Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-02-2014 01
Ran by Peter (administrator) on PETER-PC on 16-02-2014 17:36:14
Running from C:\Users\Peter\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp.) C:\Windows\SOUNDMAN.EXE
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(IObit) C:\Program Files\IObit\Advanced SystemCare 6\ASC.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Peter\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Cm108Sound] - RunDll32 cm108.cpl,CMICtrlWnd
HKLM\...\Run: [SoundMan] - C:\Windows\SOUNDMAN.EXE [604704 2009-04-14] (Realtek Semiconductor Corp.)
HKU\.DEFAULT\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [894344 2013-02-05] (Autodesk, Inc.)
HKU\S-1-5-21-2313411190-107904724-3513802042-1001\...\Run: [Facebook Update] - C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-25] (Facebook Inc.)
HKU\S-1-5-21-2313411190-107904724-3513802042-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2313411190-107904724-3513802042-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2313411190-107904724-3513802042-1001\...\MountPoints2: {95dc59fb-5c50-11e0-9375-0009d0500433} - G:\autorun.exe
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\Run: [] - [X]
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\Run: [Google Update] - C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-03-30] (Google Inc.)
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\Run: [Facebook Update] - C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-25] (Facebook Inc.)
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\Policies\Explorer: []
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2313411190-107904724-3513802042-1007\...\MountPoints2: {95dc59fb-5c50-11e0-9375-0009d0500433} - G:\autorun.exe
AppInit_DLLs: c:\progra~2\smartweb\smartweb.dll => C:\ProgramData\SmartWeb\SmartWeb.dll [4162048 2013-12-28] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyServer: 222.222.222.222:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A9E751E03EFCB01
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search =
http://search.icq.com/search/results.ph ... earchTerms}
URLSearchHook: HKCU - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe
http://www.dosearches.com/?utm_source=b ... 1379766379
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://search.dosearches.com/web/?utm_s ... earchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://search.dosearches.com/web/?utm_s ... earchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.as ... =CT2737658
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
http://search.sweetim.com/search.asp?sr ... 0000.10011
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL =
http://search.icq.com/search/results.ph ... earchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.as ... =CT2737658
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
http://search.sweetim.com/search.asp?sr ... 0000.10011
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: 127.0.0.1
www.iobit.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A8D8574F-0375-495A-B09C-66E4D1721683}: [NameServer]8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\cpactsbn.default
FF user.js: detected! => C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\cpactsbn.default\user.js
FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", "");
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", "");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Peter\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Peter\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Peter\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: No Name - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2013-07-05]
FF Extension: GoPhotoIt - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\profiles\extensions\
gophoto@gophoto.it.xpi [2012-07-31]
FF Extension: NeteoCoupon - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\cpactsbn.default\Extensions\
dsrx@jegrieiu.com [2014-01-02]
FF Extension: BitSavEr - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\cpactsbn.default\Extensions\
iyy_me6k@fibb.net [2014-01-02]
FF Extension: AdBlocknWattch - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\cpactsbn.default\Extensions\
mdwkklfhzq@nfqyttrez.co.uk [2014-01-31]
Chrome:
=======
CHR HomePage:
CHR RestoreOnStartup: ""
CHR Plugin: (Shockwave Flash) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.138\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Peter\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Peter\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Peter\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
CHR Extension: (AdBlocknWattch) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\adadcfejfmdfbdkpbcnfhmdjmhapnmok [2014-01-31]
CHR Extension: (Media Plugin) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocphobfcfafpclibolpjdafgaffkaoci [2013-12-15]
CHR Extension: (BitSavEr) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnpjdolpbnjlionimoghhjlodedbokfm [2014-01-01]
CHR Extension: (NeteoCoupon) - C:\ProgramData\pnebadonfpdmnegceohciocapepgonmg [2014-01-01]
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\ASC_GhromePlugin.crx [2013-07-05]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Peter\AppData\Local\GamePlayLabs Plugin\plugin.crx [2011-05-08]
CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit14.crx [2012-07-31]
CHR StartMenuInternet: Google Chrome - C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 34677ac8; C:\ProgramData\SmartWeb\SmartWebSvc.dll [180048 2013-12-28] ()
S4 AdvancedSystemCareService6; C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe [574272 2013-04-18] (IObit)
S4 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [86016 2013-08-30] (Dassault Systèmes)
S4 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2013-12-14] (Flexera Software LLC)
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] ()
S4 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit)
S4 mitsijm2014; D:\inventor\Inventor 2014\Moldflow\bin\mitsijm.exe [723744 2013-01-25] (Autodesk, Inc.)
S4 RzOvlMon; C:\Program Files\Razer\Core\rzovlmon.exe [30912 2013-11-21] (Razer, Inc.)
S2 WiseBootAssistant; C:\Program Files\Wise\Wise Care 365\BootTime.exe [580232 2013-04-25] (WiseCleaner.com)
S4 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [825920 2013-09-21] (Wsys Co., Ltd.)
S4 ICQ Service; No ImagePath
==================== Drivers (Whitelisted) ====================
R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC.SYS [4172832 2009-06-19] (Realtek Semiconductor Corp.)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R3 EuMusDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\vrtaucbl.sys [84096 2013-09-21] (Eugene V. Muzychenko)
S3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36640 2012-12-18] ()
S3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [19456 2012-08-15] (Siliten)
S3 NTIOLib_1_0_4; C:\Program Files\MSI\Live Update 5\NTIOLib.sys [7680 2010-10-20] (MSI)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [102592 2013-11-21] (Razer, Inc.)
R0 RzFilter; C:\Windows\System32\drivers\RzFilter.sys [65216 2013-11-21] (Razer, Inc.)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [15672 2013-05-22] ()
S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1517056 2010-08-12] (C-Media Electronics Inc)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-16 17:36 - 2014-02-16 17:36 - 00015405 _____ () C:\Users\Peter\Desktop\FRST.txt
2014-02-16 17:35 - 2014-02-16 17:36 - 00000000 ____D () C:\FRST
2014-02-16 17:34 - 2014-02-16 17:34 - 01141248 _____ (Farbar) C:\Users\Peter\Downloads\FRST.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 01141248 _____ (Farbar) C:\Users\Peter\Desktop\FRST.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Peter\Downloads\FRSTLauncher.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Peter\Desktop\FRSTLauncher.exe
2014-02-16 16:30 - 2014-02-16 16:30 - 00004577 _____ () C:\Users\Peter\Documents\hijackthis.log
2014-02-15 19:28 - 2014-02-15 19:28 - 00002147 _____ () C:\Users\Peter\Desktop\League of Legends Championship LCS IEM all music - PART 2 (breakmusic) HD - odkaz.lnk
2014-02-12 17:55 - 2014-02-16 15:32 - 00000616 _____ () C:\Windows\setupact.log
2014-02-12 17:55 - 2014-02-12 17:55 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-12 17:54 - 2014-02-12 17:54 - 00012592 _____ () C:\Windows\PFRO.log
2014-02-12 17:53 - 2014-02-12 17:53 - 00000000 _____ () C:\asc_rdflag
2014-02-11 15:41 - 2014-02-11 15:41 - 00000000 ____D () C:\Users\Peter\Downloads\backups
2014-02-11 15:39 - 2014-02-11 15:39 - 00004565 _____ () C:\Users\Peter\Desktop\hijackthis.log
2014-02-11 15:37 - 2014-02-11 15:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Peter\Downloads\hijackthis.exe
2014-02-10 10:54 - 2014-02-10 10:54 - 00013002 _____ () C:\Users\Peter\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2014-02-06 15:40 - 2014-02-07 23:21 - 00002318 _____ () C:\Users\Peter\Desktop\League of Legends Championship _ LCS _ IEM all music (breakmusic _ during a break) HD Original - odkaz.lnk
2014-02-06 10:26 - 2014-02-06 10:26 - 00019459 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E13_The_Purge_TvRip_.torrent
2014-02-06 10:25 - 2014-02-06 10:26 - 00015639 _____ () C:\Users\Peter\Downloads\Supernatural_S09E13.rar
2014-02-05 19:49 - 2014-02-05 19:49 - 00000000 ____D () C:\Users\Peter\Downloads\Mysli_jako_on_2012_cz
2014-02-05 19:48 - 2014-02-05 19:48 - 00018432 _____ () C:\Users\Peter\Downloads\[CzT]Mysli_jako_on_Think_Like_a_Man_2012_CZ_.torrent
2014-02-04 18:49 - 2014-02-04 18:49 - 00016850 _____ () C:\Users\Peter\Downloads\[CzT]Captain_America_Prvni_Avenger_Captain_America_2011_.torrent
2014-02-03 22:44 - 2013-01-31 12:21 - 19915552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2014-02-03 22:44 - 2013-01-31 12:21 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-02-03 22:44 - 2013-01-31 12:21 - 10919200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-02-03 22:44 - 2013-01-31 12:21 - 07754560 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-02-03 22:44 - 2013-01-31 12:21 - 02577184 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-02-03 22:44 - 2013-01-31 12:21 - 01869088 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-02-03 22:41 - 2014-02-03 22:41 - 00319488 _____ (Realtek Semiconductor Corp.) C:\Windows\HideWin.exe
2014-02-03 22:41 - 2014-02-03 22:41 - 00000000 ____D () C:\Program Files\Realtek AC97
2014-02-03 22:33 - 2014-02-03 22:33 - 00001165 _____ () C:\Users\Public\Desktop\Driver Genius Professional Edition.lnk
2014-02-03 22:33 - 2014-02-03 22:33 - 00000000 ____D () C:\Program Files\Driver-Soft
2014-02-03 22:31 - 2014-02-03 22:31 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Driver-Soft
2014-02-03 22:29 - 2014-02-03 22:29 - 28170967 _____ (Driver-Soft) C:\Users\Peter\Downloads\drvgenpro.exe
2014-02-03 22:28 - 2014-02-03 22:28 - 00017733 _____ () C:\Users\Peter\Downloads\[CzT]Driver_Genius_Professional_Edition_11_0_0_1138_CZ_SK_.torrent
2014-02-03 12:25 - 2014-02-03 12:25 - 00012641 _____ () C:\Users\Peter\Downloads\[CzT]Czech_Amateurs_92_720pHD_.torrent
2014-02-03 12:22 - 2014-02-03 12:22 - 00014706 _____ () C:\Users\Peter\Downloads\[CzT]Udelej_se_Katka_720pHD_.torrent
2014-02-03 12:22 - 2014-02-03 12:22 - 00014341 _____ () C:\Users\Peter\Downloads\[CzT]James_Deen_Ava_Addams.torrent
2014-02-02 21:10 - 2014-02-02 21:10 - 00000604 _____ () C:\Users\Peter\Downloads\utazky ktore boli.txt
2014-02-01 12:26 - 2014-02-01 12:26 - 06696482 _____ () C:\Users\Peter\Downloads\pap-poznamky.rar
2014-01-31 22:37 - 2014-01-31 22:37 - 00002478 __RSH () C:\ProgramData\ntuser.pol
2014-01-31 22:37 - 2014-01-31 22:37 - 00000000 ____D () C:\ProgramData\AdBlocknWattch
2014-01-31 22:37 - 2014-01-31 22:37 - 00000000 ____D () C:\ProgramData\adadcfejfmdfbdkpbcnfhmdjmhapnmok
2014-01-30 23:10 - 2014-01-30 23:10 - 00000000 ____D () C:\Users\Peter\Desktop\matika
2014-01-28 15:21 - 2014-01-28 18:39 - 00000000 ____D () C:\Users\Peter\Desktop\2014_01_28
2014-01-26 21:20 - 2014-01-26 21:21 - 00078848 _____ () C:\Users\Peter\Downloads\syntax a štylistika.ppt
2014-01-25 23:03 - 2014-01-25 23:03 - 00014607 _____ () C:\Users\Peter\Downloads\[CzT]Total_Recall_2012_.torrent
2014-01-25 15:03 - 2014-02-16 12:08 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001UA.job
2014-01-25 15:03 - 2014-02-15 15:08 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001Core.job
2014-01-25 15:03 - 2014-01-25 15:03 - 00000000 ____D () C:\Users\Peter\AppData\Local\Facebook
2014-01-25 15:00 - 2014-01-25 15:00 - 00501248 _____ (Facebook Inc.) C:\Users\Peter\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-01-24 23:39 - 2014-01-24 23:39 - 00019417 _____ () C:\Users\Peter\Downloads\[CzT]Konecna_The_Last_Stand_2013_CZ_.torrent
2014-01-23 10:40 - 2014-01-23 10:41 - 909697033 _____ () C:\Users\Peter\Downloads\Supernatural.S09E11.720p.HDTV.X264-DIMENSION.mkv
2014-01-23 10:38 - 2014-01-23 10:38 - 00017931 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E11_First_Born_TVRip_720p_.torrent
2014-01-23 10:37 - 2014-01-23 10:37 - 00017440 _____ () C:\Users\Peter\Downloads\Supernatural_S09E11.rar
2014-01-23 10:36 - 2014-01-23 10:36 - 00018836 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E11_First_Born_TVRip_.torrent
2014-01-20 22:38 - 2014-01-20 22:49 - 823046144 _____ () C:\Users\Peter\Downloads\jOBS.avi
2014-01-20 22:37 - 2014-01-20 22:37 - 00016229 _____ () C:\Users\Peter\Downloads\[CzT]jOBS_2013_CZ_.torrent
2014-01-20 13:02 - 2014-01-20 13:02 - 00020799 _____ () C:\Users\Peter\Downloads\[CzT]Rychly_prachy_34_Praha_24_08_2009_CZ_.torrent
2014-01-19 21:35 - 2014-01-19 21:50 - 00000000 ____D () C:\Users\Peter\Desktop\2014_01_19
2014-01-18 20:58 - 2014-01-18 20:58 - 00016996 _____ () C:\Users\Peter\Downloads\[CzT]Souboj_Titanu_Clash_of_the_Titans_2010_.torrent
2014-01-18 17:23 - 2014-01-18 17:33 - 00000000 ____D () C:\Users\Peter\Downloads\Plán útěku
2014-01-18 17:23 - 2014-01-18 17:23 - 00015288 _____ () C:\Users\Peter\Downloads\[CzT]Plan_uteku_Escape_Plan_2013_.torrent
2014-01-17 10:37 - 2014-01-17 11:02 - 226488722 _____ () C:\Users\Peter\Downloads\Supernatural-S09E10---Road-Trip.rar
2014-01-17 10:36 - 2014-01-17 10:42 - 364510674 _____ () C:\Users\Peter\Downloads\Supernatural.S09E10.HDTV.XviD-FUM.avi
2014-01-17 10:35 - 2014-01-17 10:35 - 00014478 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E10_Road_Trip_TvRip_.torrent
2014-01-17 10:33 - 2014-01-17 10:33 - 00016352 _____ () C:\Users\Peter\Downloads\Supernatural_S09E10.rar
==================== One Month Modified Files and Folders =======
2014-02-16 17:36 - 2014-02-16 17:36 - 00015405 _____ () C:\Users\Peter\Desktop\FRST.txt
2014-02-16 17:36 - 2014-02-16 17:35 - 00000000 ____D () C:\FRST
2014-02-16 17:34 - 2014-02-16 17:34 - 01141248 _____ (Farbar) C:\Users\Peter\Downloads\FRST.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 01141248 _____ (Farbar) C:\Users\Peter\Desktop\FRST.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Peter\Downloads\FRSTLauncher.exe
2014-02-16 17:34 - 2014-02-16 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Peter\Desktop\FRSTLauncher.exe
2014-02-16 17:32 - 2012-09-30 12:29 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Skype
2014-02-16 16:44 - 2011-03-30 18:52 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001UA.job
2014-02-16 16:37 - 2012-04-05 09:30 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-16 16:30 - 2014-02-16 16:30 - 00004577 _____ () C:\Users\Peter\Documents\hijackthis.log
2014-02-16 15:36 - 2014-01-07 08:20 - 00365696 _____ () C:\Windows\WindowsUpdate.log
2014-02-16 15:33 - 2013-12-15 23:08 - 00000444 ____H () C:\Windows\Tasks\SK.Enabler-S-1495795506.job
2014-02-16 15:32 - 2014-02-12 17:55 - 00000616 _____ () C:\Windows\setupact.log
2014-02-16 15:32 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-16 13:41 - 2011-03-30 18:52 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001Core.job
2014-02-16 12:08 - 2014-01-25 15:03 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001UA.job
2014-02-15 19:28 - 2014-02-15 19:28 - 00002147 _____ () C:\Users\Peter\Desktop\League of Legends Championship LCS IEM all music - PART 2 (breakmusic) HD - odkaz.lnk
2014-02-15 15:08 - 2014-01-25 15:03 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001Core.job
2014-02-13 23:50 - 2013-04-28 22:13 - 00000000 ____D () C:\Users\Peter\Desktop\Jeble obrazky
2014-02-13 15:50 - 2013-04-02 18:55 - 00000000 ____D () C:\Users\Peter\AppData\Local\PMB Files
2014-02-13 15:50 - 2013-04-02 18:55 - 00000000 ____D () C:\ProgramData\PMB Files
2014-02-12 17:55 - 2014-02-12 17:55 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-12 17:54 - 2014-02-12 17:54 - 00012592 _____ () C:\Windows\PFRO.log
2014-02-12 17:53 - 2014-02-12 17:53 - 00000000 _____ () C:\asc_rdflag
2014-02-12 17:53 - 2013-07-05 14:56 - 00000000 ____D () C:\Users\UpdatusUser.Peter-PC
2014-02-12 17:53 - 2011-03-30 18:49 - 00000000 ____D () C:\Users\Peter
2014-02-12 16:18 - 2009-07-14 05:34 - 00017296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:18 - 2009-07-14 05:34 - 00017296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-12 16:03 - 2011-03-30 20:26 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\uTorrent
2014-02-11 18:05 - 2011-03-30 18:52 - 00000000 ____D () C:\Users\Peter\AppData\Local\Deployment
2014-02-11 17:28 - 2013-12-26 15:52 - 00000000 ____D () C:\Users\Peter\AppData\Local\CrashDumps
2014-02-11 15:41 - 2014-02-11 15:41 - 00000000 ____D () C:\Users\Peter\Downloads\backups
2014-02-11 15:39 - 2014-02-11 15:39 - 00004565 _____ () C:\Users\Peter\Desktop\hijackthis.log
2014-02-11 15:38 - 2014-02-11 15:37 - 00388608 _____ (Trend Micro Inc.) C:\Users\Peter\Downloads\hijackthis.exe
2014-02-10 11:34 - 2014-01-02 17:24 - 2601699328 _____ () C:\Users\Peter\Downloads\The.Hobbit.An.Unexpected.Journey.2012.BRRip.XviD.AC3.CZ.avi
2014-02-10 10:54 - 2014-02-10 10:54 - 00013002 _____ () C:\Users\Peter\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2014-02-10 09:39 - 2012-04-05 09:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-10 09:39 - 2011-05-30 00:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-09 20:16 - 2013-12-08 18:34 - 00000000 ____D () C:\Users\Peter\Desktop\Ja a Nikuš
2014-02-08 15:04 - 2013-10-31 16:46 - 00026112 _____ () C:\Users\Peter\Desktop\Treningove plany.xls
2014-02-07 23:21 - 2014-02-06 15:40 - 00002318 _____ () C:\Users\Peter\Desktop\League of Legends Championship _ LCS _ IEM all music (breakmusic _ during a break) HD Original - odkaz.lnk
2014-02-07 15:38 - 2012-09-29 13:58 - 00000000 ____D () C:\Users\Peter\Desktop\POWERLEVELING
2014-02-06 10:26 - 2014-02-06 10:26 - 00019459 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E13_The_Purge_TvRip_.torrent
2014-02-06 10:26 - 2014-02-06 10:25 - 00015639 _____ () C:\Users\Peter\Downloads\Supernatural_S09E13.rar
2014-02-05 19:49 - 2014-02-05 19:49 - 00000000 ____D () C:\Users\Peter\Downloads\Mysli_jako_on_2012_cz
2014-02-05 19:48 - 2014-02-05 19:48 - 00018432 _____ () C:\Users\Peter\Downloads\[CzT]Mysli_jako_on_Think_Like_a_Man_2012_CZ_.torrent
2014-02-04 18:49 - 2014-02-04 18:49 - 00016850 _____ () C:\Users\Peter\Downloads\[CzT]Captain_America_Prvni_Avenger_Captain_America_2011_.torrent
2014-02-03 22:46 - 2012-03-21 11:28 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-03 22:46 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help
2014-02-03 22:41 - 2014-02-03 22:41 - 00319488 _____ (Realtek Semiconductor Corp.) C:\Windows\HideWin.exe
2014-02-03 22:41 - 2014-02-03 22:41 - 00000000 ____D () C:\Program Files\Realtek AC97
2014-02-03 22:40 - 2012-01-25 20:08 - 00000000 ____D () C:\ProgramData\DriverGenius
2014-02-03 22:33 - 2014-02-03 22:33 - 00001165 _____ () C:\Users\Public\Desktop\Driver Genius Professional Edition.lnk
2014-02-03 22:33 - 2014-02-03 22:33 - 00000000 ____D () C:\Program Files\Driver-Soft
2014-02-03 22:31 - 2014-02-03 22:31 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Driver-Soft
2014-02-03 22:29 - 2014-02-03 22:29 - 28170967 _____ (Driver-Soft) C:\Users\Peter\Downloads\drvgenpro.exe
2014-02-03 22:28 - 2014-02-03 22:28 - 00017733 _____ () C:\Users\Peter\Downloads\[CzT]Driver_Genius_Professional_Edition_11_0_0_1138_CZ_SK_.torrent
2014-02-03 12:25 - 2014-02-03 12:25 - 00012641 _____ () C:\Users\Peter\Downloads\[CzT]Czech_Amateurs_92_720pHD_.torrent
2014-02-03 12:22 - 2014-02-03 12:22 - 00014706 _____ () C:\Users\Peter\Downloads\[CzT]Udelej_se_Katka_720pHD_.torrent
2014-02-03 12:22 - 2014-02-03 12:22 - 00014341 _____ () C:\Users\Peter\Downloads\[CzT]James_Deen_Ava_Addams.torrent
2014-02-02 21:10 - 2014-02-02 21:10 - 00000604 _____ () C:\Users\Peter\Downloads\utazky ktore boli.txt
2014-02-01 12:26 - 2014-02-01 12:26 - 06696482 _____ () C:\Users\Peter\Downloads\pap-poznamky.rar
2014-02-01 12:26 - 2013-11-24 22:14 - 00000000 ____D () C:\Users\Peter\Desktop\Pevnosť pružnosť
2014-01-31 22:37 - 2014-01-31 22:37 - 00002478 __RSH () C:\ProgramData\ntuser.pol
2014-01-31 22:37 - 2014-01-31 22:37 - 00000000 ____D () C:\ProgramData\AdBlocknWattch
2014-01-31 22:37 - 2014-01-31 22:37 - 00000000 ____D () C:\ProgramData\adadcfejfmdfbdkpbcnfhmdjmhapnmok
2014-01-31 22:37 - 2013-12-15 23:07 - 00000000 ____D () C:\ProgramData\4c8da25714f3b573
2014-01-30 23:10 - 2014-01-30 23:10 - 00000000 ____D () C:\Users\Peter\Desktop\matika
2014-01-30 12:38 - 2014-01-10 16:25 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Spotify
2014-01-30 09:33 - 2014-01-10 16:25 - 00000000 ____D () C:\Users\Peter\AppData\Local\Spotify
2014-01-29 15:38 - 2009-07-14 05:53 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-28 23:09 - 2013-04-23 14:32 - 00000000 ____D () C:\Users\Peter\Desktop\matika11
2014-01-28 18:39 - 2014-01-28 15:21 - 00000000 ____D () C:\Users\Peter\Desktop\2014_01_28
2014-01-26 21:54 - 2013-11-24 22:16 - 00000000 ____D () C:\Users\Peter\Desktop\Vyrobne technologie
2014-01-26 21:21 - 2014-01-26 21:20 - 00078848 _____ () C:\Users\Peter\Downloads\syntax a štylistika.ppt
2014-01-25 23:03 - 2014-01-25 23:03 - 00014607 _____ () C:\Users\Peter\Downloads\[CzT]Total_Recall_2012_.torrent
2014-01-25 15:03 - 2014-01-25 15:03 - 00000000 ____D () C:\Users\Peter\AppData\Local\Facebook
2014-01-25 15:00 - 2014-01-25 15:00 - 00501248 _____ (Facebook Inc.) C:\Users\Peter\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-01-25 01:04 - 2011-03-30 18:54 - 00391756 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-01-24 23:39 - 2014-01-24 23:39 - 00019417 _____ () C:\Users\Peter\Downloads\[CzT]Konecna_The_Last_Stand_2013_CZ_.torrent
2014-01-23 10:41 - 2014-01-23 10:40 - 909697033 _____ () C:\Users\Peter\Downloads\Supernatural.S09E11.720p.HDTV.X264-DIMENSION.mkv
2014-01-23 10:38 - 2014-01-23 10:38 - 00017931 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E11_First_Born_TVRip_720p_.torrent
2014-01-23 10:37 - 2014-01-23 10:37 - 00017440 _____ () C:\Users\Peter\Downloads\Supernatural_S09E11.rar
2014-01-23 10:36 - 2014-01-23 10:36 - 00018836 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E11_First_Born_TVRip_.torrent
2014-01-22 21:47 - 2014-01-12 22:23 - 00000000 ____D () C:\Users\Peter\Desktop\2014_01_12
2014-01-20 22:49 - 2014-01-20 22:38 - 823046144 _____ () C:\Users\Peter\Downloads\jOBS.avi
2014-01-20 22:37 - 2014-01-20 22:37 - 00016229 _____ () C:\Users\Peter\Downloads\[CzT]jOBS_2013_CZ_.torrent
2014-01-20 13:02 - 2014-01-20 13:02 - 00020799 _____ () C:\Users\Peter\Downloads\[CzT]Rychly_prachy_34_Praha_24_08_2009_CZ_.torrent
2014-01-19 21:50 - 2014-01-19 21:35 - 00000000 ____D () C:\Users\Peter\Desktop\2014_01_19
2014-01-19 03:00 - 2012-03-21 07:46 - 00000332 _____ () C:\Windows\Tasks\RegInOut Scheduled Scan - Peter.job
2014-01-19 03:00 - 2012-01-20 13:29 - 00000372 _____ () C:\Windows\Tasks\RegAce Scheduled Scan - Peter.job
2014-01-18 20:58 - 2014-01-18 20:58 - 00016996 _____ () C:\Users\Peter\Downloads\[CzT]Souboj_Titanu_Clash_of_the_Titans_2010_.torrent
2014-01-18 17:33 - 2014-01-18 17:23 - 00000000 ____D () C:\Users\Peter\Downloads\Plán útěku
2014-01-18 17:23 - 2014-01-18 17:23 - 00015288 _____ () C:\Users\Peter\Downloads\[CzT]Plan_uteku_Escape_Plan_2013_.torrent
2014-01-17 11:02 - 2014-01-17 10:37 - 226488722 _____ () C:\Users\Peter\Downloads\Supernatural-S09E10---Road-Trip.rar
2014-01-17 10:42 - 2014-01-17 10:36 - 364510674 _____ () C:\Users\Peter\Downloads\Supernatural.S09E10.HDTV.XviD-FUM.avi
2014-01-17 10:35 - 2014-01-17 10:35 - 00014478 _____ () C:\Users\Peter\Downloads\[CzT]Lovci_duchu_Supernatural_S09E10_Road_Trip_TvRip_.torrent
2014-01-17 10:33 - 2014-01-17 10:33 - 00016352 _____ () C:\Users\Peter\Downloads\Supernatural_S09E10.rar
Some content of TEMP:
====================
C:\Users\Peter\AppData\Local\Temp\RTBK.EXE
C:\Users\WOW US\AppData\Local\Temp\RTBK.EXE
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 17:43
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:95.7 GB) (Free:19.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DISK D HRY) (Fixed) (Total:94.21 GB) (Free:24.83 GB) NTFS
Available physical RAM: 1638.51 MB
Total physical RAM: 2559.55 MB
Percentage of memory in use: 35%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 190 GB) (Disk ID: 3B963B95)
Partition 1: (Active) - (Size=96 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=94 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001Core.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001UA.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001Core.job => C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2313411190-107904724-3513802042-1001UA.job => C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegAce Scheduled Scan - Peter.job => C:\Program Files\RegAce System Suite\RegAce.exe
Task: C:\Windows\Tasks\RegInOut Scheduled Scan - Peter.job => C:\Program Files\RegInOut\RegInOut.exe
Task: C:\Windows\Tasks\SK.Enabler-S-1495795506.job => c:\programdata\quickset\sk.enabler\SK.Enabler.exe <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:A1EDB939
AlternateDataStreams: C:\ProgramData\TEMP:DBC416F8
AlternateDataStreams: C:\ProgramData\TEMP:FB1B13D8
==================== Security Center ==================
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Peter\Desktop" je 9568 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher
"C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager
"C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5
"C:\Users\Peter\AppData\Local\Akamai\netsession_win.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface
C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autodesk Sync
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter
"C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx
C:\Users\Peter\AppData\Roaming\ICQM\icq.exe -CU [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cm108Sound
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
C:\Program Files\MSI\Live Update 5\BootStartLiveupdate.exe /reminder [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Program Files\LOLReplay\LOLRecorder.exe" -minimize [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScannerSelectorEX
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload
C:\Program Files\Pando Networks\Media Booster\PMB.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent
"C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Live Update 5
C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LOLReplay Recorder
C:\Program Files\Razer\Core\razercore.exe /ChatApplet [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
"C:\Program Files\Razer\Synapse\RzSynapse.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nvtmru
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Converter Elite Print Dispatcher
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrivitizeVPN
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Razer Comms
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Razer Synapse
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^hpoddt01.exe.lnk
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
C:\PROGRA~1\MCAFEE~1\386EB9~1.130\SSSCHE~1.EXE [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Peter^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip
C:\PROGRA~1\MYPCBA~1\MYPCBA~1.EXE [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================