Prosím o kontrolu pomalého PC
Napsal: 08 bře 2014 16:50
Moc děkuji:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2014 01
Ran by Zdeněk (administrator) on ZDPOK on 08-03-2014 16:45:55
Running from C:\Users\Zdeněk\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\windows\SYSTEM32\WISPTIS.EXE
() C:\Windows\System32\AsusService.exe
() C:\Program Files\asus\AsusUac\AsusUacSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
() C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\windows\system32\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrUI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
() C:\Program Files\ASUS\Eee Docking Touch\Eee Docking Touch.exe
(ASUS) C:\Windows\AsScrPro.exe
(AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(GBM Software) C:\Program Files\GBM\GRemote Pro\GRemoteServer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Barracuda Networks, Inc.) C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Users\Zdeněk\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(LS) C:\Program Files\MultiClipBoard\MultiClipBoard.exe
() C:\Program Files\My Sync Center\bin\sync_server.exe
(Dropbox, Inc.) C:\Users\Zdeněk\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\GmoteServer\GmoteServer.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\javaw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [HotkeyMon] - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [100328 2009-09-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [HotkeyService] - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1166256 2010-03-04] (ASUSTeK Computer Inc.)
HKLM\...\Run: [SuperHybridEngine] - C:\Program Files\EeePC\SHE\SuperHybridEngine.exe [413688 2009-10-26] (ASUSTeK Computer Inc.)
HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1024368 2010-02-23] (Trend Micro Inc.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM\...\Run: [LiveUpdate] - C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-07-13] (AsusTek Computer Inc.)
HKLM\...\Run: [SynAsusAcpi] - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [83240 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [Eee Docking Touch] - C:\Program Files\ASUS\Eee Docking Touch\Eee Docking Touch.exe [414896 2010-02-09] ()
HKLM\...\Run: [Tutorial] - C:\Program Files\ASUS\Demo Tutorial Video\Demo Tutorial Video.exe [241328 2009-12-10] (ASUSTek Computer Inc.)
HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3058304 2010-03-07] (ASUS)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7744032 2009-09-29] (Realtek Semiconductor)
HKLM\...\Run: [PenWrite] - C:\Program Files\ASUS\PenWrite\PenWrite.exe [543920 2010-02-08] ()
HKLM\...\Run: [ASUSPRP] - C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2010-03-07] (ASUSTek Computer Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM\...\Run: [VirtualCloneDrive] - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~2.EXE
HKU\.DEFAULT\...\Run: [Copy] - C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe [13473936 2014-02-07] (Barracuda Networks, Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [GRemoteServer Pro] - C:\Program Files\GBM\GRemote Pro\GRemoteServer.exe [2310368 2010-05-04] (GBM Software)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [ShowBatteryBar] - C:\Program Files\BatteryBar\ShowBatteryBar.exe [90624 2009-05-28] ()
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [GoogleDriveSync] - C:\Program Files\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [Copy] - C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe [13473936 2014-02-07] (Barracuda Networks, Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [Google Update] - C:\Users\Zdeněk\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-05] (Google Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [MusicManager] - C:\Users\Zdeněk\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7342592 2013-09-23] (Google Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {3dec8514-648a-11e1-ae36-20cf300a2ebe} - C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {415e84c0-edd3-11df-90a6-806e6f6e6963} - E:\start.exe ar
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {e90aad40-1bc4-11e1-91d7-1c4bd617b5af} - F:\LaunchU3.exe -a
AppInit_DLLs: C:\PROGRA~2\Wincert\WIN32C~1.DLL => C:\ProgramData\Wincert\win32cert.dll [7168 2013-04-09] ()
AppInit_DLLs: C:\PROGRA~1\MOVIES~1\Datamngr\mgrldr.dll => C:\Program Files\Movies Toolbar\Datamngr\mgrldr.dll [18432 2013-09-17] ()
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Zdeněk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GmoteServer.lnk
ShortcutTarget: GmoteServer.lnk -> C:\Program Files\GmoteServer\GmoteServer.exe ()
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll [485376 2013-09-17] () <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 01-111&t=4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com
URLSearchHook: HKLM - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
URLSearchHook: HKCU - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {1645A33F-0A96-4315-904E-29E188E7720E} URL = http://startsear.ch/?q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT1098640
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT1098640
SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/sli ... 0winampie7
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File
BHO: CIEDownload Object - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
Toolbar: HKLM - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - free-downloads.net Toolbar - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - C:\Program Files\Skyline\TerraExplorer\TerraExplorerX.dll (Skyline software systems Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 46.252.224.18 8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 01-111&t=4
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a9301-111&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=8729420243354329&o=APN10645&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files\Virtual Earth 3D\ ()
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=1.1.11 - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Zdeněk\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Zdeněk\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\abz-slovnik-ceskych-synonym.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\korpuscz.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\startsear.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Zotero - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\zotero@chnm.gmu.edu [2012-12-23]
FF Extension: Winamp Toolbar - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-10-16]
FF Extension: Ask New Tabs - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{2FD73609-F02D-3849-D765-5F8F93ECC348} [2014-03-08]
FF Extension: Search-Results Toolbar - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{377e5d4d-77e5-476a-8716-7e70a9272da0} [2013-04-07]
FF Extension: Sugestron Speed Dial - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\sugestron@example.net.xpi [2011-04-24]
FF Extension: Vlc Kontextmenü - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\vlcplaylist@helgatauscher.de.xpi [2012-01-19]
FF Extension: Yoono - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}.xpi [2011-04-30]
FF Extension: SMART Notebook Extension - C:\Program Files\Mozilla Firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262} [2014-02-27]
FF Extension: vShare Add-On - C:\Program Files\Mozilla Firefox\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01} [2014-02-27]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-10-21]
Chrome:
=======
CHR HomePage:
CHR Extension: (Disk Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-11]
CHR Extension: (YouTube) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-09]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-09-08]
CHR Extension: (Torch Share) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2013-09-01]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2012-09-08]
CHR Extension: (Peněženka Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR HKLM\...\Chrome\Extension: [edcbaedcbaedcbaedcbaedcbaedcbajk] - C:\Program Files\vShare.tv plugin\vshareplg.crx [2011-03-20]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2010-10-21]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Zdeněk\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-04-07]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\ZDENK~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-09-05]
========================== Services (Whitelisted) =================
R2 AsusService; C:\Windows\System32\AsusService.exe [224680 2010-03-04] ()
R2 AsusUacSvc; C:\Program Files\asus\AsusUac\AsusUacSvc.exe [114864 2009-11-16] ()
R2 DatamngrCoordinator; C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3418624 2013-09-17] (Bandoo Media Inc.)
R2 OberonGameConsoleService; C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [44312 2009-09-15] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [88576 2011-09-15] ()
R2 PnkBstrA; C:\windows\system32\PnkBstrA.exe [75064 2010-10-22] ()
R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [736040 2010-10-09] (Trend Micro Inc.)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [345352 2010-01-06] (Trend Micro Inc.)
S3 TmPfw; C:\Program Files\Trend Micro\Internet Security\TmPfw.exe [497008 2010-01-06] (Trend Micro Inc.)
S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [689416 2010-01-06] (Trend Micro Inc.)
==================== Drivers (Whitelisted) ====================
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2011-02-09] ()
R1 ElbyCDIO; C:\windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
R3 GRemoteBus; C:\windows\System32\DRIVERS\GRemoteBus.sys [23368 2009-08-05] (GBM Software)
R3 GRemoteJoy; C:\windows\System32\DRIVERS\GRemoteJoy.sys [39112 2009-08-05] (GBM Software)
S3 JL2005C; C:\windows\System32\Drivers\jl2005c.sys [69180 2011-01-17] (Windows (R) 2000 DDK provider)
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R0 nhcDriverDevice; C:\windows\System32\drivers\nhcDriver.sys [71680 2011-01-07] (Notebook Hardware Control)
S3 Rockusb; C:\windows\System32\DRIVERS\rockusb.sys [45040 2012-08-20] (Fuzhou Rockchip Electronics Co,Ltd.)
R3 SMARTMouseFilterx86; C:\windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2009-12-15] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2009-12-15] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\windows\System32\DRIVERS\SMARTVTabletPCx86.sys [13440 2009-12-15] (SMART Technologies ULC)
R0 sptd; C:\windows\System32\Drivers\sptd.sys [436792 2010-10-15] ()
S3 tmactmon; C:\windows\System32\DRIVERS\tmactmon.sys [59472 2010-07-19] (Trend Micro Inc.)
R2 tmcomm; C:\windows\System32\DRIVERS\tmcomm.sys [163408 2010-07-19] (Trend Micro Inc.)
S3 tmevtmgr; C:\windows\System32\DRIVERS\tmevtmgr.sys [51792 2010-07-19] (Trend Micro Inc.)
S3 tmlwf; C:\windows\System32\DRIVERS\tmlwf.sys [146448 2010-01-06] (Trend Micro Inc.)
R2 tmpreflt; C:\windows\System32\DRIVERS\tmpreflt.sys [36432 2010-07-30] (Trend Micro Inc.)
R1 tmtdi; C:\windows\System32\DRIVERS\tmtdi.sys [89872 2010-01-06] (Trend Micro Inc.)
S3 tmwfp; C:\windows\System32\DRIVERS\tmwfp.sys [283152 2010-01-06] (Trend Micro Inc.)
R2 tmxpflt; C:\windows\System32\DRIVERS\tmxpflt.sys [249424 2010-07-30] (Trend Micro Inc.)
R3 usbsmi; C:\windows\System32\DRIVERS\SMIksdrv.sys [181760 2009-12-25] (SMI)
R2 vsapint; C:\windows\System32\DRIVERS\vsapint.sys [1331512 2010-07-30] (Trend Micro Inc.)
S3 wdf_usb; C:\windows\System32\drivers\usb2ser.sys [56832 2011-05-18] (MediaTek Inc.)
U3 ary4kr4i; C:\windows\system32\Drivers\ary4kr4i.sys [0 ] (Elaborate Bytes AG)
S3 cpuz132; \??\C:\Users\ZDENK~1\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-08 16:45 - 2014-03-08 16:49 - 00028173 _____ () C:\Users\Zdeněk\Desktop\FRST.txt
2014-03-08 16:45 - 2014-03-08 16:45 - 00000000 ____D () C:\FRST
2014-03-08 16:43 - 2014-03-08 16:43 - 00112640 _____ (forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
2014-03-08 16:34 - 2014-03-08 16:34 - 1582512036 _____ () C:\Users\Zdeněk\Downloads\pinavý trik (American Hustle, 2013) CZ tit.avi
2014-03-08 14:19 - 2014-03-08 14:19 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Speclean
2014-03-08 14:16 - 2014-03-08 14:17 - 01145344 _____ (Farbar) C:\Users\Zdeněk\Desktop\FRST.exe
2014-03-08 13:59 - 2014-03-08 15:12 - 782848000 _____ () C:\Users\Zdeněk\Downloads\Lovelace - Pravdivá spoveď kráľovnej porna (Lovelace) (2013) CZ.avi
2014-03-08 13:43 - 2014-03-08 13:46 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (2).exe
2014-03-08 13:42 - 2014-03-08 13:45 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (1).exe
2014-03-08 13:40 - 2014-03-08 13:40 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-01 15:57 - 2014-03-01 18:28 - 1863655424 _____ () C:\Users\Zdeněk\Downloads\Rush - Rivalové(2013)CZ.avi
2014-02-27 22:20 - 2014-02-27 22:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-14 17:57 - 2013-12-21 08:56 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 01140736 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-02-14 16:20 - 2014-02-01 08:57 - 14359040 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-02-14 16:20 - 2014-02-01 08:34 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-02-14 16:20 - 2014-02-01 07:38 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2014-02-13 17:57 - 2014-01-01 00:05 - 00420008 _____ () C:\windows\system32\locale.nls
2014-02-13 17:57 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-02-13 17:57 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-02-13 17:56 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2014-02-13 17:56 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2014-02-13 17:52 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2014-02-13 17:52 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2014-02-08 08:45 - 2014-02-08 08:45 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Gravitace-2013-cz-dab.AVI
2014-02-06 17:30 - 2012-05-02 19:28 - 02933248 _____ () C:\Users\Zdeněk\Downloads\Kulturni_instituce.ppt
==================== One Month Modified Files and Folders =======
2014-03-08 16:49 - 2014-03-08 16:45 - 00028173 _____ () C:\Users\Zdeněk\Desktop\FRST.txt
2014-03-08 16:49 - 2013-09-20 13:41 - 00000000 ____D () C:\ProgramData\Datamngr
2014-03-08 16:47 - 2009-07-14 05:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-08 16:47 - 2009-07-14 05:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-08 16:46 - 2010-10-13 05:31 - 01217895 _____ () C:\windows\WindowsUpdate.log
2014-03-08 16:45 - 2014-03-08 16:45 - 00000000 ____D () C:\FRST
2014-03-08 16:43 - 2014-03-08 16:43 - 00112640 _____ (forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
2014-03-08 16:42 - 2011-09-25 12:45 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Dropbox
2014-03-08 16:41 - 2012-06-01 11:24 - 00000000 ___RD () C:\Users\Zdeněk\Google Drive
2014-03-08 16:41 - 2011-12-31 09:09 - 00064693 _____ () C:\Users\Zdeněk\.mysync.log
2014-03-08 16:41 - 2011-10-19 18:44 - 01406464 ___SH () C:\Users\Zdeněk\Downloads\Thumbs.db
2014-03-08 16:41 - 2011-09-25 12:50 - 00000000 ___RD () C:\Users\Zdeněk\Dropbox
2014-03-08 16:40 - 2013-08-04 07:29 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Copy
2014-03-08 16:38 - 2014-01-08 19:36 - 00006965 _____ () C:\windows\setupact.log
2014-03-08 16:38 - 2011-08-08 12:00 - 00000374 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-03-08 16:38 - 2010-10-21 12:43 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-08 16:38 - 2009-07-14 05:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-03-08 16:37 - 2014-01-08 19:36 - 00069704 _____ () C:\windows\PFRO.log
2014-03-08 16:37 - 2012-05-31 10:01 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-08 16:35 - 2012-07-10 19:04 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-03-08 16:34 - 2014-03-08 16:34 - 1582512036 _____ () C:\Users\Zdeněk\Downloads\pinavý trik (American Hustle, 2013) CZ tit.avi
2014-03-08 16:10 - 2010-10-21 12:43 - 00000940 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-08 15:58 - 2013-10-05 10:20 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001UA.job
2014-03-08 15:12 - 2014-03-08 13:59 - 782848000 _____ () C:\Users\Zdeněk\Downloads\Lovelace - Pravdivá spoveď kráľovnej porna (Lovelace) (2013) CZ.avi
2014-03-08 14:37 - 2013-10-05 10:20 - 00000914 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001Core.job
2014-03-08 14:19 - 2014-03-08 14:19 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Speclean
2014-03-08 14:17 - 2014-03-08 14:16 - 01145344 _____ (Farbar) C:\Users\Zdeněk\Desktop\FRST.exe
2014-03-08 13:46 - 2014-03-08 13:43 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (2).exe
2014-03-08 13:45 - 2014-03-08 13:42 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (1).exe
2014-03-08 13:42 - 2010-03-07 02:29 - 00000000 ____D () C:\ProgramData\Skype
2014-03-08 13:40 - 2014-03-08 13:40 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-08 13:40 - 2010-03-07 02:30 - 00000000 ___RD () C:\Program Files\Skype
2014-03-08 13:37 - 2014-01-04 20:15 - 00107978 _____ () C:\windows\IE11_main.log
2014-03-06 18:54 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\Microsoft.NET
2014-03-06 18:20 - 2010-03-07 02:01 - 01568800 _____ () C:\windows\system32\PerfStringBackup.INI
2014-03-04 17:40 - 2013-09-01 13:01 - 00002122 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-01 18:39 - 2012-01-19 18:44 - 00000000 ____D () C:\Users\Zdeněk\.smplayer
2014-03-01 18:28 - 2014-03-01 15:57 - 1863655424 _____ () C:\Users\Zdeněk\Downloads\Rush - Rivalové(2013)CZ.avi
2014-02-27 22:21 - 2014-02-27 22:20 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-22 18:45 - 2013-01-17 18:43 - 00002004 ____H () C:\Users\Zdeněk\Documents\Default.rdp
2014-02-22 16:38 - 2010-10-28 08:50 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\dvdcss
2014-02-21 15:35 - 2012-07-10 19:04 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-02-21 15:35 - 2011-06-29 16:28 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-16 14:45 - 2012-12-25 10:57 - 00092672 ___SH () C:\Users\Zdeněk\Thumbs.db
2014-02-14 18:35 - 2009-07-26 22:40 - 00000000 ____D () C:\windows\panther
2014-02-14 18:13 - 2010-03-07 02:13 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-14 17:33 - 2013-09-13 18:16 - 00000000 ____D () C:\windows\system32\MRT
2014-02-14 17:15 - 2010-10-25 16:42 - 85946576 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-02-14 16:56 - 2009-07-14 03:04 - 00000507 _____ () C:\windows\win.ini
2014-02-09 17:08 - 2010-10-12 14:06 - 00000000 ____D () C:\Users\Zdeněk\AppData\Local\Mozilla
2014-02-08 08:45 - 2014-02-08 08:45 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Gravitace-2013-cz-dab.AVI
2014-02-08 08:33 - 2010-10-14 17:11 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Winamp
Files to move or delete:
====================
C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll
C:\Users\Zdeněk\ChromeSetup.exe
Some content of TEMP:
====================
C:\Users\Zdeněk\AppData\Local\Temp\atl80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfc80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfc80u.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfcm80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfcm80u.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcm80.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcp80.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcr80.dll
C:\Users\Zdeněk\AppData\Local\Temp\TmDbg32.dll
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
FontResizer (HKLM\...\InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}) (Version: 1.01.0011 - ASUSTek)
FontResizer (Version: 1.01.0011 - ASUSTek) Hidden
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001Core.job => C:\Users\Zdenk\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001UA.job => C:\Users\Zdenk\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Trend Micro Internet Security (Disabled - Up to date) {68F968AC-2AA0-091D-848C-803E83E35902}
AS: Trend Micro Internet Security (Disabled - Up to date) {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Trend Micro Personal Firewall (Disabled) {70A91CD9-303D-A217-A80E-6DEE136EDB2B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Zden�k\Desktop" je 718 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
"C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LivCam
"C:\Program Files\ASUS\LivCam\LivCam.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess
"C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service
C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent
C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe -e [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
"C:\Program Files\Winamp\winampa.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center
%windir%\WindowsMobile\wmdc.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSync
"C:\Program Files\Windows Live\Mesh\WLSync.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board Tools.lnk
C:\PROGRA~1\SMARTT~1\SMARTP~1\SMARTB~2.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Zden�k^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^V��ezy obrazovky a spu�t�n� aplikace OneNote 2010.lnk
C:\PROGRA~1\MICROS~2\Office14\ONENOTEM.EXE /tsr [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe"="C:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe:*:Enabled:River Past Audio Converter"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2014 01
Ran by Zdeněk (administrator) on ZDPOK on 08-03-2014 16:45:55
Running from C:\Users\Zdeněk\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\windows\SYSTEM32\WISPTIS.EXE
() C:\Windows\System32\AsusService.exe
() C:\Program Files\asus\AsusUac\AsusUacSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
() C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\windows\system32\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Bandoo Media Inc.) C:\Program Files\Movies Toolbar\Datamngr\DatamngrUI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
() C:\Program Files\ASUS\Eee Docking Touch\Eee Docking Touch.exe
(ASUS) C:\Windows\AsScrPro.exe
(AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(GBM Software) C:\Program Files\GBM\GRemote Pro\GRemoteServer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Barracuda Networks, Inc.) C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Users\Zdeněk\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(LS) C:\Program Files\MultiClipBoard\MultiClipBoard.exe
() C:\Program Files\My Sync Center\bin\sync_server.exe
(Dropbox, Inc.) C:\Users\Zdeněk\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\GmoteServer\GmoteServer.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\javaw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [HotkeyMon] - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [100328 2009-09-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [HotkeyService] - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1166256 2010-03-04] (ASUSTeK Computer Inc.)
HKLM\...\Run: [SuperHybridEngine] - C:\Program Files\EeePC\SHE\SuperHybridEngine.exe [413688 2009-10-26] (ASUSTeK Computer Inc.)
HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1024368 2010-02-23] (Trend Micro Inc.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM\...\Run: [LiveUpdate] - C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-07-13] (AsusTek Computer Inc.)
HKLM\...\Run: [SynAsusAcpi] - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [83240 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [Eee Docking Touch] - C:\Program Files\ASUS\Eee Docking Touch\Eee Docking Touch.exe [414896 2010-02-09] ()
HKLM\...\Run: [Tutorial] - C:\Program Files\ASUS\Demo Tutorial Video\Demo Tutorial Video.exe [241328 2009-12-10] (ASUSTek Computer Inc.)
HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3058304 2010-03-07] (ASUS)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7744032 2009-09-29] (Realtek Semiconductor)
HKLM\...\Run: [PenWrite] - C:\Program Files\ASUS\PenWrite\PenWrite.exe [543920 2010-02-08] ()
HKLM\...\Run: [ASUSPRP] - C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2010-03-07] (ASUSTek Computer Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM\...\Run: [VirtualCloneDrive] - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~2.EXE
HKU\.DEFAULT\...\Run: [Copy] - C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe [13473936 2014-02-07] (Barracuda Networks, Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [GRemoteServer Pro] - C:\Program Files\GBM\GRemote Pro\GRemoteServer.exe [2310368 2010-05-04] (GBM Software)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [ShowBatteryBar] - C:\Program Files\BatteryBar\ShowBatteryBar.exe [90624 2009-05-28] ()
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [GoogleDriveSync] - C:\Program Files\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [Copy] - C:\Users\Zdeněk\AppData\Roaming\Copy\CopyAgent.exe [13473936 2014-02-07] (Barracuda Networks, Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [Google Update] - C:\Users\Zdeněk\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-05] (Google Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\Run: [MusicManager] - C:\Users\Zdeněk\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7342592 2013-09-23] (Google Inc.)
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {3dec8514-648a-11e1-ae36-20cf300a2ebe} - C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {415e84c0-edd3-11df-90a6-806e6f6e6963} - E:\start.exe ar
HKU\S-1-5-21-3287936036-1640913841-3883395169-1001\...\MountPoints2: {e90aad40-1bc4-11e1-91d7-1c4bd617b5af} - F:\LaunchU3.exe -a
AppInit_DLLs: C:\PROGRA~2\Wincert\WIN32C~1.DLL => C:\ProgramData\Wincert\win32cert.dll [7168 2013-04-09] ()
AppInit_DLLs: C:\PROGRA~1\MOVIES~1\Datamngr\mgrldr.dll => C:\Program Files\Movies Toolbar\Datamngr\mgrldr.dll [18432 2013-09-17] ()
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Zdeněk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GmoteServer.lnk
ShortcutTarget: GmoteServer.lnk -> C:\Program Files\GmoteServer\GmoteServer.exe ()
Startup: C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll [485376 2013-09-17] () <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 01-111&t=4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com
URLSearchHook: HKLM - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
URLSearchHook: HKCU - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {1645A33F-0A96-4315-904E-29E188E7720E} URL = http://startsear.ch/?q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT1098640
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT1098640
SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/sli ... 0winampie7
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File
BHO: CIEDownload Object - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
Toolbar: HKLM - free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - free-downloads.net Toolbar - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - C:\Program Files\Skyline\TerraExplorer\TerraExplorerX.dll (Skyline software systems Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 46.252.224.18 8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 01-111&t=4
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a9301-111&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=8729420243354329&o=APN10645&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files\Virtual Earth 3D\ ()
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=1.1.11 - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Zdeněk\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Zdeněk\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\abz-slovnik-ceskych-synonym.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\korpuscz.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\searchplugins\startsear.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Zotero - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\zotero@chnm.gmu.edu [2012-12-23]
FF Extension: Winamp Toolbar - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-10-16]
FF Extension: Ask New Tabs - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{2FD73609-F02D-3849-D765-5F8F93ECC348} [2014-03-08]
FF Extension: Search-Results Toolbar - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{377e5d4d-77e5-476a-8716-7e70a9272da0} [2013-04-07]
FF Extension: Sugestron Speed Dial - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\sugestron@example.net.xpi [2011-04-24]
FF Extension: Vlc Kontextmenü - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\vlcplaylist@helgatauscher.de.xpi [2012-01-19]
FF Extension: Yoono - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\axn0sq43.default\Extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}.xpi [2011-04-30]
FF Extension: SMART Notebook Extension - C:\Program Files\Mozilla Firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262} [2014-02-27]
FF Extension: vShare Add-On - C:\Program Files\Mozilla Firefox\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01} [2014-02-27]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-10-21]
Chrome:
=======
CHR HomePage:
CHR Extension: (Disk Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-11]
CHR Extension: (YouTube) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-09]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-09-08]
CHR Extension: (Torch Share) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2013-09-01]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2012-09-08]
CHR Extension: (Peněženka Google) - C:\Users\Zdeněk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR HKLM\...\Chrome\Extension: [edcbaedcbaedcbaedcbaedcbaedcbajk] - C:\Program Files\vShare.tv plugin\vshareplg.crx [2011-03-20]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2010-10-21]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Zdeněk\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-04-07]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\ZDENK~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-09-05]
========================== Services (Whitelisted) =================
R2 AsusService; C:\Windows\System32\AsusService.exe [224680 2010-03-04] ()
R2 AsusUacSvc; C:\Program Files\asus\AsusUac\AsusUacSvc.exe [114864 2009-11-16] ()
R2 DatamngrCoordinator; C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3418624 2013-09-17] (Bandoo Media Inc.)
R2 OberonGameConsoleService; C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [44312 2009-09-15] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [88576 2011-09-15] ()
R2 PnkBstrA; C:\windows\system32\PnkBstrA.exe [75064 2010-10-22] ()
R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [736040 2010-10-09] (Trend Micro Inc.)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [345352 2010-01-06] (Trend Micro Inc.)
S3 TmPfw; C:\Program Files\Trend Micro\Internet Security\TmPfw.exe [497008 2010-01-06] (Trend Micro Inc.)
S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [689416 2010-01-06] (Trend Micro Inc.)
==================== Drivers (Whitelisted) ====================
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2011-02-09] ()
R1 ElbyCDIO; C:\windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
R3 GRemoteBus; C:\windows\System32\DRIVERS\GRemoteBus.sys [23368 2009-08-05] (GBM Software)
R3 GRemoteJoy; C:\windows\System32\DRIVERS\GRemoteJoy.sys [39112 2009-08-05] (GBM Software)
S3 JL2005C; C:\windows\System32\Drivers\jl2005c.sys [69180 2011-01-17] (Windows (R) 2000 DDK provider)
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R0 nhcDriverDevice; C:\windows\System32\drivers\nhcDriver.sys [71680 2011-01-07] (Notebook Hardware Control)
S3 Rockusb; C:\windows\System32\DRIVERS\rockusb.sys [45040 2012-08-20] (Fuzhou Rockchip Electronics Co,Ltd.)
R3 SMARTMouseFilterx86; C:\windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2009-12-15] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2009-12-15] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\windows\System32\DRIVERS\SMARTVTabletPCx86.sys [13440 2009-12-15] (SMART Technologies ULC)
R0 sptd; C:\windows\System32\Drivers\sptd.sys [436792 2010-10-15] ()
S3 tmactmon; C:\windows\System32\DRIVERS\tmactmon.sys [59472 2010-07-19] (Trend Micro Inc.)
R2 tmcomm; C:\windows\System32\DRIVERS\tmcomm.sys [163408 2010-07-19] (Trend Micro Inc.)
S3 tmevtmgr; C:\windows\System32\DRIVERS\tmevtmgr.sys [51792 2010-07-19] (Trend Micro Inc.)
S3 tmlwf; C:\windows\System32\DRIVERS\tmlwf.sys [146448 2010-01-06] (Trend Micro Inc.)
R2 tmpreflt; C:\windows\System32\DRIVERS\tmpreflt.sys [36432 2010-07-30] (Trend Micro Inc.)
R1 tmtdi; C:\windows\System32\DRIVERS\tmtdi.sys [89872 2010-01-06] (Trend Micro Inc.)
S3 tmwfp; C:\windows\System32\DRIVERS\tmwfp.sys [283152 2010-01-06] (Trend Micro Inc.)
R2 tmxpflt; C:\windows\System32\DRIVERS\tmxpflt.sys [249424 2010-07-30] (Trend Micro Inc.)
R3 usbsmi; C:\windows\System32\DRIVERS\SMIksdrv.sys [181760 2009-12-25] (SMI)
R2 vsapint; C:\windows\System32\DRIVERS\vsapint.sys [1331512 2010-07-30] (Trend Micro Inc.)
S3 wdf_usb; C:\windows\System32\drivers\usb2ser.sys [56832 2011-05-18] (MediaTek Inc.)
U3 ary4kr4i; C:\windows\system32\Drivers\ary4kr4i.sys [0 ] (Elaborate Bytes AG)
S3 cpuz132; \??\C:\Users\ZDENK~1\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-08 16:45 - 2014-03-08 16:49 - 00028173 _____ () C:\Users\Zdeněk\Desktop\FRST.txt
2014-03-08 16:45 - 2014-03-08 16:45 - 00000000 ____D () C:\FRST
2014-03-08 16:43 - 2014-03-08 16:43 - 00112640 _____ (forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
2014-03-08 16:34 - 2014-03-08 16:34 - 1582512036 _____ () C:\Users\Zdeněk\Downloads\pinavý trik (American Hustle, 2013) CZ tit.avi
2014-03-08 14:19 - 2014-03-08 14:19 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Speclean
2014-03-08 14:16 - 2014-03-08 14:17 - 01145344 _____ (Farbar) C:\Users\Zdeněk\Desktop\FRST.exe
2014-03-08 13:59 - 2014-03-08 15:12 - 782848000 _____ () C:\Users\Zdeněk\Downloads\Lovelace - Pravdivá spoveď kráľovnej porna (Lovelace) (2013) CZ.avi
2014-03-08 13:43 - 2014-03-08 13:46 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (2).exe
2014-03-08 13:42 - 2014-03-08 13:45 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (1).exe
2014-03-08 13:40 - 2014-03-08 13:40 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-01 15:57 - 2014-03-01 18:28 - 1863655424 _____ () C:\Users\Zdeněk\Downloads\Rush - Rivalové(2013)CZ.avi
2014-02-27 22:20 - 2014-02-27 22:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-14 17:57 - 2013-12-21 08:56 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 01140736 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-02-14 16:20 - 2014-02-01 08:58 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-02-14 16:20 - 2014-02-01 08:57 - 14359040 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-02-14 16:20 - 2014-02-01 08:57 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-02-14 16:20 - 2014-02-01 08:34 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-02-14 16:20 - 2014-02-01 07:38 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2014-02-13 17:57 - 2014-01-01 00:05 - 00420008 _____ () C:\windows\system32\locale.nls
2014-02-13 17:57 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-02-13 17:57 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-02-13 17:56 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2014-02-13 17:56 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2014-02-13 17:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2014-02-13 17:52 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2014-02-13 17:52 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2014-02-13 17:52 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2014-02-08 08:45 - 2014-02-08 08:45 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Gravitace-2013-cz-dab.AVI
2014-02-06 17:30 - 2012-05-02 19:28 - 02933248 _____ () C:\Users\Zdeněk\Downloads\Kulturni_instituce.ppt
==================== One Month Modified Files and Folders =======
2014-03-08 16:49 - 2014-03-08 16:45 - 00028173 _____ () C:\Users\Zdeněk\Desktop\FRST.txt
2014-03-08 16:49 - 2013-09-20 13:41 - 00000000 ____D () C:\ProgramData\Datamngr
2014-03-08 16:47 - 2009-07-14 05:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-08 16:47 - 2009-07-14 05:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-08 16:46 - 2010-10-13 05:31 - 01217895 _____ () C:\windows\WindowsUpdate.log
2014-03-08 16:45 - 2014-03-08 16:45 - 00000000 ____D () C:\FRST
2014-03-08 16:43 - 2014-03-08 16:43 - 00112640 _____ (forum.viry.cz) C:\Users\Zdeněk\Desktop\FRSTLauncher.exe
2014-03-08 16:42 - 2011-09-25 12:45 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Dropbox
2014-03-08 16:41 - 2012-06-01 11:24 - 00000000 ___RD () C:\Users\Zdeněk\Google Drive
2014-03-08 16:41 - 2011-12-31 09:09 - 00064693 _____ () C:\Users\Zdeněk\.mysync.log
2014-03-08 16:41 - 2011-10-19 18:44 - 01406464 ___SH () C:\Users\Zdeněk\Downloads\Thumbs.db
2014-03-08 16:41 - 2011-09-25 12:50 - 00000000 ___RD () C:\Users\Zdeněk\Dropbox
2014-03-08 16:40 - 2013-08-04 07:29 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Copy
2014-03-08 16:38 - 2014-01-08 19:36 - 00006965 _____ () C:\windows\setupact.log
2014-03-08 16:38 - 2011-08-08 12:00 - 00000374 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-03-08 16:38 - 2010-10-21 12:43 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-08 16:38 - 2009-07-14 05:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-03-08 16:37 - 2014-01-08 19:36 - 00069704 _____ () C:\windows\PFRO.log
2014-03-08 16:37 - 2012-05-31 10:01 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-08 16:35 - 2012-07-10 19:04 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-03-08 16:34 - 2014-03-08 16:34 - 1582512036 _____ () C:\Users\Zdeněk\Downloads\pinavý trik (American Hustle, 2013) CZ tit.avi
2014-03-08 16:10 - 2010-10-21 12:43 - 00000940 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-08 15:58 - 2013-10-05 10:20 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001UA.job
2014-03-08 15:12 - 2014-03-08 13:59 - 782848000 _____ () C:\Users\Zdeněk\Downloads\Lovelace - Pravdivá spoveď kráľovnej porna (Lovelace) (2013) CZ.avi
2014-03-08 14:37 - 2013-10-05 10:20 - 00000914 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001Core.job
2014-03-08 14:19 - 2014-03-08 14:19 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Speclean
2014-03-08 14:17 - 2014-03-08 14:16 - 01145344 _____ (Farbar) C:\Users\Zdeněk\Desktop\FRST.exe
2014-03-08 13:46 - 2014-03-08 13:43 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (2).exe
2014-03-08 13:45 - 2014-03-08 13:42 - 01581384 _____ (ESET) C:\Users\Zdeněk\Downloads\eset_smart_security_live_installer_ (1).exe
2014-03-08 13:42 - 2010-03-07 02:29 - 00000000 ____D () C:\ProgramData\Skype
2014-03-08 13:40 - 2014-03-08 13:40 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-08 13:40 - 2010-03-07 02:30 - 00000000 ___RD () C:\Program Files\Skype
2014-03-08 13:37 - 2014-01-04 20:15 - 00107978 _____ () C:\windows\IE11_main.log
2014-03-06 18:54 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\Microsoft.NET
2014-03-06 18:20 - 2010-03-07 02:01 - 01568800 _____ () C:\windows\system32\PerfStringBackup.INI
2014-03-04 17:40 - 2013-09-01 13:01 - 00002122 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-01 18:39 - 2012-01-19 18:44 - 00000000 ____D () C:\Users\Zdeněk\.smplayer
2014-03-01 18:28 - 2014-03-01 15:57 - 1863655424 _____ () C:\Users\Zdeněk\Downloads\Rush - Rivalové(2013)CZ.avi
2014-02-27 22:21 - 2014-02-27 22:20 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-22 18:45 - 2013-01-17 18:43 - 00002004 ____H () C:\Users\Zdeněk\Documents\Default.rdp
2014-02-22 16:38 - 2010-10-28 08:50 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\dvdcss
2014-02-21 15:35 - 2012-07-10 19:04 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-02-21 15:35 - 2011-06-29 16:28 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-16 14:45 - 2012-12-25 10:57 - 00092672 ___SH () C:\Users\Zdeněk\Thumbs.db
2014-02-14 18:35 - 2009-07-26 22:40 - 00000000 ____D () C:\windows\panther
2014-02-14 18:13 - 2010-03-07 02:13 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-14 17:33 - 2013-09-13 18:16 - 00000000 ____D () C:\windows\system32\MRT
2014-02-14 17:15 - 2010-10-25 16:42 - 85946576 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-02-14 16:56 - 2009-07-14 03:04 - 00000507 _____ () C:\windows\win.ini
2014-02-09 17:08 - 2010-10-12 14:06 - 00000000 ____D () C:\Users\Zdeněk\AppData\Local\Mozilla
2014-02-08 08:45 - 2014-02-08 08:45 - 00000000 ____D () C:\Users\Zdeněk\Downloads\Gravitace-2013-cz-dab.AVI
2014-02-08 08:33 - 2010-10-14 17:11 - 00000000 ____D () C:\Users\Zdeněk\AppData\Roaming\Winamp
Files to move or delete:
====================
C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll
C:\Users\Zdeněk\ChromeSetup.exe
Some content of TEMP:
====================
C:\Users\Zdeněk\AppData\Local\Temp\atl80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfc80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfc80u.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfcm80.dll
C:\Users\Zdeněk\AppData\Local\Temp\mfcm80u.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcm80.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcp80.dll
C:\Users\Zdeněk\AppData\Local\Temp\msvcr80.dll
C:\Users\Zdeněk\AppData\Local\Temp\TmDbg32.dll
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
FontResizer (HKLM\...\InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}) (Version: 1.01.0011 - ASUSTek)
FontResizer (Version: 1.01.0011 - ASUSTek) Hidden
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001Core.job => C:\Users\Zdenk\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3287936036-1640913841-3883395169-1001UA.job => C:\Users\Zdenk\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Trend Micro Internet Security (Disabled - Up to date) {68F968AC-2AA0-091D-848C-803E83E35902}
AS: Trend Micro Internet Security (Disabled - Up to date) {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Trend Micro Personal Firewall (Disabled) {70A91CD9-303D-A217-A80E-6DEE136EDB2B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Zden�k\Desktop" je 718 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
"C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LivCam
"C:\Program Files\ASUS\LivCam\LivCam.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess
"C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service
C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent
C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe -e [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
"C:\Program Files\Winamp\winampa.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center
%windir%\WindowsMobile\wmdc.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSync
"C:\Program Files\Windows Live\Mesh\WLSync.exe" /background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board Tools.lnk
C:\PROGRA~1\SMARTT~1\SMARTP~1\SMARTB~2.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Zden�k^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^V��ezy obrazovky a spu�t�n� aplikace OneNote 2010.lnk
C:\PROGRA~1\MICROS~2\Office14\ONENOTEM.EXE /tsr [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe"="C:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe:*:Enabled:River Past Audio Converter"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================