awardhotspot
Napsal: 18 úno 2014 19:36
Zdravíčko . . poslední přibližně dva dny mě v prohlížeči trápi awardhotspot reklamy, které se objevují jak ve Firefoxu tak v Exploreru, snažil jsem se najít nějaký návod na odstranění, ale nic co jsem našel nepomohlo.
přikládám log z FRST pro kontrolu
Dekuji
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-02-2014
Ran by Honza (administrator) on HONZA-PC on 18-02-2014 19:29:37
Running from C:\Users\Honza\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Users\Honza\AppData\Local\PirritSuggestor\PirritService.exe
() C:\Program Files (x86)\Pirrit\AutoUpdater.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(ICQ, LLC.) C:\Program Files (x86)\ICQ7M\ICQ.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Users\Honza\AppData\Local\PirritSuggestor\PirritDesktop.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [ICQ] - C:\Program Files (x86)\ICQ7M\ICQ.exe [127040 2012-05-16] (ICQ, LLC.)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {425624a9-a025-11e1-a6bb-5404a6b4f80b} - E:\setup.exe
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {92b9828d-6ed4-11e3-afb1-5404a6b4f80b} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {a8f2bea9-7524-11e3-a10a-5404a6b4f80b} - E:\HTC_Sync_Manager_PC.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=http://127.0.0.1:9880
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\2v354g31.default-1391862899672
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-05-15]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-05-15]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (No Name) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc [2013-12-28]
CHR Extension: (Google Drive) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-09]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-09]
CHR Extension: (Google Search) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-09]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-09]
==================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [974944 2011-09-22] (ESET)
U2 PirritDesktop; C:\Users\Honza\AppData\Local\PirritSuggestor\PirritService.exe [52568 2014-02-17] ()
R2 PirritUpdater; C:\Program Files (x86)\Pirrit\AutoUpdater.exe [59904 2014-02-17] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-05] ()
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-18] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [202576 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [146432 2011-08-04] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [187632 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [38288 2011-08-04] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62496 2011-08-04] (ESET)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-18 19:29 - 2014-02-18 19:30 - 00009403 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-02-18 19:29 - 2014-02-18 19:29 - 00000000 ____D () C:\FRST
2014-02-18 19:28 - 2014-02-18 19:28 - 02152448 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-02-18 19:07 - 2014-02-18 19:07 - 00001032 _____ () C:\Windows\PFRO.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000056 _____ () C:\Windows\setupact.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-18 18:12 - 2014-02-18 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-18 16:36 - 2014-02-18 16:36 - 00000000 ____D () C:\Users\Honza\AppData\Local\Origin
2014-02-14 16:37 - 2014-02-18 18:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\PirritSuggestor
2014-02-03 15:20 - 2014-02-03 15:20 - 00001249 _____ () C:\Users\Public\Desktop\Assassins Creed IV Black Flag.lnk
2014-02-03 15:10 - 2014-02-03 15:24 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed IV Black Flag
==================== One Month Modified Files and Folders =======
2015-02-18 17:51 - 2012-05-16 16:59 - 00000000 ____D () C:\Users\Honza
2015-02-18 17:49 - 2013-12-08 12:20 - 00000000 ____D () C:\Users\Honza\Documents\Assassin's Creed IV Black Flag
2015-02-18 17:49 - 2013-09-26 18:51 - 00000000 ____D () C:\Users\Honza\Documents\FIFA 14
2015-02-18 17:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-02-18 17:48 - 2013-12-28 15:54 - 00000000 ____D () C:\Program Files (x86)\Pirrit
2015-02-18 17:48 - 2013-11-18 15:54 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-02-18 17:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-02-18 17:46 - 2012-05-16 17:21 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Winamp
2015-02-18 17:45 - 2012-05-16 19:26 - 00000000 ____D () C:\ProgramData\Battle.net
2014-02-18 19:30 - 2014-02-18 19:29 - 00009403 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-02-18 19:29 - 2014-02-18 19:29 - 00000000 ____D () C:\FRST
2014-02-18 19:28 - 2014-02-18 19:28 - 02152448 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-02-18 19:16 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:16 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:14 - 2012-05-15 13:09 - 01300117 _____ () C:\Windows\WindowsUpdate.log
2014-02-18 19:09 - 2013-07-22 13:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-18 19:07 - 2014-02-18 19:07 - 00001032 _____ () C:\Windows\PFRO.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000056 _____ () C:\Windows\setupact.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-18 19:07 - 2012-05-16 17:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-18 19:07 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-18 18:50 - 2012-05-16 17:41 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-18 18:46 - 2012-06-08 16:27 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-02-18 18:46 - 2012-05-18 14:35 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Media Player Classic
2014-02-18 18:29 - 2014-02-14 16:37 - 00000000 ____D () C:\Users\Honza\AppData\Local\PirritSuggestor
2014-02-18 18:28 - 2013-12-28 15:23 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5
2014-02-18 18:12 - 2014-02-18 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-18 17:59 - 2013-09-26 14:43 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-02-18 17:59 - 2012-11-07 18:47 - 00000000 ____D () C:\ProgramData\Origin
2014-02-18 16:36 - 2014-02-18 16:36 - 00000000 ____D () C:\Users\Honza\AppData\Local\Origin
2014-02-16 19:08 - 2013-09-26 14:43 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-09 18:23 - 2012-07-05 19:10 - 00000000 ____D () C:\Users\Honza\Desktop\Movies
2014-02-08 13:35 - 2012-05-20 22:37 - 00000000 ___RD () C:\Users\Honza\Desktop\Foto
2014-02-05 16:50 - 2013-12-11 17:50 - 05556104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-02-05 16:50 - 2012-05-16 17:41 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-05 16:50 - 2012-05-16 17:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-05 16:50 - 2012-05-16 17:41 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-05 16:35 - 2013-06-15 14:06 - 00038698 _____ () C:\Users\Honza\Desktop\Narozky.odt
2014-02-03 21:02 - 2011-04-12 09:34 - 00631276 _____ () C:\Windows\system32\perfh005.dat
2014-02-03 21:02 - 2011-04-12 09:34 - 00121930 _____ () C:\Windows\system32\perfc005.dat
2014-02-03 21:02 - 2009-07-14 06:13 - 01470298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-03 15:24 - 2014-02-03 15:10 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed IV Black Flag
2014-02-03 15:21 - 2013-12-25 12:04 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-03 15:21 - 2012-12-27 18:29 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-02-03 15:20 - 2014-02-03 15:20 - 00001249 _____ () C:\Users\Public\Desktop\Assassins Creed IV Black Flag.lnk
2014-02-03 15:20 - 2012-12-27 18:29 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-02-03 15:05 - 2012-05-18 15:10 - 00000000 ____D () C:\Games
2014-02-03 15:00 - 2013-12-08 11:32 - 00000000 ____D () C:\Users\Honza\Desktop\Assassin's Creed IV Black Flag
2014-01-23 19:56 - 2012-05-18 14:36 - 00000000 ___RD () C:\Users\Honza\Desktop\Anime
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 15:07
==================== End Of Log ============================
přikládám log z FRST pro kontrolu
Dekuji
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-02-2014
Ran by Honza (administrator) on HONZA-PC on 18-02-2014 19:29:37
Running from C:\Users\Honza\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Users\Honza\AppData\Local\PirritSuggestor\PirritService.exe
() C:\Program Files (x86)\Pirrit\AutoUpdater.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(ICQ, LLC.) C:\Program Files (x86)\ICQ7M\ICQ.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Users\Honza\AppData\Local\PirritSuggestor\PirritDesktop.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [ICQ] - C:\Program Files (x86)\ICQ7M\ICQ.exe [127040 2012-05-16] (ICQ, LLC.)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation)
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {425624a9-a025-11e1-a6bb-5404a6b4f80b} - E:\setup.exe
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {92b9828d-6ed4-11e3-afb1-5404a6b4f80b} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1025233422-2582190980-4078685208-1000\...\MountPoints2: {a8f2bea9-7524-11e3-a10a-5404a6b4f80b} - E:\HTC_Sync_Manager_PC.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=http://127.0.0.1:9880
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\2v354g31.default-1391862899672
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-05-15]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-05-15]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (No Name) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc [2013-12-28]
CHR Extension: (Google Drive) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-09]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-09]
CHR Extension: (Google Search) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-09]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-09]
==================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [974944 2011-09-22] (ESET)
U2 PirritDesktop; C:\Users\Honza\AppData\Local\PirritSuggestor\PirritService.exe [52568 2014-02-17] ()
R2 PirritUpdater; C:\Program Files (x86)\Pirrit\AutoUpdater.exe [59904 2014-02-17] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-05] ()
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-18] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [202576 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [146432 2011-08-04] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [187632 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [38288 2011-08-04] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62496 2011-08-04] (ESET)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-18 19:29 - 2014-02-18 19:30 - 00009403 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-02-18 19:29 - 2014-02-18 19:29 - 00000000 ____D () C:\FRST
2014-02-18 19:28 - 2014-02-18 19:28 - 02152448 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-02-18 19:07 - 2014-02-18 19:07 - 00001032 _____ () C:\Windows\PFRO.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000056 _____ () C:\Windows\setupact.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-18 18:12 - 2014-02-18 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-18 16:36 - 2014-02-18 16:36 - 00000000 ____D () C:\Users\Honza\AppData\Local\Origin
2014-02-14 16:37 - 2014-02-18 18:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\PirritSuggestor
2014-02-03 15:20 - 2014-02-03 15:20 - 00001249 _____ () C:\Users\Public\Desktop\Assassins Creed IV Black Flag.lnk
2014-02-03 15:10 - 2014-02-03 15:24 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed IV Black Flag
==================== One Month Modified Files and Folders =======
2015-02-18 17:51 - 2012-05-16 16:59 - 00000000 ____D () C:\Users\Honza
2015-02-18 17:49 - 2013-12-08 12:20 - 00000000 ____D () C:\Users\Honza\Documents\Assassin's Creed IV Black Flag
2015-02-18 17:49 - 2013-09-26 18:51 - 00000000 ____D () C:\Users\Honza\Documents\FIFA 14
2015-02-18 17:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-02-18 17:48 - 2013-12-28 15:54 - 00000000 ____D () C:\Program Files (x86)\Pirrit
2015-02-18 17:48 - 2013-11-18 15:54 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-02-18 17:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-02-18 17:46 - 2012-05-16 17:21 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Winamp
2015-02-18 17:45 - 2012-05-16 19:26 - 00000000 ____D () C:\ProgramData\Battle.net
2014-02-18 19:30 - 2014-02-18 19:29 - 00009403 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-02-18 19:29 - 2014-02-18 19:29 - 00000000 ____D () C:\FRST
2014-02-18 19:28 - 2014-02-18 19:28 - 02152448 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-02-18 19:16 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:16 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:14 - 2012-05-15 13:09 - 01300117 _____ () C:\Windows\WindowsUpdate.log
2014-02-18 19:09 - 2013-07-22 13:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-18 19:07 - 2014-02-18 19:07 - 00001032 _____ () C:\Windows\PFRO.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000056 _____ () C:\Windows\setupact.log
2014-02-18 19:07 - 2014-02-18 19:07 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-18 19:07 - 2012-05-16 17:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-18 19:07 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-18 18:50 - 2012-05-16 17:41 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-18 18:46 - 2012-06-08 16:27 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-02-18 18:46 - 2012-05-18 14:35 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Media Player Classic
2014-02-18 18:29 - 2014-02-14 16:37 - 00000000 ____D () C:\Users\Honza\AppData\Local\PirritSuggestor
2014-02-18 18:28 - 2013-12-28 15:23 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5
2014-02-18 18:12 - 2014-02-18 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-18 17:59 - 2013-09-26 14:43 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-02-18 17:59 - 2012-11-07 18:47 - 00000000 ____D () C:\ProgramData\Origin
2014-02-18 16:36 - 2014-02-18 16:36 - 00000000 ____D () C:\Users\Honza\AppData\Local\Origin
2014-02-16 19:08 - 2013-09-26 14:43 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-09 18:23 - 2012-07-05 19:10 - 00000000 ____D () C:\Users\Honza\Desktop\Movies
2014-02-08 13:35 - 2012-05-20 22:37 - 00000000 ___RD () C:\Users\Honza\Desktop\Foto
2014-02-05 16:50 - 2013-12-11 17:50 - 05556104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-02-05 16:50 - 2012-05-16 17:41 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-05 16:50 - 2012-05-16 17:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-05 16:50 - 2012-05-16 17:41 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-05 16:35 - 2013-06-15 14:06 - 00038698 _____ () C:\Users\Honza\Desktop\Narozky.odt
2014-02-03 21:02 - 2011-04-12 09:34 - 00631276 _____ () C:\Windows\system32\perfh005.dat
2014-02-03 21:02 - 2011-04-12 09:34 - 00121930 _____ () C:\Windows\system32\perfc005.dat
2014-02-03 21:02 - 2009-07-14 06:13 - 01470298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-03 15:24 - 2014-02-03 15:10 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed IV Black Flag
2014-02-03 15:21 - 2013-12-25 12:04 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-03 15:21 - 2012-12-27 18:29 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-02-03 15:20 - 2014-02-03 15:20 - 00001249 _____ () C:\Users\Public\Desktop\Assassins Creed IV Black Flag.lnk
2014-02-03 15:20 - 2012-12-27 18:29 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-02-03 15:05 - 2012-05-18 15:10 - 00000000 ____D () C:\Games
2014-02-03 15:00 - 2013-12-08 11:32 - 00000000 ____D () C:\Users\Honza\Desktop\Assassin's Creed IV Black Flag
2014-01-23 19:56 - 2012-05-18 14:36 - 00000000 ___RD () C:\Users\Honza\Desktop\Anime
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 15:07
==================== End Of Log ============================