klíčová slova v textu - vyskakující reklama
Napsal: 28 bře 2014 19:59
Ahoj, při surfování se mi podtrhávají slova a při najetí na ně vyskakují banery s odkazem na watchItNoAds.
zde je muj log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Acer (administrator) on ACER-PC on 28-03-2014 19:52:54
Running from C:\Users\Acer\Desktop
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(BitTorrent Inc.) C:\Users\Acer\AppData\Roaming\uTorrent\uTorrent.exe
(forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [ODDPwr] - C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe [223264 2010-04-22] (Acer Incorporated)
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-04-17] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2107176 2010-03-11] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2010-04-23] (Acer Incorporated)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10081312 2010-02-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [877600 2010-02-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-04-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608 2010-03-09] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.)
HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [124136 2010-04-24] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [Google Update] - C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-06-18] (Google Inc.)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [APISupport] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Acer\AppData\Local\Conduit\APISupport\APISupport.dll",DLLRunAPISupport <===== ATTENTION
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {4efb415e-4113-11e0-9726-5cac4c77853d} - "F:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {4efb4174-4113-11e0-9726-5cac4c77853d} - G:\Setup.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {674a3cec-992e-11e2-b7e5-5cac4c77853d} - E:\TMCCSetup_3.57.95.14.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {712d6f00-4808-11e0-99aa-5cac4c77853d} - D:\AutoRun.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {dae842f8-672b-11e3-a410-c80aa9c604af} - E:\LGAutoRun.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {dfa1a884-6240-11e1-9a0e-c80aa9c604af} - "G:\WD SmartWare.exe" autoplay=true
AppInit_DLLs: C:\PROGRA~3\WINFIL~1\WINFIL~2.DLL => C:\ProgramData\WinFilter\WinFilter_x64.dll [4356096 2014-01-11] ()
AppInit_DLLs-x32: c:\progra~2\citrix\icacli~1\rshook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257176 2012-04-05] (Citrix Systems, Inc.)
AppInit_DLLs-x32: c:\progra~3\winfil~1\winfil~1.dll => C:\ProgramData\WinFilter\WinFilter.dll [4157952 2014-01-11] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchpages.info/?unqvl=29
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchpages.info/?unqvl=29
URLSearchHook: HKCU - (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT3072253
SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {9D4AD3AC-93CF-4D93-AC41-2A2276F0FB49} URL = http://websearch.ask.com/redirect?clien ... 4610E6D806
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT3072253
SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
BHO: WaottCChIatNoAds - {0933B14F-5321-C1CF-C48D-227E40B921CD} - C:\ProgramData\WaottCChIatNoAds\R4.x64.dll ()
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: FindBesitDeal - {D3920129-228B-804D-5E1F-BB7385D029EF} - C:\ProgramData\FindBesitDeal\y15_3C8Qzv.x64.dll ()
BHO-x32: WaottCChIatNoAds - {0933B14F-5321-C1CF-C48D-227E40B921CD} - C:\ProgramData\WaottCChIatNoAds\R4.dll ()
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: CtxIEInterceptorBHO Class - {2C4631FF-5CC8-4EBC-A0DF-34C92291759E} - C:\Program Files (x86)\Citrix\ICA Client\IEInterceptor.dll (Citrix Systems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: FindBesitDeal - {D3920129-228B-804D-5E1F-BB7385D029EF} - C:\ProgramData\FindBesitDeal\y15_3C8Qzv.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default
FF user.js: detected! => C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\user.js
FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", "");
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://websearch.searchpages.info/?unqvl=29&l=1&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Citrix.com/npican - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Acer\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Acer\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\searchplugins\WebSearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WaottCChIatNoAds - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\joajau@ao-vfsw.edu [2014-01-31]
FF Extension: FindBesitDeal - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\rfzj@ioooouou.net [2014-03-06]
FF Extension: Garmin Communicator - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-20]
FF Extension: Seznam lištička - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-29]
FF Extension: Adblock Plus - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-02-20]
Chrome:
=======
CHR HomePage: hxxp://websearch.searchpages.info/?unqvl=29
CHR RestoreOnStartup: "hxxp://websearch.searchpages.info/?unqvl=29"
CHR DefaultSearchKeyword: websearch
CHR DefaultSearchProvider: WebSearch
CHR DefaultSearchURL: http://websearch.searchpages.info/?unqv ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Citrix ICA Client) - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Acer\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-18]
CHR Extension: (Vyhledvn Google) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-18]
CHR Extension: (WaottCChIatNoAds) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdklgkmdncckfacndpfdkcfodaagjlmk [2014-03-27]
CHR Extension: (GreaatSave4U) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhdpmggjjdokaplmejdngeggfdkkknbb [2014-01-12]
CHR Extension: (Peněženka Google) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-29]
CHR Extension: (FindBesitDeal) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\opbeehcldpcflbapodnleajdikeeagka [2014-03-06]
CHR Extension: (uTorrentControl2) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc [2012-06-22]
CHR Extension: (Gmail) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-18]
CHR Extension: (JoniCouPon) - C:\ProgramData\ikialoaigjekepdfkpiahljfkchcflfd [2014-01-12]
CHR HKCU\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Acer\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-06-07]
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Acer\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-06-07]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 03e661da; C:\ProgramData\WinFilter\WinFilterSvc.dll [178512 2014-01-11] ()
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-04-23] (Acer Incorporated)
S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [375176 2011-10-09] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-04-17] (Egis Technology Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-08-19] (DT Soft Ltd)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-12-15] (Huawei Technologies Co., Ltd.)
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [29696 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-12-15] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 Andbus; system32\DRIVERS\lgandbus64.sys [X]
S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X]
S3 AndGps; system32\DRIVERS\lgandgps64.sys [X]
S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtpt64.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbs64.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmdm64.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-28 19:52 - 2014-03-28 19:53 - 00030096 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-03-28 19:51 - 2014-03-28 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-03-28 19:50 - 2014-03-28 19:52 - 00000000 ____D () C:\FRST
2014-03-28 19:49 - 2014-03-28 19:49 - 02157056 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-03-28 19:05 - 2014-03-28 19:12 - 00000000 ____D () C:\Users\Acer\Downloads\Her.2013.DVDSCR.XviD.MP3-RARBG
2014-03-27 19:32 - 2014-03-27 21:55 - 00000000 ____D () C:\Users\Acer\Documents\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:32 - 00000000 ____D () C:\Program Files\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:31 - 00000800 _____ () C:\Users\Public\Desktop\OpenTTD.lnk
2014-03-25 21:38 - 2014-03-25 21:53 - 371878445 _____ () C:\Users\Acer\Downloads\Vikings.S02E04.HDTV.x264-KILLERS.mp4
2014-03-25 21:38 - 2014-03-25 21:42 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E03 HDTV x264-KILLERS[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E02 HDTV x264-EXCELLENCE[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E01 HDTV x264-EXCELLENCE[ettv]
2014-03-25 00:41 - 2014-03-25 00:41 - 00031179 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x04(0000072184).srt
2014-03-25 00:40 - 2014-03-25 00:40 - 00029660 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x03(0000072018).srt
2014-03-25 00:39 - 2014-03-25 00:39 - 00039033 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x02-Work-Experience(0000063307).srt
2014-03-24 18:56 - 2014-03-24 18:56 - 00029308 _____ () C:\Users\Acer\Downloads\The-Office-US-02x01-The-Dundies(0000088947).srt
2014-03-23 19:06 - 2014-03-23 19:06 - 00000000 ____D () C:\Users\Acer\Downloads\Anchorman 2 The Legend Continues [2013] HDRip XViD juggs[ETRG]
2014-03-23 19:05 - 2014-03-23 19:34 - 00000000 ____D () C:\Users\Acer\Downloads\The Hobbit The Desolation of Smaug (2013) [1080p]
2014-03-22 11:20 - 2014-03-22 11:20 - 00000706 _____ () C:\Windows\PFRO.log
2014-03-22 01:44 - 2014-03-22 01:44 - 00030144 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x01(0000071553).srt
2014-03-21 18:30 - 2014-03-28 16:57 - 00004312 _____ () C:\Windows\setupact.log
2014-03-21 18:30 - 2014-03-21 18:30 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-21 17:21 - 2014-03-28 19:42 - 00308652 _____ () C:\Windows\WindowsUpdate.log
2014-03-14 18:43 - 2014-03-14 18:43 - 00003028 _____ () C:\Windows\System32\Tasks\{A1967811-C67D-4DDA-94D5-A9F96A9B0FB0}
2014-03-14 18:38 - 2014-03-14 18:42 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 18:38 - 2014-03-14 18:42 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 18:38 - 2014-03-14 18:42 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 17:29 - 2014-03-14 17:33 - 00000000 ____D () C:\Program Files (x86)\Spawn
2014-03-14 17:09 - 2014-03-14 17:11 - 00000000 ____D () C:\Users\Acer\Downloads\The Office (UK) Series 1 + 2 Christmas Specials And Extras
2014-03-08 18:07 - 2014-03-08 18:07 - 00096678 _____ () C:\Users\Acer\Downloads\Futurama-Into-the-Wild-Green-Yonder(0000126129).srt
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{E1F4B145-E903-4F36-A2AC-970F9C4D5F62}
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{74AB941E-BF69-4735-8982-3B619A505EEC}
2014-03-06 22:54 - 2014-03-06 22:55 - 00000000 ____D () C:\ProgramData\FindBesitDeal
2014-03-05 17:52 - 2014-03-05 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-04 23:54 - 2014-03-04 23:54 - 00000014 _____ () C:\Users\Acer\Desktop\sex.txt
2014-03-02 09:41 - 2014-03-02 09:45 - 00000000 ____D () C:\Users\Acer\Downloads\Blade.Runner (1997)
2014-02-28 21:31 - 2014-02-28 22:10 - 00000000 ____D () C:\Program Files (x86)\battlefield
==================== One Month Modified Files and Folders =======
2014-03-28 19:53 - 2014-03-28 19:52 - 00030096 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-03-28 19:52 - 2014-03-28 19:50 - 00000000 ____D () C:\FRST
2014-03-28 19:51 - 2014-03-28 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-03-28 19:50 - 2011-01-12 19:00 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\uTorrent
2014-03-28 19:49 - 2014-03-28 19:49 - 02157056 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-03-28 19:42 - 2014-03-21 17:21 - 00308652 _____ () C:\Windows\WindowsUpdate.log
2014-03-28 19:13 - 2013-05-29 16:03 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-28 19:13 - 2012-06-18 17:42 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000UA.job
2014-03-28 19:12 - 2014-03-28 19:05 - 00000000 ____D () C:\Users\Acer\Downloads\Her.2013.DVDSCR.XviD.MP3-RARBG
2014-03-28 18:13 - 2012-06-18 17:42 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000Core.job
2014-03-28 17:04 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-28 17:04 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-28 16:57 - 2014-03-21 18:30 - 00004312 _____ () C:\Windows\setupact.log
2014-03-28 16:57 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-27 22:33 - 2010-12-23 14:09 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AADA1DE1-C4EA-4E45-B845-2B3562A555BF}
2014-03-27 21:55 - 2014-03-27 19:32 - 00000000 ____D () C:\Users\Acer\Documents\OpenTTD
2014-03-27 19:32 - 2014-03-27 19:31 - 00000000 ____D () C:\Program Files\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:31 - 00000800 _____ () C:\Users\Public\Desktop\OpenTTD.lnk
2014-03-27 18:18 - 2012-06-19 19:09 - 00000000 ____D () C:\Users\Acer\AppData\Local\Conduit
2014-03-26 17:49 - 2012-05-01 10:06 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-26 17:48 - 2012-03-31 14:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-26 17:48 - 2012-03-31 14:29 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-25 21:53 - 2014-03-25 21:38 - 371878445 _____ () C:\Users\Acer\Downloads\Vikings.S02E04.HDTV.x264-KILLERS.mp4
2014-03-25 21:42 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E03 HDTV x264-KILLERS[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E02 HDTV x264-EXCELLENCE[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E01 HDTV x264-EXCELLENCE[ettv]
2014-03-25 00:41 - 2014-03-25 00:41 - 00031179 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x04(0000072184).srt
2014-03-25 00:40 - 2014-03-25 00:40 - 00029660 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x03(0000072018).srt
2014-03-25 00:39 - 2014-03-25 00:39 - 00039033 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x02-Work-Experience(0000063307).srt
2014-03-24 18:56 - 2014-03-24 18:56 - 00029308 _____ () C:\Users\Acer\Downloads\The-Office-US-02x01-The-Dundies(0000088947).srt
2014-03-23 19:34 - 2014-03-23 19:05 - 00000000 ____D () C:\Users\Acer\Downloads\The Hobbit The Desolation of Smaug (2013) [1080p]
2014-03-23 19:06 - 2014-03-23 19:06 - 00000000 ____D () C:\Users\Acer\Downloads\Anchorman 2 The Legend Continues [2013] HDRip XViD juggs[ETRG]
2014-03-23 12:49 - 2014-01-29 11:00 - 00002000 ____H () C:\Users\Acer\Documents\Default.rdp
2014-03-22 11:20 - 2014-03-22 11:20 - 00000706 _____ () C:\Windows\PFRO.log
2014-03-22 01:44 - 2014-03-22 01:44 - 00030144 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x01(0000071553).srt
2014-03-21 18:30 - 2014-03-21 18:30 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-18 18:03 - 2013-08-11 22:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 18:00 - 2010-12-17 14:00 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 21:43 - 2011-02-25 20:30 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-03-17 21:41 - 2013-03-14 22:51 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-17 21:41 - 2013-03-14 22:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-17 00:06 - 2010-08-24 12:47 - 00631526 _____ () C:\Windows\system32\perfh005.dat
2014-03-17 00:06 - 2010-08-24 12:47 - 00122148 _____ () C:\Windows\system32\perfc005.dat
2014-03-17 00:06 - 2009-07-14 06:13 - 01470298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-17 00:05 - 2010-12-27 11:49 - 00000000 ____D () C:\Users\Acer\Documents\knížky
2014-03-14 18:43 - 2014-03-14 18:43 - 00003028 _____ () C:\Windows\System32\Tasks\{A1967811-C67D-4DDA-94D5-A9F96A9B0FB0}
2014-03-14 18:42 - 2014-03-14 18:38 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 18:42 - 2014-03-14 18:38 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 18:42 - 2014-03-14 18:38 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 18:38 - 2012-06-04 07:25 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-14 18:27 - 2013-05-10 21:55 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\AIMP3
2014-03-14 17:33 - 2014-03-14 17:29 - 00000000 ____D () C:\Program Files (x86)\Spawn
2014-03-14 17:11 - 2014-03-14 17:09 - 00000000 ____D () C:\Users\Acer\Downloads\The Office (UK) Series 1 + 2 Christmas Specials And Extras
2014-03-14 06:08 - 2013-03-11 17:42 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-14 06:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-13 22:14 - 2013-05-29 16:03 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-13 22:14 - 2013-03-11 17:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-13 22:14 - 2011-07-17 18:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-13 21:09 - 2010-12-17 18:19 - 00000000 ____D () C:\Users\Acer
2014-03-11 09:52 - 2011-04-27 14:25 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys
2014-03-09 14:49 - 2010-12-27 11:50 - 00000000 ____D () C:\Users\Acer\Documents\recepty
2014-03-08 18:07 - 2014-03-08 18:07 - 00096678 _____ () C:\Users\Acer\Downloads\Futurama-Into-the-Wild-Green-Yonder(0000126129).srt
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{E1F4B145-E903-4F36-A2AC-970F9C4D5F62}
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{74AB941E-BF69-4735-8982-3B619A505EEC}
2014-03-08 17:05 - 2011-02-06 17:54 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-08 16:48 - 2010-12-27 18:09 - 00063160 _____ () C:\Users\Acer\AppData\Roaming\GDIPFONTCACHEV1.DAT
2014-03-06 22:55 - 2014-03-06 22:54 - 00000000 ____D () C:\ProgramData\FindBesitDeal
2014-03-06 22:55 - 2014-01-12 13:18 - 00000000 ____D () C:\ProgramData\32da34b8ed9c5e86
2014-03-05 17:52 - 2014-03-05 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-05 17:52 - 2010-12-26 19:25 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-05 17:52 - 2010-12-26 19:25 - 00000000 ____D () C:\ProgramData\Skype
2014-03-04 23:54 - 2014-03-04 23:54 - 00000014 _____ () C:\Users\Acer\Desktop\sex.txt
2014-03-02 22:01 - 2014-01-31 22:15 - 00000000 ____D () C:\Users\Acer\Downloads\The.Counselor.2013.UNRATED.HDRip XViD NO1KNOWS
2014-03-02 09:45 - 2014-03-02 09:41 - 00000000 ____D () C:\Users\Acer\Downloads\Blade.Runner (1997)
2014-02-28 22:10 - 2014-02-28 21:31 - 00000000 ____D () C:\Program Files (x86)\battlefield
2014-02-28 22:08 - 2011-01-14 20:32 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000Core.job => C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000UA.job => C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:798A3728
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:93EB7685
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:AEBFFE08
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E36F5B57
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Acer\Desktop" je 9133 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AthBtTray
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtherosBtStack
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ConnectionCenter
"C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Garmin Lifetime Updater
C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
"C:\Program Files (x86)\ASUSTek\ASUSDVD\PDVDServ.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk
C:\PROGRA~2\Acer\ACERVC~1\AcerVCM.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Acer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk
C:\PROGRA~2\Evernote\Evernote\EVERNO~2.EXE [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
děkuji za pomoc
olda
zde je muj log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Acer (administrator) on ACER-PC on 28-03-2014 19:52:54
Running from C:\Users\Acer\Desktop
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(BitTorrent Inc.) C:\Users\Acer\AppData\Roaming\uTorrent\uTorrent.exe
(forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [ODDPwr] - C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe [223264 2010-04-22] (Acer Incorporated)
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-04-17] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2107176 2010-03-11] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2010-04-23] (Acer Incorporated)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10081312 2010-02-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [877600 2010-02-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-04-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608 2010-03-09] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.)
HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [124136 2010-04-24] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [Google Update] - C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-06-18] (Google Inc.)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd)
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\Run: [APISupport] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Acer\AppData\Local\Conduit\APISupport\APISupport.dll",DLLRunAPISupport <===== ATTENTION
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {4efb415e-4113-11e0-9726-5cac4c77853d} - "F:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {4efb4174-4113-11e0-9726-5cac4c77853d} - G:\Setup.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {674a3cec-992e-11e2-b7e5-5cac4c77853d} - E:\TMCCSetup_3.57.95.14.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {712d6f00-4808-11e0-99aa-5cac4c77853d} - D:\AutoRun.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {dae842f8-672b-11e3-a410-c80aa9c604af} - E:\LGAutoRun.exe
HKU\S-1-5-21-1327258627-3190711363-1570324734-1000\...\MountPoints2: {dfa1a884-6240-11e1-9a0e-c80aa9c604af} - "G:\WD SmartWare.exe" autoplay=true
AppInit_DLLs: C:\PROGRA~3\WINFIL~1\WINFIL~2.DLL => C:\ProgramData\WinFilter\WinFilter_x64.dll [4356096 2014-01-11] ()
AppInit_DLLs-x32: c:\progra~2\citrix\icacli~1\rshook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257176 2012-04-05] (Citrix Systems, Inc.)
AppInit_DLLs-x32: c:\progra~3\winfil~1\winfil~1.dll => C:\ProgramData\WinFilter\WinFilter.dll [4157952 2014-01-11] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchpages.info/?unqvl=29
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5791k16r
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchpages.info/?unqvl=29
URLSearchHook: HKCU - (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT3072253
SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {9D4AD3AC-93CF-4D93-AC41-2A2276F0FB49} URL = http://websearch.ask.com/redirect?clien ... 4610E6D806
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT3072253
SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchpages.info/?unqv ... earchTerms}
BHO: WaottCChIatNoAds - {0933B14F-5321-C1CF-C48D-227E40B921CD} - C:\ProgramData\WaottCChIatNoAds\R4.x64.dll ()
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: FindBesitDeal - {D3920129-228B-804D-5E1F-BB7385D029EF} - C:\ProgramData\FindBesitDeal\y15_3C8Qzv.x64.dll ()
BHO-x32: WaottCChIatNoAds - {0933B14F-5321-C1CF-C48D-227E40B921CD} - C:\ProgramData\WaottCChIatNoAds\R4.dll ()
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: CtxIEInterceptorBHO Class - {2C4631FF-5CC8-4EBC-A0DF-34C92291759E} - C:\Program Files (x86)\Citrix\ICA Client\IEInterceptor.dll (Citrix Systems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: FindBesitDeal - {D3920129-228B-804D-5E1F-BB7385D029EF} - C:\ProgramData\FindBesitDeal\y15_3C8Qzv.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default
FF user.js: detected! => C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\user.js
FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", "");
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://websearch.searchpages.info/?unqvl=29&l=1&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Citrix.com/npican - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Acer\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Acer\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\searchplugins\WebSearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WaottCChIatNoAds - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\joajau@ao-vfsw.edu [2014-01-31]
FF Extension: FindBesitDeal - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\rfzj@ioooouou.net [2014-03-06]
FF Extension: Garmin Communicator - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-20]
FF Extension: Seznam lištička - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-29]
FF Extension: Adblock Plus - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\mtw0xyie.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-02-20]
Chrome:
=======
CHR HomePage: hxxp://websearch.searchpages.info/?unqvl=29
CHR RestoreOnStartup: "hxxp://websearch.searchpages.info/?unqvl=29"
CHR DefaultSearchKeyword: websearch
CHR DefaultSearchProvider: WebSearch
CHR DefaultSearchURL: http://websearch.searchpages.info/?unqv ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Acer\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Citrix ICA Client) - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Acer\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-18]
CHR Extension: (Vyhledvn Google) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-18]
CHR Extension: (WaottCChIatNoAds) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdklgkmdncckfacndpfdkcfodaagjlmk [2014-03-27]
CHR Extension: (GreaatSave4U) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhdpmggjjdokaplmejdngeggfdkkknbb [2014-01-12]
CHR Extension: (Peněženka Google) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-29]
CHR Extension: (FindBesitDeal) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\opbeehcldpcflbapodnleajdikeeagka [2014-03-06]
CHR Extension: (uTorrentControl2) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc [2012-06-22]
CHR Extension: (Gmail) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-18]
CHR Extension: (JoniCouPon) - C:\ProgramData\ikialoaigjekepdfkpiahljfkchcflfd [2014-01-12]
CHR HKCU\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Acer\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-06-07]
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Acer\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-06-07]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 03e661da; C:\ProgramData\WinFilter\WinFilterSvc.dll [178512 2014-01-11] ()
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-04-23] (Acer Incorporated)
S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [375176 2011-10-09] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-04-17] (Egis Technology Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-08-19] (DT Soft Ltd)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-12-15] (Huawei Technologies Co., Ltd.)
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [29696 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-12-15] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 Andbus; system32\DRIVERS\lgandbus64.sys [X]
S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X]
S3 AndGps; system32\DRIVERS\lgandgps64.sys [X]
S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtpt64.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbs64.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmdm64.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-28 19:52 - 2014-03-28 19:53 - 00030096 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-03-28 19:51 - 2014-03-28 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-03-28 19:50 - 2014-03-28 19:52 - 00000000 ____D () C:\FRST
2014-03-28 19:49 - 2014-03-28 19:49 - 02157056 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-03-28 19:05 - 2014-03-28 19:12 - 00000000 ____D () C:\Users\Acer\Downloads\Her.2013.DVDSCR.XviD.MP3-RARBG
2014-03-27 19:32 - 2014-03-27 21:55 - 00000000 ____D () C:\Users\Acer\Documents\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:32 - 00000000 ____D () C:\Program Files\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:31 - 00000800 _____ () C:\Users\Public\Desktop\OpenTTD.lnk
2014-03-25 21:38 - 2014-03-25 21:53 - 371878445 _____ () C:\Users\Acer\Downloads\Vikings.S02E04.HDTV.x264-KILLERS.mp4
2014-03-25 21:38 - 2014-03-25 21:42 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E03 HDTV x264-KILLERS[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E02 HDTV x264-EXCELLENCE[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E01 HDTV x264-EXCELLENCE[ettv]
2014-03-25 00:41 - 2014-03-25 00:41 - 00031179 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x04(0000072184).srt
2014-03-25 00:40 - 2014-03-25 00:40 - 00029660 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x03(0000072018).srt
2014-03-25 00:39 - 2014-03-25 00:39 - 00039033 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x02-Work-Experience(0000063307).srt
2014-03-24 18:56 - 2014-03-24 18:56 - 00029308 _____ () C:\Users\Acer\Downloads\The-Office-US-02x01-The-Dundies(0000088947).srt
2014-03-23 19:06 - 2014-03-23 19:06 - 00000000 ____D () C:\Users\Acer\Downloads\Anchorman 2 The Legend Continues [2013] HDRip XViD juggs[ETRG]
2014-03-23 19:05 - 2014-03-23 19:34 - 00000000 ____D () C:\Users\Acer\Downloads\The Hobbit The Desolation of Smaug (2013) [1080p]
2014-03-22 11:20 - 2014-03-22 11:20 - 00000706 _____ () C:\Windows\PFRO.log
2014-03-22 01:44 - 2014-03-22 01:44 - 00030144 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x01(0000071553).srt
2014-03-21 18:30 - 2014-03-28 16:57 - 00004312 _____ () C:\Windows\setupact.log
2014-03-21 18:30 - 2014-03-21 18:30 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-21 17:21 - 2014-03-28 19:42 - 00308652 _____ () C:\Windows\WindowsUpdate.log
2014-03-14 18:43 - 2014-03-14 18:43 - 00003028 _____ () C:\Windows\System32\Tasks\{A1967811-C67D-4DDA-94D5-A9F96A9B0FB0}
2014-03-14 18:38 - 2014-03-14 18:42 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 18:38 - 2014-03-14 18:42 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 18:38 - 2014-03-14 18:42 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 17:29 - 2014-03-14 17:33 - 00000000 ____D () C:\Program Files (x86)\Spawn
2014-03-14 17:09 - 2014-03-14 17:11 - 00000000 ____D () C:\Users\Acer\Downloads\The Office (UK) Series 1 + 2 Christmas Specials And Extras
2014-03-08 18:07 - 2014-03-08 18:07 - 00096678 _____ () C:\Users\Acer\Downloads\Futurama-Into-the-Wild-Green-Yonder(0000126129).srt
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{E1F4B145-E903-4F36-A2AC-970F9C4D5F62}
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{74AB941E-BF69-4735-8982-3B619A505EEC}
2014-03-06 22:54 - 2014-03-06 22:55 - 00000000 ____D () C:\ProgramData\FindBesitDeal
2014-03-05 17:52 - 2014-03-05 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-04 23:54 - 2014-03-04 23:54 - 00000014 _____ () C:\Users\Acer\Desktop\sex.txt
2014-03-02 09:41 - 2014-03-02 09:45 - 00000000 ____D () C:\Users\Acer\Downloads\Blade.Runner (1997)
2014-02-28 21:31 - 2014-02-28 22:10 - 00000000 ____D () C:\Program Files (x86)\battlefield
==================== One Month Modified Files and Folders =======
2014-03-28 19:53 - 2014-03-28 19:52 - 00030096 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-03-28 19:52 - 2014-03-28 19:50 - 00000000 ____D () C:\FRST
2014-03-28 19:51 - 2014-03-28 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-03-28 19:50 - 2011-01-12 19:00 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\uTorrent
2014-03-28 19:49 - 2014-03-28 19:49 - 02157056 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-03-28 19:42 - 2014-03-21 17:21 - 00308652 _____ () C:\Windows\WindowsUpdate.log
2014-03-28 19:13 - 2013-05-29 16:03 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-28 19:13 - 2012-06-18 17:42 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000UA.job
2014-03-28 19:12 - 2014-03-28 19:05 - 00000000 ____D () C:\Users\Acer\Downloads\Her.2013.DVDSCR.XviD.MP3-RARBG
2014-03-28 18:13 - 2012-06-18 17:42 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000Core.job
2014-03-28 17:04 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-28 17:04 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-28 16:57 - 2014-03-21 18:30 - 00004312 _____ () C:\Windows\setupact.log
2014-03-28 16:57 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-27 22:33 - 2010-12-23 14:09 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AADA1DE1-C4EA-4E45-B845-2B3562A555BF}
2014-03-27 21:55 - 2014-03-27 19:32 - 00000000 ____D () C:\Users\Acer\Documents\OpenTTD
2014-03-27 19:32 - 2014-03-27 19:31 - 00000000 ____D () C:\Program Files\OpenTTD
2014-03-27 19:31 - 2014-03-27 19:31 - 00000800 _____ () C:\Users\Public\Desktop\OpenTTD.lnk
2014-03-27 18:18 - 2012-06-19 19:09 - 00000000 ____D () C:\Users\Acer\AppData\Local\Conduit
2014-03-26 17:49 - 2012-05-01 10:06 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-26 17:48 - 2012-03-31 14:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-26 17:48 - 2012-03-31 14:29 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-25 21:53 - 2014-03-25 21:38 - 371878445 _____ () C:\Users\Acer\Downloads\Vikings.S02E04.HDTV.x264-KILLERS.mp4
2014-03-25 21:42 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E03 HDTV x264-KILLERS[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E02 HDTV x264-EXCELLENCE[ettv]
2014-03-25 21:38 - 2014-03-25 21:38 - 00000000 ____D () C:\Users\Acer\Downloads\Vikings S02E01 HDTV x264-EXCELLENCE[ettv]
2014-03-25 00:41 - 2014-03-25 00:41 - 00031179 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x04(0000072184).srt
2014-03-25 00:40 - 2014-03-25 00:40 - 00029660 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x03(0000072018).srt
2014-03-25 00:39 - 2014-03-25 00:39 - 00039033 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x02-Work-Experience(0000063307).srt
2014-03-24 18:56 - 2014-03-24 18:56 - 00029308 _____ () C:\Users\Acer\Downloads\The-Office-US-02x01-The-Dundies(0000088947).srt
2014-03-23 19:34 - 2014-03-23 19:05 - 00000000 ____D () C:\Users\Acer\Downloads\The Hobbit The Desolation of Smaug (2013) [1080p]
2014-03-23 19:06 - 2014-03-23 19:06 - 00000000 ____D () C:\Users\Acer\Downloads\Anchorman 2 The Legend Continues [2013] HDRip XViD juggs[ETRG]
2014-03-23 12:49 - 2014-01-29 11:00 - 00002000 ____H () C:\Users\Acer\Documents\Default.rdp
2014-03-22 11:20 - 2014-03-22 11:20 - 00000706 _____ () C:\Windows\PFRO.log
2014-03-22 01:44 - 2014-03-22 01:44 - 00030144 _____ () C:\Users\Acer\Downloads\The-Office-UK-02x01(0000071553).srt
2014-03-21 18:30 - 2014-03-21 18:30 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-18 18:03 - 2013-08-11 22:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 18:00 - 2010-12-17 14:00 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 21:43 - 2011-02-25 20:30 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-03-17 21:41 - 2013-03-14 22:51 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-17 21:41 - 2013-03-14 22:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-17 00:06 - 2010-08-24 12:47 - 00631526 _____ () C:\Windows\system32\perfh005.dat
2014-03-17 00:06 - 2010-08-24 12:47 - 00122148 _____ () C:\Windows\system32\perfc005.dat
2014-03-17 00:06 - 2009-07-14 06:13 - 01470298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-17 00:05 - 2010-12-27 11:49 - 00000000 ____D () C:\Users\Acer\Documents\knížky
2014-03-14 18:43 - 2014-03-14 18:43 - 00003028 _____ () C:\Windows\System32\Tasks\{A1967811-C67D-4DDA-94D5-A9F96A9B0FB0}
2014-03-14 18:42 - 2014-03-14 18:38 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 18:42 - 2014-03-14 18:38 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 18:42 - 2014-03-14 18:38 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 18:38 - 2012-06-04 07:25 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-14 18:27 - 2013-05-10 21:55 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\AIMP3
2014-03-14 17:33 - 2014-03-14 17:29 - 00000000 ____D () C:\Program Files (x86)\Spawn
2014-03-14 17:11 - 2014-03-14 17:09 - 00000000 ____D () C:\Users\Acer\Downloads\The Office (UK) Series 1 + 2 Christmas Specials And Extras
2014-03-14 06:08 - 2013-03-11 17:42 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-14 06:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-13 22:14 - 2013-05-29 16:03 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-13 22:14 - 2013-03-11 17:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-13 22:14 - 2011-07-17 18:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-13 21:09 - 2010-12-17 18:19 - 00000000 ____D () C:\Users\Acer
2014-03-11 09:52 - 2011-04-27 14:25 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys
2014-03-09 14:49 - 2010-12-27 11:50 - 00000000 ____D () C:\Users\Acer\Documents\recepty
2014-03-08 18:07 - 2014-03-08 18:07 - 00096678 _____ () C:\Users\Acer\Downloads\Futurama-Into-the-Wild-Green-Yonder(0000126129).srt
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{E1F4B145-E903-4F36-A2AC-970F9C4D5F62}
2014-03-08 17:14 - 2014-03-08 17:14 - 00003070 _____ () C:\Windows\System32\Tasks\{74AB941E-BF69-4735-8982-3B619A505EEC}
2014-03-08 17:05 - 2011-02-06 17:54 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-08 16:48 - 2010-12-27 18:09 - 00063160 _____ () C:\Users\Acer\AppData\Roaming\GDIPFONTCACHEV1.DAT
2014-03-06 22:55 - 2014-03-06 22:54 - 00000000 ____D () C:\ProgramData\FindBesitDeal
2014-03-06 22:55 - 2014-01-12 13:18 - 00000000 ____D () C:\ProgramData\32da34b8ed9c5e86
2014-03-05 17:52 - 2014-03-05 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-05 17:52 - 2010-12-26 19:25 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-05 17:52 - 2010-12-26 19:25 - 00000000 ____D () C:\ProgramData\Skype
2014-03-04 23:54 - 2014-03-04 23:54 - 00000014 _____ () C:\Users\Acer\Desktop\sex.txt
2014-03-02 22:01 - 2014-01-31 22:15 - 00000000 ____D () C:\Users\Acer\Downloads\The.Counselor.2013.UNRATED.HDRip XViD NO1KNOWS
2014-03-02 09:45 - 2014-03-02 09:41 - 00000000 ____D () C:\Users\Acer\Downloads\Blade.Runner (1997)
2014-02-28 22:10 - 2014-02-28 21:31 - 00000000 ____D () C:\Program Files (x86)\battlefield
2014-02-28 22:08 - 2011-01-14 20:32 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000Core.job => C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1327258627-3190711363-1570324734-1000UA.job => C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:798A3728
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:93EB7685
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:AEBFFE08
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E36F5B57
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Acer\Desktop" je 9133 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AthBtTray
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtherosBtStack
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ConnectionCenter
"C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Garmin Lifetime Updater
C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
"C:\Program Files (x86)\ASUSTek\ASUSDVD\PDVDServ.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk
C:\PROGRA~2\Acer\ACERVC~1\AcerVCM.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Acer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk
C:\PROGRA~2\Evernote\Evernote\EVERNO~2.EXE [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
děkuji za pomoc
olda