717-830924702-2248461599-1000\...\Run: [] - [X]

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
URLSearchHook: HKLM - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7SNYT
SearchScopes: HKLM - {8638BB4A-0AC5-4D55-B152-157B059FEE39} URL = http://www.google.co.uk/search?hl=en&q= ... rms}&meta=
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7SNYT
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {8638BB4A-0AC5-4D55-B152-157B059FEE39} URL = http://www.google.co.uk/search?hl=en&q= ... rms}&meta=
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: https://www.srch.szn.cz/login
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam Admin Software - C:\Users\Rodina\AppData\Roaming\Mozilla\Firefox\Profiles\1jv6yqsj.default\Extensions\SeznamAdmin@software.xpi [2013-11-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []

Chrome:
=======
CHR HomePage: hxxp://seznam.cz/
CHR Extension: (Dokumenty Google) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-16]
CHR Extension: (Disk Google) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-16]
CHR Extension: (YouTube) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-16]
CHR Extension: (Peněženka Google) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-19]
CHR Extension: (Gmail) - C:\Users\Rodina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-16]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-02-12] (AVAST Software)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NSUService; C:\Program Files\Sony\Network Utility\NSUService.exe [303104 2008-12-22] (Sony Corporation)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-03-05] (Sony Corporation)
R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [203624 2009-01-19] (Sony Corporation)
R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [415592 2008-12-19] (Sony Corporation)
R2 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation)
R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-03-05] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-03-05] (Sony Corporation)
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [X]

==================== Drivers (Whitelisted) ====================

S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-02-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-12-01] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-12-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-02-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410784 2014-02-12] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-02-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-09] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2010-03-15] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [25280 2011-07-31] (LogMeIn, Inc.)
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2010-03-15] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7523840 2012-01-23] (Intel Corporation)
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [46096 2012-08-10] (Corel Corporation)
S3 SMARTMouseFilterx86; C:\Windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2008-07-30] (SMART Technologies ULC)
S3 SMARTVHidMini2000x86; C:\Windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2008-07-30] (SMART Technologies ULC)
S3 SMARTVTabletPCx86; C:\Windows\System32\DRIVERS\SMARTVTabletPCx86.sys [16808 2008-07-30] (SMART Technologies ULC)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-03-09] (Duplex Secure Ltd.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2014-02-15] ()
S3 RimUsb; System32\Drivers\RimUsb.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-17 15:28 - 2014-02-17 15:28 - 00014488 _____ () C:\Users\Rodina\Desktop\FRST.txt
2014-02-17 15:27 - 2014-02-17 15:28 - 00000000 ____D () C:\FRST
2014-02-17 15:26 - 2014-02-17 15:26 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Downloads\FRSTLauncher (1).exe
2014-02-17 15:26 - 2014-02-17 15:26 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Desktop\FRSTLauncher (1).exe
2014-02-17 15:24 - 2014-02-17 15:24 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Downloads\Nepotvrzeno 718756.crdownload
2014-02-17 15:15 - 2014-02-17 15:15 - 01141248 _____ (Farbar) C:\Users\Rodina\Downloads\FRST.exe
2014-02-17 15:15 - 2014-02-17 15:15 - 01141248 _____ (Farbar) C:\Users\Rodina\Desktop\FRST.exe
2014-02-17 15:15 - 2014-02-17 15:15 - 00110747 _____ () C:\Users\Rodina\Downloads\trz4F00.tmp
2014-02-16 18:44 - 2014-02-16 19:21 - 671169880 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x04-cz.avi
2014-02-16 17:18 - 2014-02-16 17:56 - 671872292 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x03-cz.avi
2014-02-16 16:40 - 2014-02-16 17:17 - 671788722 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x02-cz.avi.crdownload
2014-02-16 15:59 - 2014-02-16 16:36 - 672914046 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x01-cz.avi.crdownload
2014-02-16 11:59 - 2014-02-16 11:59 - 00000334 _____ () C:\Windows\PFRO.log
2014-02-16 11:57 - 2014-02-16 11:40 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-16 11:42 - 2014-02-16 12:01 - 00014186 _____ () C:\zoek-results.log
2014-02-16 11:40 - 2014-02-16 11:56 - 00000000 ____D () C:\zoek_backup
2014-02-16 11:37 - 2014-02-16 11:37 - 01283584 _____ () C:\Users\Rodina\Downloads\zoek.exe
2014-02-16 11:37 - 2014-02-16 11:37 - 01283584 _____ () C:\Users\Rodina\Desktop\zoek.exe
2014-02-16 11:19 - 2014-02-16 11:19 - 01166132 _____ () C:\Users\Rodina\Desktop\adwcleaner.exe
2014-02-16 11:18 - 2014-02-16 11:19 - 01166132 _____ () C:\Users\Rodina\Downloads\adwcleaner.exe
2014-02-15 22:38 - 2014-02-15 22:38 - 00000000 ____D () C:\Program Files\Marvell
2014-02-15 22:37 - 2014-02-15 22:38 - 00009436 _____ () C:\Windows\ykinstutil.log
2014-02-15 22:37 - 2014-02-15 22:38 - 00000364 ____R () C:\Windows\YukonInstall.log
2014-02-15 22:31 - 2014-02-17 15:21 - 00014872 _____ () C:\Windows\setupact.log
2014-02-15 22:31 - 2014-02-15 22:31 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 17:22 - 2014-02-15 17:23 - 00000023 _____ () C:\Windows\Model.txt
2014-02-15 16:49 - 2014-02-15 16:49 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-02-15 16:46 - 2000-01-01 01:00 - 38385664 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2014-02-15 16:46 - 2000-01-01 01:00 - 27369216 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 13881088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 06176944 _____ (Dolby Laboratories) C:\Windows\system32\DDPP32A.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 05773592 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 05681192 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2014-02-15 16:46 - 2000-01-01 01:00 - 03444992 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 02888536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2014-02-15 16:46 - 2000-01-01 01:00 - 02547928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 02395680 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 02328792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 01935104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 01824000 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 01677568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 01596488 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2014-02-15 16:46 - 2000-01-01 01:00 - 01489072 _____ (Dolby Laboratories) C:\Windows\system32\DDPD32A.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 01097984 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00938752 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00926976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00919600 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00877880 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00873728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00859904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00852016 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00823040 _____ (DTS, Inc.) C:\Windows\system32\sl3apo32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00782040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00761088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00681905 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-02-15 16:46 - 2000-01-01 01:00 - 00604928 _____ (DTS, Inc.) C:\Windows\system32\sltech32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00502584 _____ () C:\Windows\system32\audioLibVc.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00426944 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00403392 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00346048 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00272048 _____ (Dolby Laboratories) C:\Windows\system32\DDPO32A.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00219312 _____ (Dolby Laboratories) C:\Windows\system32\DDPA32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00218368 _____ (TODO: <Company name>) C:\Windows\system32\slprp32.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00188696 _____ () C:\Windows\system32\AcpiServiceVnA.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00182472 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00124632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2014-02-15 16:46 - 2000-01-01 01:00 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-02-15 16:25 - 2014-02-15 17:25 - 00013464 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-02-15 16:25 - 2014-02-15 16:25 - 00000000 ____D () C:\Users\Rodina\AppData\Local\SlimWare Utilities Inc
2014-02-15 16:25 - 2014-02-15 16:25 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-02-15 14:34 - 2014-02-15 14:34 - 00000899 _____ () C:\Users\host\Desktop\Plus500.lnk
2014-02-15 14:34 - 2014-02-15 14:34 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plus500
2014-02-15 14:33 - 2014-02-15 14:34 - 00000000 ____D () C:\Users\Rodina\AppData\Local\Plus500
2014-02-15 14:33 - 2014-02-15 14:33 - 00000000 ____D () C:\Program Files\Plus500
2014-02-15 14:16 - 2014-02-15 17:26 - 00000510 _____ () C:\Users\Rodina\rgmnr
2014-02-14 15:29 - 2014-02-14 15:29 - 00023456 _____ (Phoenix Technologies) C:\Windows\system32\Drivers\DrvAgent32.sys
2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\AVG
2014-02-14 15:16 - 2014-02-14 15:18 - 00000000 ____D () C:\ProgramData\AVG
2014-02-14 15:16 - 2014-02-14 15:16 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-02-14 15:14 - 2014-02-14 15:14 - 00000000 ____D () C:\DriverPack Solution
2014-02-14 12:04 - 2014-02-15 18:16 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-02-14 10:26 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-14 10:26 - 2014-02-06 11:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 10:26 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-14 10:26 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-14 10:26 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-14 10:26 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-14 10:26 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-14 10:26 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 10:26 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-14 10:26 - 2014-02-06 10:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-14 10:26 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-14 10:26 - 2014-02-06 10:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-14 10:26 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-14 10:26 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-14 10:26 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-14 10:25 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-14 10:25 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-14 10:25 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-14 10:25 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-14 10:25 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-14 10:25 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-14 10:08 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 21:05 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 21:05 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 21:05 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 21:04 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 21:04 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 21:04 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 21:04 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 21:04 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 21:04 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 21:04 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 21:04 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 21:04 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 21:04 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 21:04 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 17:50 - 2014-02-13 18:58 - 00000000 ____D () C:\Users\Rodina\Desktop\DIPLOMKA
2014-02-11 17:47 - 2014-02-15 22:13 - 00000000 ____D () C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)
2014-02-11 17:44 - 2014-02-11 17:44 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\PC Drivers HeadQuarters
2014-02-11 17:44 - 2014-02-11 17:44 - 00000000 ____D () C:\Program Files\PC Drivers HeadQuarters
2014-02-11 17:38 - 2014-02-11 17:38 - 00000000 ____D () C:\ProgramData\PC Drivers HeadQuarters
2014-02-10 21:36 - 2014-02-10 21:36 - 00000110 ____H () C:\Users\Rodina\Desktop\DSC06628.JPG.uid-zps
2014-02-10 21:05 - 2014-02-11 17:40 - 00000000 ____D () C:\Program Files\Gabest
2014-02-10 21:04 - 2014-02-11 17:40 - 00000000 ____D () C:\Program Files\AviSynth 2.5
2014-02-10 16:15 - 2014-01-30 01:19 - 1329400960 _____ () C:\Users\Rodina\Downloads\Vlk z Wall Street CZ-titulky.avi
2014-02-09 17:41 - 2014-02-09 18:07 - 00000000 ____D () C:\Users\Rodina\Desktop\2014
2014-02-08 16:33 - 2014-02-08 16:33 - 01972224 _____ () C:\Users\host\Downloads\Jak_ma_vypadat_babicka (1).pps
2014-02-08 16:27 - 2014-02-08 16:27 - 02011648 _____ () C:\Users\host\Downloads\2116_D_--_hajzliky.pps
2014-02-08 16:27 - 2014-02-08 16:27 - 01972224 _____ () C:\Users\host\Downloads\Jak_ma_vypadat_babicka.pps
2014-02-08 16:26 - 2014-02-08 16:26 - 04161536 _____ () C:\Users\host\Downloads\pohádková_vesnicka.pps
2014-02-02 18:36 - 2014-02-02 18:53 - 589503881 _____ () C:\Users\Rodina\Downloads\The.Philosophers.2013.BDRip.x264-kst.mkv
2014-02-02 16:38 - 2014-02-17 15:26 - 01553118 _____ () C:\Windows\WindowsUpdate.log
2014-02-02 15:32 - 2014-02-02 15:42 - 183437621 _____ () C:\Users\Rodina\Downloads\Windows-8---Základní-instalační-balíček-1.0.zip
2014-02-01 14:15 - 2014-02-01 14:15 - 00905728 _____ (Share-rapid.com) C:\Users\Rodina\Downloads\SRDownloader (1).exe
2014-02-01 11:57 - 2014-02-03 18:06 - 00000000 ____D () C:\Users\Rodina\xbox
2014-01-31 13:29 - 2014-01-31 13:29 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\abgx360
2014-01-31 13:27 - 2014-01-31 13:27 - 00000000 ____D () C:\Program Files\abgx360
2014-01-29 16:55 - 2014-01-29 16:55 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-29 16:55 - 2014-01-29 16:55 - 00000000 ____D () C:\Program Files\Common Files\Java

==================== One Month Modified Files and Folders =======

2014-02-17 15:28 - 2014-02-17 15:28 - 00014488 _____ () C:\Users\Rodina\Desktop\FRST.txt
2014-02-17 15:28 - 2014-02-17 15:27 - 00000000 ____D () C:\FRST
2014-02-17 15:26 - 2014-02-17 15:26 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Downloads\FRSTLauncher (1).exe
2014-02-17 15:26 - 2014-02-17 15:26 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Desktop\FRSTLauncher (1).exe
2014-02-17 15:26 - 2014-02-02 16:38 - 01553118 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 15:24 - 2014-02-17 15:24 - 00112640 _____ (forum.viry.cz) C:\Users\Rodina\Downloads\Nepotvrzeno 718756.crdownload
2014-02-17 15:21 - 2014-02-15 22:31 - 00014872 _____ () C:\Windows\setupact.log
2014-02-17 15:21 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-17 15:19 - 2010-03-18 23:02 - 00010512 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-17 15:19 - 2010-03-18 23:02 - 00010512 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-17 15:15 - 2014-02-17 15:15 - 01141248 _____ (Farbar) C:\Users\Rodina\Downloads\FRST.exe
2014-02-17 15:15 - 2014-02-17 15:15 - 01141248 _____ (Farbar) C:\Users\Rodina\Desktop\FRST.exe
2014-02-17 15:15 - 2014-02-17 15:15 - 00110747 _____ () C:\Users\Rodina\Downloads\trz4F00.tmp
2014-02-17 13:22 - 2012-07-11 19:02 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-16 19:59 - 2013-02-23 13:39 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\vlc
2014-02-16 19:21 - 2014-02-16 18:44 - 671169880 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x04-cz.avi
2014-02-16 17:56 - 2014-02-16 17:18 - 671872292 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x03-cz.avi
2014-02-16 17:17 - 2014-02-16 16:40 - 671788722 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x02-cz.avi.crdownload
2014-02-16 16:36 - 2014-02-16 15:59 - 672914046 _____ () C:\Users\Rodina\Downloads\Skutecni-lide-1x01-cz.avi.crdownload
2014-02-16 14:54 - 2009-06-16 17:30 - 00000000 ____D () C:\Users\Rodina\AppData\Local\Adobe
2014-02-16 14:53 - 2012-07-11 19:02 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-16 14:53 - 2011-06-24 17:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-16 12:01 - 2014-02-16 11:42 - 00014186 _____ () C:\zoek-results.log
2014-02-16 11:59 - 2014-02-16 11:59 - 00000334 _____ () C:\Windows\PFRO.log
2014-02-16 11:56 - 2014-02-16 11:40 - 00000000 ____D () C:\zoek_backup
2014-02-16 11:40 - 2014-02-16 11:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-16 11:37 - 2014-02-16 11:37 - 01283584 _____ () C:\Users\Rodina\Downloads\zoek.exe
2014-02-16 11:37 - 2014-02-16 11:37 - 01283584 _____ () C:\Users\Rodina\Desktop\zoek.exe
2014-02-16 11:32 - 2013-10-11 12:31 - 00000000 ____D () C:\AdwCleaner
2014-02-16 11:19 - 2014-02-16 11:19 - 01166132 _____ () C:\Users\Rodina\Desktop\adwcleaner.exe
2014-02-16 11:19 - 2014-02-16 11:18 - 01166132 _____ () C:\Users\Rodina\Downloads\adwcleaner.exe
2014-02-15 22:41 - 2010-03-19 00:12 - 01497710 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-15 22:38 - 2014-02-15 22:38 - 00000000 ____D () C:\Program Files\Marvell
2014-02-15 22:38 - 2014-02-15 22:37 - 00009436 _____ () C:\Windows\ykinstutil.log
2014-02-15 22:38 - 2014-02-15 22:37 - 00000364 ____R () C:\Windows\YukonInstall.log
2014-02-15 22:34 - 2012-06-07 15:16 - 00000000 ____D () C:\Users\Rodina\x
2014-02-15 22:34 - 2010-03-18 23:03 - 00000000 ____D () C:\Users\Rodina
2014-02-15 22:31 - 2014-02-15 22:31 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-15 22:23 - 2012-12-09 17:56 - 00000000 ____D () C:\Users\Rodina\AppData\Local\CrashDumps
2014-02-15 22:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-02-15 22:23 - 2009-06-05 17:43 - 00000000 ___RD () C:\Users\Rodina\Programy
2014-02-15 22:16 - 2012-08-24 15:34 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-15 22:13 - 2014-02-11 17:47 - 00000000 ____D () C:\Program Files\Driver Detective 9.0.0.23(malestom)(h33t)
2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 18:16 - 2014-02-14 12:04 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-02-15 17:26 - 2014-02-15 14:16 - 00000510 _____ () C:\Users\Rodina\rgmnr
2014-02-15 17:25 - 2014-02-15 16:25 - 00013464 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-02-15 17:23 - 2014-02-15 17:22 - 00000023 _____ () C:\Windows\Model.txt
2014-02-15 16:49 - 2014-02-15 16:49 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-02-15 16:48 - 2010-03-18 23:02 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-02-15 16:25 - 2014-02-15 16:25 - 00000000 ____D () C:\Users\Rodina\AppData\Local\SlimWare Utilities Inc
2014-02-15 16:25 - 2014-02-15 16:25 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-02-15 15:32 - 2009-07-20 12:22 - 00000000 ____D () C:\Program Files\trend micro
2014-02-15 14:34 - 2014-02-15 14:34 - 00000899 _____ () C:\Users\host\Desktop\Plus500.lnk
2014-02-15 14:34 - 2014-02-15 14:34 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plus500
2014-02-15 14:34 - 2014-02-15 14:33 - 00000000 ____D () C:\Users\Rodina\AppData\Local\Plus500
2014-02-15 14:33 - 2014-02-15 14:33 - 00000000 ____D () C:\Program Files\Plus500
2014-02-15 14:01 - 2013-10-04 17:25 - 00001136 _____ () C:\Users\Rodina\AppData\Local\SRDownloader (1).nast
2014-02-15 13:53 - 2013-10-04 17:25 - 00006845 _____ () C:\Users\Rodina\AppData\Local\SRDownloader (1).err
2014-02-14 15:29 - 2014-02-14 15:29 - 00023456 _____ (Phoenix Technologies) C:\Windows\system32\Drivers\DrvAgent32.sys
2014-02-14 15:18 - 2014-02-14 15:16 - 00000000 ____D () C:\ProgramData\AVG
2014-02-14 15:18 - 2009-07-14 05:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\AVG
2014-02-14 15:16 - 2014-02-14 15:16 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-02-14 15:14 - 2014-02-14 15:14 - 00000000 ____D () C:\DriverPack Solution
2014-02-14 12:42 - 2013-09-25 11:05 - 00000000 ____D () C:\Users\Rodina\2. ročník Ing
2014-02-14 12:24 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-02-14 10:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-14 10:22 - 2013-08-01 10:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-14 10:13 - 2010-04-15 08:16 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 18:58 - 2014-02-13 17:50 - 00000000 ____D () C:\Users\Rodina\Desktop\DIPLOMKA
2014-02-12 15:18 - 2014-01-09 22:59 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-02-12 15:18 - 2011-02-25 17:42 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-12 15:18 - 2010-06-30 17:04 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-12 15:18 - 2009-08-07 16:39 - 00410784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-12 15:18 - 2009-08-07 16:39 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-12 15:18 - 2009-08-07 16:39 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-12 15:12 - 2012-07-11 17:41 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-12 15:12 - 2012-07-11 17:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-11 20:03 - 2009-07-14 03:37 - 00000000 __RSD () C:\Windows\Media
2014-02-11 17:44 - 2014-02-11 17:44 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\PC Drivers HeadQuarters
2014-02-11 17:44 - 2014-02-11 17:44 - 00000000 ____D () C:\Program Files\PC Drivers HeadQuarters
2014-02-11 17:40 - 2014-02-10 21:05 - 00000000 ____D () C:\Program Files\Gabest
2014-02-11 17:40 - 2014-02-10 21:04 - 00000000 ____D () C:\Program Files\AviSynth 2.5
2014-02-11 17:38 - 2014-02-11 17:38 - 00000000 ____D () C:\ProgramData\PC Drivers HeadQuarters
2014-02-10 21:36 - 2014-02-10 21:36 - 00000110 ____H () C:\Users\Rodina\Desktop\DSC06628.JPG.uid-zps
2014-02-09 18:07 - 2014-02-09 17:41 - 00000000 ____D () C:\Users\Rodina\Desktop\2014
2014-02-08 16:33 - 2014-02-08 16:33 - 01972224 _____ () C:\Users\host\Downloads\Jak_ma_vypadat_babicka (1).pps
2014-02-08 16:27 - 2014-02-08 16:27 - 02011648 _____ () C:\Users\host\Downloads\2116_D_--_hajzliky.pps
2014-02-08 16:27 - 2014-02-08 16:27 - 01972224 _____ () C:\Users\host\Downloads\Jak_ma_vypadat_babicka.pps
2014-02-08 16:26 - 2014-02-08 16:26 - 04161536 _____ () C:\Users\host\Downloads\pohádková_vesnicka.pps
2014-02-06 11:38 - 2014-02-14 10:25 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 11:20 - 2014-02-14 10:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 11:19 - 2014-02-14 10:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 11:01 - 2014-02-14 10:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 11:00 - 2014-02-14 10:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-14 10:26 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 10:52 - 2014-02-14 10:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 10:52 - 2014-02-14 10:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 10:49 - 2014-02-14 10:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 10:47 - 2014-02-14 10:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 10:47 - 2014-02-14 10:26 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 10:46 - 2014-02-14 10:26 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 10:34 - 2014-02-14 10:26 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 10:25 - 2014-02-14 10:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 10:25 - 2014-02-14 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 10:13 - 2014-02-14 10:26 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:09 - 2014-02-14 10:25 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:03 - 2014-02-14 10:25 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 09:41 - 2014-02-14 10:25 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 09:36 - 2014-02-14 10:25 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:34 - 2014-02-14 10:26 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-03 20:37 - 2010-06-11 07:05 - 00000000 ____D () C:\Windows\PCHEALTH
2014-02-03 18:06 - 2014-02-01 11:57 - 00000000 ____D () C:\Users\Rodina\xbox
2014-02-02 18:53 - 2014-02-02 18:36 - 589503881 _____ () C:\Users\Rodina\Downloads\The.Philosophers.2013.BDRip.x264-kst.mkv
2014-02-02 16:29 - 2009-06-16 14:24 - 00000000 ____D () C:\Program Files\CCleaner
2014-02-02 16:21 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-02-02 15:42 - 2014-02-02 15:32 - 183437621 _____ () C:\Users\Rodina\Downloads\Windows-8---Základní-instalační-balíček-1.0.zip
2014-02-01 20:10 - 2010-01-17 13:32 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\Skype
2014-02-01 14:15 - 2014-02-01 14:15 - 00905728 _____ (Share-rapid.com) C:\Users\Rodina\Downloads\SRDownloader (1).exe
2014-01-31 13:29 - 2014-01-31 13:29 - 00000000 ____D () C:\Users\Rodina\AppData\Roaming\abgx360
2014-01-31 13:27 - 2014-01-31 13:27 - 00000000 ____D () C:\Program Files\abgx360
2014-01-30 17:54 - 2011-03-08 22:17 - 00001376 _____ () C:\Users\Rodina\AppData\Local\SRDownloader.nast
2014-01-30 17:48 - 2012-08-25 10:11 - 00004833 _____ () C:\Users\Rodina\AppData\Local\SRDownloader.err
2014-01-30 01:19 - 2014-02-10 16:15 - 1329400960 _____ () C:\Users\Rodina\Downloads\Vlk z Wall Street CZ-titulky.avi
2014-01-29 16:59 - 2010-01-22 19:33 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2014-01-29 16:56 - 2013-09-28 11:31 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-29 16:55 - 2014-01-29 16:55 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-29 16:55 - 2014-01-29 16:55 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-29 16:55 - 2014-01-29 16:55 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-01-29 16:44 - 2014-01-03 17:42 - 00000000 ____D () C:\Users\Rodina\vocvohoz
2014-01-20 15:57 - 2009-03-09 19:40 - 00000000 ____D () C:\Windows\InstDrvs

Files to move or delete:
====================
C:\Users\Rodina\AppData\Roaming\desktop.ini


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\ProgramData\TEMP:24051EFF

==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Rodina\Desktop" je 1063 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\20131121
C:\Program Files\Alwil Software\Avast5\setup\emupdate\7701b66b-47da-460f-88f5-b714419b246d.exe /check [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
"C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader
"C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
"C:\Program Files\ICQ7M\ICQ.exe" silent loginmode=4 [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncqsvtnSrv
C:\Windows\inf\mncqsvtn.vbe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
C:\PROGRA~1\McAfee Security Scan\3.8.130\SSScheduler.exe [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================

Re: Preventivka,dekuji.

Napsal: 23 úno 2014 09:33
od vyosek
Udelejte novy sken MBAMem

Re: Preventivka,dekuji.

Napsal: 26 úno 2014 19:59
od lost16
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.26.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16518
Rodina :: FANDA-PC [administrátor]

26.2.2014 16:37:01
MBAM-log-2014-02-26 (19-57-48).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 429947
Uplynulý čas: 3 hodin, 13 minut, 51 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
C:\Users\Rodina\Downloads\trz4F00.tmp (Trojan.Agent.BAT) -> Nebyla provedena žádná instrukce.

(konec)

Re: Preventivka,dekuji.

Napsal: 01 bře 2014 23:27
od vyosek
Nalezy smazte, objevi se log, ten rad uvidim