Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Owner (administrator) on ACER-6212E367EE on 14-03-2014 03:15:05
Running from C:\Documents and Settings\Owner\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 6
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(acer Inc.) C:\Acer\Empowering Technology\eRecovery\Monitor.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Documents and Settings\Owner\Plocha\FRSTLauncher.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
(Adobe Systems Incorporated) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
(Microsoft Corporation) C:\WINDOWS\system32\ping.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-08-22] (RealNetworks, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [14565376 2005-06-08] (Realtek Semiconductor Corp.)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.)
HKLM\...\Run: [PHIME2002ASync] - C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] - C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [ntiMUI] - c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [45056 2005-05-11] ()
HKLM\...\Run: [MSPY2002] - C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [59392 2004-08-18] ()
HKLM\...\Run: [LaunchApp] - Alaunch
HKLM\...\Run: [IMJPMIG8.1] - C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [High Definition Audio Property Page Shortcut] - C:\WINDOWS\system32\HDAShCut.exe [61952 2005-01-07] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [eRecoveryService] - C:\Acer\Empowering Technology\eRecovery\Monitor.exe [368640 2005-08-16] (acer Inc.)
HKLM\...\Run: [ADMTray.exe] - C:\Acer\Empowering Technology\admtray.exe [2460672 2005-08-18] (Avocent Inc.)
HKLM\...\Run: [AdminWorks Tray] - C:\Acer\Empowering Technology\awtray.exe [1304576 2005-08-18] (OSA Technologies, An Avocent Company)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-306829412-3668169067-3135776419-1003\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-22] (Google Inc.)
HKU\S-1-5-21-306829412-3668169067-3135776419-1003\...\Run: [Facebook Update] - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe [138096 2014-02-08] (Facebook Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
==================== Internet (Whitelisted) ====================
ProxyServer: :0
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={searchT ... {startPage}
BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\4f1qi6qf.default
FF DefaultSearchEngine: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL: hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=198484&ilc=12&p=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\4f1qi6qf.default\searchplugins\yahoo_ff.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Adblock Plus - C:\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\4f1qi6qf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-13]
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-22]
Chrome:
=======
CHR HomePage: hxxp://
www.google.com
CHR DefaultSearchProvider: SearchYa!
CHR DefaultSearchURL:
http://www.google.com
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.146\pdf.dll ()
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Adobe Acrobat) - c:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealDownloader Plugin) - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
CHR Extension: (YouTube) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-22]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-22]
CHR Extension: (AdBlock) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-08-22]
CHR Extension: (Value apps) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2013-12-25]
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd [2013-08-22]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-22]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx [2014-01-05]
========================== Services (Whitelisted) =================
S3 AppMgmt; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S4 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2007-10-16] ()
S4 AWService; C:\Acer\Empowering Technology\awServ.exe [86528 2005-08-18] (OSA Technologies Inc., An Avocent Company)
S4 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-01-11] (Oracle Corporation)
S4 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S4 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76888 2014-01-17] ()
S4 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [43008 2006-07-01] (Advanced Micro Devices)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider)
R2 int15.sys; C:\Acer\Empowering Technology\eRecovery\int15.sys [69632 2005-01-13] ()
R0 m5287; C:\WINDOWS\System32\drivers\m5287.sys [85888 2005-02-05] (ULi Electronics Inc.)
S3 NdisFilt; C:\WINDOWS\System32\Drivers\NdisFilt.sys [5035 2004-06-07] (OSA Technologies)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 NETMNT; C:\WINDOWS\System32\DRIVERS\NETMNT.sys [9600 2005-05-02] ()
R1 OsaFsLoc; C:\WINDOWS\system32\drivers\OsaFsLoc.sys [11978 2005-07-19] (OSA Technologies)
R2 osaio; C:\WINDOWS\system32\drivers\osaio.sys [7296 2005-06-30] (OSA Technologies, An Avocent Company)
R2 osanbm; C:\WINDOWS\system32\drivers\osanbm.sys [4010 2005-01-14] (Windows (R) 2000 DDK provider)
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2014-01-31] (Duplex Secure Ltd.)
R1 UBHelper; C:\WINDOWS\system32\Drivers\UBHelper.sys [13952 2004-12-17] ()
R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [234752 2005-06-27] (Marvell)
S3 cpuz130; No ImagePath
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-14 03:15 - 2014-03-14 03:15 - 00017852 _____ () C:\Documents and Settings\Owner\Plocha\FRST.txt
2014-03-14 03:13 - 2014-03-14 03:15 - 00000000 ____D () C:\FRST
2014-03-14 03:13 - 2014-03-14 03:13 - 00029696 _____ () C:\Documents and Settings\Owner\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-14 03:13 - 2014-03-14 03:13 - 00015327 _____ () C:\Documents and Settings\Owner\Plocha\LM.bat
2014-03-14 03:12 - 2014-03-14 03:12 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Owner\Plocha\FRSTLauncher.exe
2014-03-14 03:11 - 2014-03-14 03:11 - 01145856 _____ (Farbar) C:\Documents and Settings\Owner\Plocha\FRST.exe
2014-03-14 02:56 - 2014-03-14 02:49 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-03-14 02:50 - 2014-03-14 02:57 - 00007435 _____ () C:\zoek-results.log
2014-03-14 02:49 - 2014-03-14 02:54 - 00000000 ____D () C:\zoek_backup
2014-03-14 02:48 - 2014-03-14 02:48 - 01285120 _____ () C:\Documents and Settings\Owner\Plocha\zoek.exe
2014-03-14 02:45 - 2014-03-14 02:57 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-14 02:45 - 2014-03-14 02:57 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-03-14 02:45 - 2014-03-14 02:45 - 00000000 _____ () C:\WINDOWS\Sti_Trace.log
2014-03-14 02:44 - 2014-03-14 02:56 - 00005334 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-14 02:41 - 2014-03-14 02:43 - 00000000 ____D () C:\AdwCleaner
2014-03-14 02:41 - 2014-03-14 02:41 - 01950720 _____ () C:\Documents and Settings\Owner\Plocha\adwcleaner.exe
2014-03-14 02:35 - 2014-03-14 02:35 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-03-14 02:34 - 2014-03-14 02:34 - 01037734 _____ (Thisisu) C:\Documents and Settings\Owner\Plocha\JRT.exe
2014-03-14 02:33 - 2014-03-14 02:33 - 00000000 ____D () C:\WINDOWS\Tasks\ImCleanDisabled
2014-03-14 02:15 - 2014-03-14 02:15 - 00000000 ____D () C:\rsit
2014-03-14 02:15 - 2014-03-14 02:15 - 00000000 ____D () C:\Program Files\trend micro
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Program Files\Combined Community Codec Pack
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Combined Community Codec Pack
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Catalyst Control Center
2014-03-14 01:12 - 2014-03-14 01:12 - 00000000 ____D () C:\Program Files\ATI
2014-03-14 01:11 - 2014-03-14 01:11 - 00000000 ____D () C:\AMD
2014-03-13 03:15 - 2014-03-13 03:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-13 03:01 - 2014-03-14 03:12 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\Stažené soubory
2014-03-13 02:56 - 2014-03-13 02:56 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Data aplikací\Mozilla
2014-03-13 02:56 - 2014-03-13 02:56 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\Mozilla
2014-03-13 02:55 - 2014-03-14 01:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-13 02:55 - 2014-03-13 02:55 - 24501312 _____ (Mozilla) C:\Documents and Settings\Owner\Dokumenty\Firefox Setup 27.0.exe
2014-03-13 02:55 - 2014-03-13 02:55 - 00000734 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Mozilla Firefox.lnk
2014-03-13 02:55 - 2014-03-13 02:55 - 00000728 _____ () C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
2014-03-13 02:55 - 2014-03-13 02:55 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Mozilla
2014-03-13 02:41 - 2014-03-14 01:35 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\Media Player Classic
2014-03-13 02:35 - 2014-03-13 02:35 - 09357880 _____ (CCCP Project ) C:\Documents and Settings\Owner\Dokumenty\Combined-Community-Codec-Pack-2013-04-20.exe
2014-03-01 16:28 - 2014-03-01 16:28 - 00000874 _____ () C:\Documents and Settings\Owner\Plocha\San Andreas Multiplayer.lnk
2014-03-01 16:28 - 2014-03-01 16:28 - 00000000 ____D () C:\Documents and Settings\Owner\Nabídka Start\Programy\San Andreas Multiplayer
2014-03-01 16:27 - 2014-03-01 16:28 - 11990847 _____ () C:\Documents and Settings\Owner\Dokumenty\sa-mp-0.3z-R1-install.exe
2014-03-01 14:17 - 2014-03-05 23:19 - 00202752 _____ () C:\Documents and Settings\Owner\Plocha\GTASAsf1.b
2014-02-26 19:39 - 2014-02-26 19:39 - 01191753 _____ () C:\Documents and Settings\Owner\Dokumenty\gtasa120cz.zip
2014-02-26 19:38 - 2014-03-01 16:28 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\GTA San Andreas User Files
2014-02-26 19:37 - 2014-02-26 19:37 - 00098304 _____ (Sony DADC Austria AG.) C:\WINDOWS\system32\CmdLineExt.dll
2014-02-26 19:26 - 2014-02-26 19:26 - 00001591 _____ () C:\Documents and Settings\All Users\Plocha\GTA San Andreas.lnk
2014-02-25 22:14 - 2014-02-25 22:14 - 00000000 ____D () C:\Documents and Settings\Owner\WINDOWS
2014-02-25 22:14 - 1998-02-06 21:37 - 00299520 _____ (InstallShield Corporation, Inc.) C:\WINDOWS\uninst.exe
2014-02-24 19:21 - 2014-02-24 19:46 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\Max Payne 2 Savegames
2014-02-24 19:20 - 2014-02-24 19:20 - 01486848 _____ (Remedy Entertainment) C:\Documents and Settings\Owner\Dokumenty\Max-Payne-2-crack-(alik).exe
2014-02-24 19:16 - 2014-02-26 19:26 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Rockstar Games
2014-02-24 18:54 - 2014-02-24 18:55 - 38542610 _____ () C:\Documents and Settings\Owner\Dokumenty\MaxPayne2CZ_komplet.exe
2014-02-24 18:52 - 2014-02-24 18:52 - 00001757 _____ () C:\Documents and Settings\Owner\Plocha\Max Payne 2.lnk
2014-02-24 18:42 - 2014-02-26 19:26 - 00000000 ____D () C:\Program Files\Rockstar Games
2014-02-22 13:28 - 2014-02-23 18:55 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Data aplikací\Game Dev Tycoon
2014-02-22 13:25 - 2014-02-22 13:25 - 00000633 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Game Dev Tycoon v1.3.2.lnk
2014-02-22 13:25 - 2014-02-22 13:25 - 00000627 _____ () C:\Documents and Settings\All Users\Plocha\Game Dev Tycoon v1.3.2.lnk
2014-02-22 13:25 - 2014-02-22 13:25 - 00000000 ____D () C:\Program Files\Game Dev Tycoon v1.3.2
2014-02-22 13:25 - 2013-04-29 23:19 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\Game.Dev.Tycoon-ALiAS
2014-02-22 13:07 - 2014-02-22 13:20 - 115532320 _____ () C:\Documents and Settings\Owner\Dokumenty\Game.Dev.Tycoon-ALiAS.rar
2014-02-15 14:14 - 2014-02-15 14:20 - 00000000 ____D () C:\Documents and Settings\Owner\Plocha\Flashka
==================== One Month Modified Files and Folders =======
2014-03-14 03:15 - 2014-03-14 03:15 - 00017852 _____ () C:\Documents and Settings\Owner\Plocha\FRST.txt
2014-03-14 03:15 - 2014-03-14 03:13 - 00000000 ____D () C:\FRST
2014-03-14 03:15 - 2013-10-03 15:34 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-03-14 03:15 - 2005-09-08 10:20 - 00000000 ____D () C:\Documents and Settings\Owner\Plocha
2014-03-14 03:13 - 2014-03-14 03:13 - 00029696 _____ () C:\Documents and Settings\Owner\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-14 03:13 - 2014-03-14 03:13 - 00015327 _____ () C:\Documents and Settings\Owner\Plocha\LM.bat
2014-03-14 03:13 - 2005-09-08 10:20 - 00000000 ___HD () C:\Documents and Settings\Owner\Local Settings\Data aplikací
2014-03-14 03:12 - 2014-03-14 03:12 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Owner\Plocha\FRSTLauncher.exe
2014-03-14 03:12 - 2014-03-13 03:01 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\Stažené soubory
2014-03-14 03:11 - 2014-03-14 03:11 - 01145856 _____ (Farbar) C:\Documents and Settings\Owner\Plocha\FRST.exe
2014-03-14 02:57 - 2014-03-14 02:50 - 00007435 _____ () C:\zoek-results.log
2014-03-14 02:57 - 2014-03-14 02:45 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-14 02:57 - 2014-03-14 02:45 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-03-14 02:57 - 2013-12-24 12:39 - 00000270 _____ () C:\WINDOWS\Tasks\Driver Booster Scan.job
2014-03-14 02:57 - 2013-08-22 16:43 - 00000278 _____ () C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-306829412-3668169067-3135776419-1003.job
2014-03-14 02:57 - 2013-08-22 16:42 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-14 02:57 - 2013-08-22 15:45 - 00000739 _____ () C:\WINDOWS\system32\eRLog.ini
2014-03-14 02:57 - 2005-09-08 10:55 - 00000000 ____D () C:\WINDOWS\system32\Lang
2014-03-14 02:57 - 2005-09-08 10:20 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-14 02:56 - 2014-03-14 02:44 - 00005334 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-14 02:56 - 2013-08-22 18:18 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-03-14 02:56 - 2005-09-08 10:20 - 00000178 ___SH () C:\Documents and Settings\Owner\ntuser.ini
2014-03-14 02:56 - 2005-09-08 10:16 - 00358925 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-14 02:54 - 2014-03-14 02:49 - 00000000 ____D () C:\zoek_backup
2014-03-14 02:54 - 2005-09-08 10:13 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-03-14 02:52 - 2013-08-22 16:42 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-14 02:49 - 2014-03-14 02:56 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-03-14 02:48 - 2014-03-14 02:48 - 01285120 _____ () C:\Documents and Settings\Owner\Plocha\zoek.exe
2014-03-14 02:45 - 2014-03-14 02:45 - 00000000 _____ () C:\WINDOWS\Sti_Trace.log
2014-03-14 02:43 - 2014-03-14 02:41 - 00000000 ____D () C:\AdwCleaner
2014-03-14 02:43 - 2005-09-08 10:20 - 00000000 __RHD () C:\Documents and Settings\Owner\Data aplikací
2014-03-14 02:41 - 2014-03-14 02:41 - 01950720 _____ () C:\Documents and Settings\Owner\Plocha\adwcleaner.exe
2014-03-14 02:35 - 2014-03-14 02:35 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-03-14 02:34 - 2014-03-14 02:34 - 01037734 _____ (Thisisu) C:\Documents and Settings\Owner\Plocha\JRT.exe
2014-03-14 02:34 - 2005-09-08 10:20 - 00000000 ___RD () C:\Documents and Settings\Owner\Nabídka Start
2014-03-14 02:34 - 2005-09-08 10:13 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-03-14 02:34 - 2005-09-08 10:13 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-03-14 02:33 - 2014-03-14 02:33 - 00000000 ____D () C:\WINDOWS\Tasks\ImCleanDisabled
2014-03-14 02:33 - 2013-08-22 21:51 - 00000000 ____D () C:\Program Files\IObit
2014-03-14 02:23 - 2014-02-08 20:18 - 00000992 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-306829412-3668169067-3135776419-1003UA.job
2014-03-14 02:15 - 2014-03-14 02:15 - 00000000 ____D () C:\rsit
2014-03-14 02:15 - 2014-03-14 02:15 - 00000000 ____D () C:\Program Files\trend micro
2014-03-14 02:05 - 2005-09-08 10:20 - 00000000 ____D () C:\Documents and Settings\Owner
2014-03-14 02:05 - 2005-09-08 10:15 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-03-14 02:04 - 2013-11-16 22:40 - 00000000 ____D () C:\Qoobox
2014-03-14 01:35 - 2014-03-13 02:41 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\Media Player Classic
2014-03-14 01:32 - 2013-12-23 18:43 - 19988480 _____ () C:\WINDOWS\system32\config\SOFTWARE.iobit
2014-03-14 01:32 - 2013-12-23 18:43 - 00253952 _____ () C:\WINDOWS\system32\config\DEFAULT.iobit
2014-03-14 01:32 - 2013-12-23 18:43 - 00053248 _____ () C:\WINDOWS\system32\config\SECURITY.iobit
2014-03-14 01:32 - 2013-12-23 18:43 - 00024576 _____ () C:\WINDOWS\system32\config\SAM.iobit
2014-03-14 01:32 - 2005-09-08 10:20 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-03-14 01:32 - 2005-09-08 10:20 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-03-14 01:27 - 2014-03-13 02:55 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Program Files\Combined Community Codec Pack
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Combined Community Codec Pack
2014-03-14 01:26 - 2014-03-14 01:26 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Catalyst Control Center
2014-03-14 01:26 - 2005-09-08 10:15 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-14 01:12 - 2014-03-14 01:12 - 00000000 ____D () C:\Program Files\ATI
2014-03-14 01:11 - 2014-03-14 01:11 - 00000000 ____D () C:\AMD
2014-03-14 00:12 - 2013-08-22 21:02 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\Skype
2014-03-13 20:23 - 2014-02-08 20:18 - 00000970 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-306829412-3668169067-3135776419-1003Core.job
2014-03-13 18:22 - 2013-08-22 16:43 - 00000286 _____ () C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-306829412-3668169067-3135776419-1003.job
2014-03-13 03:20 - 2013-11-02 15:33 - 00000000 ___RD () C:\Documents and Settings\Owner\Plocha\Hudba
2014-03-13 03:15 - 2014-03-13 03:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-13 03:01 - 2005-09-08 10:20 - 00000000 ___RD () C:\Documents and Settings\Owner\Dokumenty
2014-03-13 02:56 - 2014-03-13 02:56 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Data aplikací\Mozilla
2014-03-13 02:56 - 2014-03-13 02:56 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\Mozilla
2014-03-13 02:55 - 2014-03-13 02:55 - 24501312 _____ (Mozilla) C:\Documents and Settings\Owner\Dokumenty\Firefox Setup 27.0.exe
2014-03-13 02:55 - 2014-03-13 02:55 - 00000734 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Mozilla Firefox.lnk
2014-03-13 02:55 - 2014-03-13 02:55 - 00000728 _____ () C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
2014-03-13 02:55 - 2014-03-13 02:55 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Mozilla
2014-03-13 02:35 - 2014-03-13 02:35 - 09357880 _____ (CCCP Project ) C:\Documents and Settings\Owner\Dokumenty\Combined-Community-Codec-Pack-2013-04-20.exe
2014-03-13 00:36 - 2013-09-01 18:18 - 00000000 ____D () C:\Documents and Settings\Owner\Data aplikací\vlc
2014-03-12 17:54 - 2014-02-11 18:40 - 00002283 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-03-12 11:04 - 2013-10-03 15:34 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-12 11:04 - 2013-10-03 15:34 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-11 11:41 - 2013-10-23 22:46 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\POjuwqJUh85
2014-03-06 23:20 - 2013-11-02 15:33 - 00000000 ____D () C:\Documents and Settings\Owner\Plocha\Obrázky
2014-03-05 23:19 - 2014-03-01 14:17 - 00202752 _____ () C:\Documents and Settings\Owner\Plocha\GTASAsf1.b
2014-03-04 18:04 - 2013-08-22 16:42 - 00001817 _____ () C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-03-04 17:20 - 2013-10-03 15:30 - 00000000 ____D () C:\Program Files\Opera
2014-03-04 17:18 - 2005-09-08 10:09 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-02 14:24 - 2014-02-07 18:55 - 19881984 _____ () C:\WINDOWS\system32\config\SOFTWARE.iodefrag.bak
2014-03-02 14:24 - 2014-02-07 18:55 - 00253952 _____ () C:\WINDOWS\system32\config\DEFAULT.iodefrag.bak
2014-03-02 14:24 - 2014-02-07 18:55 - 00053248 _____ () C:\WINDOWS\system32\config\SECURITY.iodefrag.bak
2014-03-02 14:24 - 2014-02-07 18:55 - 00024576 _____ () C:\WINDOWS\system32\config\SAM.iodefrag.bak
2014-03-01 20:47 - 2014-01-19 16:13 - 00000000 ____D () C:\Program Files\Steam
2014-03-01 20:47 - 2013-08-24 17:25 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\League of Legends
2014-03-01 16:28 - 2014-03-01 16:28 - 00000874 _____ () C:\Documents and Settings\Owner\Plocha\San Andreas Multiplayer.lnk
2014-03-01 16:28 - 2014-03-01 16:28 - 00000000 ____D () C:\Documents and Settings\Owner\Nabídka Start\Programy\San Andreas Multiplayer
2014-03-01 16:28 - 2014-03-01 16:27 - 11990847 _____ () C:\Documents and Settings\Owner\Dokumenty\sa-mp-0.3z-R1-install.exe
2014-03-01 16:28 - 2014-02-26 19:38 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\GTA San Andreas User Files
2014-03-01 16:28 - 2005-09-08 10:20 - 00000000 ___RD () C:\Documents and Settings\Owner\Nabídka Start\Programy
2014-02-26 19:39 - 2014-02-26 19:39 - 01191753 _____ () C:\Documents and Settings\Owner\Dokumenty\gtasa120cz.zip
2014-02-26 19:37 - 2014-02-26 19:37 - 00098304 _____ (Sony DADC Austria AG.) C:\WINDOWS\system32\CmdLineExt.dll
2014-02-26 19:26 - 2014-02-26 19:26 - 00001591 _____ () C:\Documents and Settings\All Users\Plocha\GTA San Andreas.lnk
2014-02-26 19:26 - 2014-02-24 19:16 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Rockstar Games
2014-02-26 19:26 - 2014-02-24 18:42 - 00000000 ____D () C:\Program Files\Rockstar Games
2014-02-26 19:26 - 2005-09-08 10:24 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-02-25 22:21 - 2005-09-08 10:13 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start
2014-02-25 22:14 - 2014-02-25 22:14 - 00000000 ____D () C:\Documents and Settings\Owner\WINDOWS
2014-02-24 19:46 - 2014-02-24 19:21 - 00000000 ____D () C:\Documents and Settings\Owner\Dokumenty\Max Payne 2 Savegames
2014-02-24 19:20 - 2014-02-24 19:20 - 01486848 _____ (Remedy Entertainment) C:\Documents and Settings\Owner\Dokumenty\Max-Payne-2-crack-(alik).exe
2014-02-24 18:55 - 2014-02-24 18:54 - 38542610 _____ () C:\Documents and Settings\Owner\Dokumenty\MaxPayne2CZ_komplet.exe
2014-02-24 18:52 - 2014-02-24 18:52 - 00001757 _____ () C:\Documents and Settings\Owner\Plocha\Max Payne 2.lnk
2014-02-23 18:55 - 2014-02-22 13:28 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Data aplikací\Game Dev Tycoon
2014-02-22 13:25 - 2014-02-22 13:25 - 00000633 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Game Dev Tycoon v1.3.2.lnk
2014-02-22 13:25 - 2014-02-22 13:25 - 00000627 _____ () C:\Documents and Settings\All Users\Plocha\Game Dev Tycoon v1.3.2.lnk
2014-02-22 13:25 - 2014-02-22 13:25 - 00000000 ____D () C:\Program Files\Game Dev Tycoon v1.3.2
2014-02-22 13:20 - 2014-02-22 13:07 - 115532320 _____ () C:\Documents and Settings\Owner\Dokumenty\Game.Dev.Tycoon-ALiAS.rar
2014-02-15 14:20 - 2014-02-15 14:14 - 00000000 ____D () C:\Documents and Settings\Owner\Plocha\Flashka
2014-02-15 14:14 - 2013-12-08 21:06 - 00011264 _____ () C:\Documents and Settings\Owner\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Documents and Settings\Owner\Local Settings\Temp\jre-7u51-windows-i586-iftw.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2005-09-08 10:08] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2005-09-08 10:09] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2005-09-08 10:09] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2013-08-22 16:59] - [2008-04-14 07:52] - 0108544 ____A (Microsoft Corporation) f0d2ae69035092bf22dad6b50fab85c2
C:\WINDOWS\system32\User32.dll
[2005-09-08 10:09] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2013-08-22 16:59] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll
[2005-09-08 10:09] - [2008-04-14 07:51] - 0399360 ____A (Microsoft Corporation) c868f3ae15cf71a93f2aa3a32856d839
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\WINDOWS\system32\Drivers\volsnap.sys
[2013-08-22 16:59] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================