Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Monika (administrator) on MONIKA-PC on 21-03-2014 13:44:47
Running from C:\Users\Monika\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
() C:\Program Files\Guard-ICQ\GuardICQ.exe
() C:\Windows\system32\dmwu.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
() C:\Program Files\Guard-ICQ\GuardICQ.exe
(SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Messenger\SweetIM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
() C:\Program Files\Vtune\TBPANEL.exe
(Yontoo LLC) C:\Users\Monika\AppData\Roaming\Yontoo\YontooDesktop.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Windows\System32\jmdp\stij.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Google Inc.) C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Monika\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-10-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [3080264 2011-09-22] (ESET)
HKLM\...\Run: [Guard.Mail.ru.gui] - C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-05-06] ()
HKLM\...\Run: [SweetIM] - C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-08] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [TBPanel] - C:\Program Files\Vtune\TBPanel.exe [2158592 2009-08-19] ()
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [Google Update] - C:\Users\Monika\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-07-23] (Google Inc.)
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE [188928 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1824000 2014-02-11] (Valve Corporation)
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\Run: [Yontoo Desktop] - C:\Users\Monika\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-01-31] (Yontoo LLC)
HKU\S-1-5-21-3085873043-2672085813-2627963472-1000\...\MountPoints2: {f8e94fa5-dc48-11df-90f0-406186284371} - E:\Setup.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://isearch.babylon.com/?affID=11206 ... 6186284371
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x61BD7457DBBDCA01
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search =
http://search.icq.com/search/results.ph ... &ch_id=osd
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL =
http://search.sweetim.com/search.asp?sr ... 6186284371}
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
http://search.sweetim.com/search.asp?sr ... 6186284371}
SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL =
http://slirsredirect.search.aol.com/sli ... 0winampie7
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://search.babylon.com/?q={searchTer ... 6186284371
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://search.babylon.com/?q={searchTer ... 6186284371
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
http://websearch.ask.com/redirect?clien ... 18A914FA26
SearchScopes: HKCU - {4BAB4D87-52D7-4493-A318-96EC535F1F61} URL =
http://search.conduit.com/ResultsExt.as ... 6811380217
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL =
http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
http://search.sweetim.com/search.asp?sr ... t=23&st=23
SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL =
http://slirsredirect.search.aol.com/sli ... 0winampie7
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {1C749E08-6B62-11E0-B6DA-075F4824019B} - No File
BHO: No Name - {2EECD738-5844-4a99-B4B6-146BF802613B} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 80.87.208.29 8.8.8.8
Chrome:
=======
CHR HomePage: hxxp://home.sweetim.com/?barid=&src=10&&st=23
CHR Plugin: (Shockwave Flash) - C:\Users\Monika\AppData\Local\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Monika\AppData\Local\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Monika\AppData\Local\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Extension: (Video Player) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\bffjccobdichdckaoldboabfigpbokfa [2014-01-10]
CHR Extension: (McAfee Security Scan+) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-21]
CHR Extension: (Browser Companion Helper) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\clbfjfbnelcflpgpklppgplejolacbej [2013-06-05]
CHR Extension: (Webexp Enhanced) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\emlcldapalaljnflpanlkgoepnmmjdkl [2013-12-20]
CHR Extension: (avast! Online Security) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-08]
CHR Extension: (SweetIM for Facebook) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn [2013-06-05]
CHR Extension: (BrotherSoft Extreme2 B1) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\jndeiekmdhemaggmkgljlpdeaomeplbp [2013-06-05]
CHR Extension: (Yontoo) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc [2013-06-05]
CHR Extension: (Peněženka Google) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-06-05]
CHR HKLM\...\Chrome\Extension: [bffjccobdichdckaoldboabfigpbokfa] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta548\ch\VideoPlayerV3beta548.crx [2014-01-07]
CHR HKLM\...\Chrome\Extension: [clbfjfbnelcflpgpklppgplejolacbej] - C:\Program Files\BrowserCompanion\blabbers-ch.crx [2011-12-22]
CHR HKLM\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files\BetterSurf\ch\Chrome.crx [2011-12-22]
CHR HKLM\...\Chrome\Extension: [emlcldapalaljnflpanlkgoepnmmjdkl] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha708\ch\WebexpEnhancedV1alpha708.crx [2013-12-19]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-08]
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-12-20]
CHR HKLM\...\Chrome\Extension: [jndeiekmdhemaggmkgljlpdeaomeplbp] - C:\Users\Monika\AppData\Local\CRE\jndeiekmdhemaggmkgljlpdeaomeplbp.crx [2013-01-30]
CHR HKLM\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx [2013-01-30]
CHR HKLM\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files\Yontoo\YontooLayers.crx [2013-02-01]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Monika\AppData\Local\GamePlayLabs Plugin\plugin.crx [2011-04-23]
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\System32\jmdp\SweetNT.crx [2014-02-04]
CHR HKLM\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files\Better-Surf\ch\Chrome.crx [2014-02-04]
CHR HKCU\...\Chrome\Extension: [jndeiekmdhemaggmkgljlpdeaomeplbp] - C:\Users\Monika\AppData\Local\CRE\jndeiekmdhemaggmkgljlpdeaomeplbp.crx [2013-01-30]
CHR StartMenuInternet: Google Chrome - C:\Users\Monika\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-08] (AVAST Software)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [974944 2011-09-22] (ESET)
R2 Guard.Mail.ru; C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-05-06] ()
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1527600 2014-02-04] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [235696 2014-01-16] (McAfee, Inc.)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-08] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-12-08] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-12-08] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-08] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-08] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-01-08] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-08] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-08-16] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [103112 2011-08-04] (ESET)
S3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36640 2009-12-22] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-01-11] (Duplex Secure Ltd.)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2009-09-19] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2009-09-19] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2009-09-19] (MCCI Corporation)
S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [100224 2009-09-19] (MCCI Corporation)
R2 TBPanel; C:\Windows\system32\Drivers\TBPanel.sys [12256 2007-03-16] (Windows (R) 2000 DDK provider)
U3 awgiygxx; C:\Windows\system32\Drivers\awgiygxx.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-21 13:44 - 2014-03-21 13:45 - 00018511 _____ () C:\Users\Monika\Desktop\FRST.txt
2014-03-21 13:44 - 2014-03-21 13:44 - 00000000 ____D () C:\FRST
2014-03-21 13:42 - 2014-03-21 13:42 - 00112640 _____ (forum.viry.cz) C:\Users\Monika\Desktop\FRSTLauncher.exe
2014-03-21 13:34 - 2014-03-21 13:30 - 01145856 _____ (Farbar) C:\Users\Monika\Desktop\FRST.exe
2014-03-21 13:27 - 2014-03-21 13:27 - 00118200 _____ () C:\Users\Monika\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-20 14:10 - 2014-03-21 05:55 - 00000112 _____ () C:\Windows\setupact.log
2014-03-20 14:10 - 2014-03-20 14:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-20 14:09 - 2014-03-20 14:09 - 01773344 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-20 14:09 - 2014-03-20 14:09 - 00001516 _____ () C:\Windows\PFRO.log
2014-03-19 22:07 - 2014-03-19 22:07 - 00002083 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-19 22:07 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2014-03-19 22:06 - 2014-03-19 22:08 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-19 22:06 - 2014-03-19 22:07 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-03-19 21:57 - 2014-03-19 21:57 - 00003006 _____ () C:\Windows\DPINST.LOG
2014-03-19 21:37 - 2014-03-19 21:38 - 00000000 ___SD () C:\ComboFix
2014-03-19 21:37 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-19 21:37 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-19 21:37 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-19 21:37 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-19 21:37 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-19 21:37 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-03-19 21:37 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-03-19 21:37 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-03-19 21:32 - 2014-03-19 21:32 - 00000000 ____D () C:\Qoobox
2014-03-19 21:30 - 2014-03-19 21:30 - 00000000 ____D () C:\Windows\erdnt
2014-03-12 14:46 - 2014-03-11 13:22 - 00000000 ____D () C:\Users\Monika\Desktop\Separ--Pirát-ALBUM-2014Separ-- mp3
2014-03-11 21:38 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-11 21:38 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-11 21:38 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-11 21:38 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-11 21:38 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-11 21:38 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-11 21:38 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-11 21:38 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-11 21:38 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-11 21:38 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-11 21:38 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-11 21:38 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-11 21:38 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-11 21:38 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-11 21:37 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-11 21:37 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-11 21:37 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-11 21:37 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-11 21:37 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-11 21:37 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-11 21:37 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-11 21:37 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-11 21:37 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-11 21:33 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-11 21:33 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-11 21:33 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-11 21:33 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-05 16:17 - 2014-03-05 16:17 - 00000000 ____D () C:\Windows\system32\jmdp
2014-03-05 03:03 - 2014-03-05 03:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
==================== One Month Modified Files and Folders =======
2014-03-21 13:45 - 2014-03-21 13:44 - 00018511 _____ () C:\Users\Monika\Desktop\FRST.txt
2014-03-21 13:44 - 2014-03-21 13:44 - 00000000 ____D () C:\FRST
2014-03-21 13:42 - 2014-03-21 13:42 - 00112640 _____ (forum.viry.cz) C:\Users\Monika\Desktop\FRSTLauncher.exe
2014-03-21 13:33 - 2009-07-14 05:34 - 00015344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-21 13:33 - 2009-07-14 05:34 - 00015344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-21 13:30 - 2014-03-21 13:34 - 01145856 _____ (Farbar) C:\Users\Monika\Desktop\FRST.exe
2014-03-21 13:27 - 2014-03-21 13:27 - 00118200 _____ () C:\Users\Monika\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-21 13:15 - 2010-07-23 19:44 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3085873043-2672085813-2627963472-1000UA.job
2014-03-21 13:00 - 2012-04-24 17:52 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-21 12:58 - 2013-02-24 01:52 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-21 12:41 - 2013-08-16 14:32 - 00000360 _____ () C:\Windows\Tasks\AmiUpdXp.job
2014-03-21 11:57 - 2013-02-01 21:14 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Yontoo
2014-03-21 09:45 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2014-03-21 06:00 - 2012-07-18 18:48 - 00000000 ____D () C:\Program Files\Steam
2014-03-21 05:59 - 2010-01-30 22:27 - 01806060 _____ () C:\Windows\WindowsUpdate.log
2014-03-21 05:55 - 2014-03-20 14:10 - 00000112 _____ () C:\Windows\setupact.log
2014-03-21 05:55 - 2012-04-24 17:52 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-21 05:55 - 2011-02-16 11:59 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-03-21 05:55 - 2010-01-30 22:40 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-21 05:55 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-20 21:53 - 2011-05-12 20:45 - 00000438 ____H () C:\Windows\Tasks\Norton Security Scan for Monika.job
2014-03-20 14:27 - 2010-01-30 22:34 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-20 14:10 - 2014-03-20 14:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-20 14:09 - 2014-03-20 14:09 - 01773344 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-20 14:09 - 2014-03-20 14:09 - 00001516 _____ () C:\Windows\PFRO.log
2014-03-20 02:15 - 2010-07-23 19:44 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3085873043-2672085813-2627963472-1000Core.job
2014-03-19 22:08 - 2014-03-19 22:06 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-19 22:07 - 2014-03-19 22:07 - 00002083 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-19 22:07 - 2014-03-19 22:06 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-03-19 22:01 - 2012-12-20 17:05 - 00000000 ____D () C:\ProgramData\SweetIM
2014-03-19 22:01 - 2012-12-20 17:05 - 00000000 ____D () C:\Program Files\SweetIM
2014-03-19 21:59 - 2012-05-31 05:59 - 00000000 ____D () C:\Program Files\BrowserCompanion
2014-03-19 21:57 - 2014-03-19 21:57 - 00003006 _____ () C:\Windows\DPINST.LOG
2014-03-19 21:38 - 2014-03-19 21:37 - 00000000 ___SD () C:\ComboFix
2014-03-19 21:35 - 2011-04-09 13:43 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVI ReComp
2014-03-19 21:35 - 2010-11-20 08:13 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Check Disk
2014-03-19 21:35 - 2010-07-23 19:49 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-03-19 21:32 - 2014-03-19 21:32 - 00000000 ____D () C:\Qoobox
2014-03-19 21:30 - 2014-03-19 21:30 - 00000000 ____D () C:\Windows\erdnt
2014-03-19 09:37 - 2013-08-16 18:57 - 00000000 ____D () C:\Users\Monika\Documents\Command and Conquer Generals Zero Hour Data
2014-03-19 03:05 - 2013-07-15 22:19 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 03:01 - 2010-08-23 19:10 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-15 19:56 - 2013-10-05 15:07 - 00000000 ____D () C:\Users\Monika\Documents\NHL09
2014-03-15 18:11 - 2013-08-16 17:40 - 00000000 ____D () C:\Users\Monika\Documents\Command and Conquer Generals Data
2014-03-12 03:03 - 2010-01-30 23:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-12 02:58 - 2013-02-24 01:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-12 02:58 - 2011-07-06 18:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 22:03 - 2010-02-02 21:46 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Skype
2014-03-11 13:22 - 2014-03-12 14:46 - 00000000 ____D () C:\Users\Monika\Desktop\Separ--Pirát-ALBUM-2014Separ-- mp3
2014-03-08 09:31 - 2013-05-28 11:45 - 00000000 ____D () C:\Users\Monika\Desktop\Cata - 4.3.4 Deffender
2014-03-05 16:17 - 2014-03-05 16:17 - 00000000 ____D () C:\Windows\system32\jmdp
2014-03-05 08:42 - 2013-06-10 05:33 - 00000000 ____D () C:\Windows\system32\WNLT
2014-03-05 08:42 - 2013-06-10 05:33 - 00000000 ____D () C:\Windows\system32\ARFC
2014-03-05 03:03 - 2014-03-05 03:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-05 03:03 - 2010-02-02 21:45 - 00002719 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-05 03:03 - 2010-02-02 21:45 - 00000000 ___RD () C:\Program Files\Skype
2014-03-05 03:03 - 2010-02-02 21:45 - 00000000 ____D () C:\ProgramData\Skype
2014-03-01 05:30 - 2014-03-11 21:37 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 05:11 - 2014-03-11 21:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 05:10 - 2014-03-11 21:38 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 04:52 - 2014-03-11 21:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 04:51 - 2014-03-11 21:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-11 21:38 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 04:43 - 2014-03-11 21:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 04:43 - 2014-03-11 21:38 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 04:40 - 2014-03-11 21:38 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 04:38 - 2014-03-11 21:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 04:38 - 2014-03-11 21:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 04:37 - 2014-03-11 21:38 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 04:31 - 2014-03-11 21:38 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 04:25 - 2014-03-11 21:37 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 04:16 - 2014-03-11 21:37 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:14 - 2014-03-11 21:38 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:03 - 2014-03-11 21:37 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:00 - 2014-03-11 21:37 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 03:57 - 2014-03-11 21:37 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 03:32 - 2014-03-11 21:38 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 03:27 - 2014-03-11 21:37 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:25 - 2014-03-11 21:38 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 03:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Monika\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3085873043-2672085813-2627963472-1000Core.job => C:\Users\Monika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3085873043-2672085813-2627963472-1000UA.job => C:\Users\Monika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Monika.job => C:\PROGRA~1\NORTON~2\Engine\311~1.6\Nss.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET NOD32 Antivirus 5.0 (Enabled - Out of date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: ESET NOD32 Antivirus 5.0 (Enabled - Out of date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Monika\Desktop" je 93254 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================