pozor, E:\ je virtuální mechanika, flashka je G:\. ale jak říkám - já se pokušel o čištění už sám, než jsem našel tohle vlákno. takže PC už jsem projel adwCleanerem a JRT (mám i uložené logy) a pak ještě Microsoft Security Essentials (na nějakém eng fóru psali, žeprý je schopný vir najít a vymazat) a taky ještě nějakou utilitkou pro USB jejíž jméno si už žel nepamatuju (tady už logy nemám, ale u všech proběhly scany a čištění)
tady je FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Murdoc (administrator) on MURDOC-NTB on 23-04-2014 13:02:17
Running from C:\Users\Murdoc\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenManagerService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Murdoc\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
(Dropbox, Inc.) C:\Users\Murdoc\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
() C:\Program Files (x86)\Opera\20.0.1387.91\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
() C:\Program Files (x86)\foobar2000\foobar2000.exe
(Last.fm) C:\Program Files (x86)\Last.fm\Last.fm Scrobbler.exe
(forum.viry.cz) C:\Users\Murdoc\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FileOpenBroker] => C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [1092528 2012-10-17] (FileOpen Systems Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2809856 2012-01-16] (ELAN Microelectronics Corp.)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6202416 2012-08-07] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-08-07] (Lenovo (Beijing) Limited)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2011-12-15] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4297136 2012-10-31] (AVAST Software)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-26] ( )
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-30] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-21] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207360 2010-03-18] (ArcSoft Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [687336 2013-06-20] (Zbshareware Lab)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.)
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-08-07] (Google Inc.)
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\Run: [Spotify Web Helper] => C:\Users\Murdoc\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-20] (Spotify Ltd)
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.)
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\Policies\Explorer: []
HKU\S-1-5-21-673523585-3230307534-867329203-1001\...\MountPoints2: {77761f27-1ed1-11e2-a4a0-08edb9a70762} - E:\Setup.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [205184 2013-02-10] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\Murdoc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Murdoc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Murdoc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.google.com/ig/redirectdomain ... &bmod=KMOH
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_search_url =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search bar =
http://search.msn.com/spbasic.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages =
SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?sourceid=i ... OH_csCZ506
SearchScopes: HKCU - ${searchCLSID} URL =
http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?sourceid=i ... OH_csCZ506
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{53287C29-BC37-4883-924D-DF69F50744FD}: [NameServer]192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Murdoc\AppData\Roaming\Mozilla\Firefox\Profiles\i3b3fo04.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=1.6.0_38 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Murdoc\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Media Stealer - C:\Users\Murdoc\AppData\Roaming\Mozilla\Firefox\Profiles\i3b3fo04.default\Extensions\
stealer@physacco.com.xpi [2013-09-09]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} [2014-03-24]
FF HKLM-x32\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-10-16]
Chrome:
=======
CHR HomePage:
CHR Extension: (avast! WebRep) - C:\Users\Murdoc\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda [2013-11-10]
CHR Extension: (Web Navigation) - C:\Users\Murdoc\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkemddiljapcmhicklfpcbpfffahfbja [2014-04-22]
CHR Extension: (Peněženka Google) - C:\Users\Murdoc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-10]
CHR Extension: (No Name) - C:\Users\Murdoc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2013-11-10]
CHR HKLM-x32\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2012-10-16]
CHR HKLM-x32\...\Chrome\Extension: [lkemddiljapcmhicklfpcbpfffahfbja] - C:\Users\Murdoc\AppData\Local\Google\Chrome\User Data\Default\extensions\WebNavigation.crx [2014-04-19]
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-10-31] (AVAST Software)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-02] (Broadcom Corporation.)
S4 DamageGuardSvc; C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe [572976 2012-03-26] (Lenovo (Beijing) Limited)
R2 FileOpenManagerService; C:\Program Files\FileOpen\Services\FileOpenManagerService64.exe [335288 2012-10-17] (FileOpen Systems Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-02-26] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [71600 2012-10-31] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-31] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-31] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-10-31] (AVAST Software)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-10-28] ()
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.)
S4 DamageGuard; C:\Windows\System32\DRIVERS\DamageGuardX64.sys [217392 2012-02-11] (Lenovo)
S4 dgFltr; C:\Windows\System32\drivers\dgFltrX64.sys [23648 2011-12-13] (Lenovo)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-28] (DT Soft Ltd)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2014-02-12] (ITE )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-10-28] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () <===== ATTENTION Necurs Rootkit?
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation)
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [97792 2011-09-22] (WIBU-SYSTEMS AG)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-23 13:02 - 2014-04-23 13:02 - 00024148 _____ () C:\Users\Murdoc\Desktop\FRST.txt
2014-04-23 13:01 - 2014-04-23 13:02 - 00000000 ____D () C:\FRST
2014-04-23 13:00 - 2014-04-23 13:00 - 00112640 _____ (forum.viry.cz) C:\Users\Murdoc\Desktop\FRSTLauncher.exe
2014-04-23 12:53 - 2014-04-23 12:53 - 02061312 _____ (Farbar) C:\Users\Murdoc\Desktop\FRST64.exe
2014-04-23 00:01 - 2014-04-23 00:01 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zařízení Bluetooth
2014-04-22 23:53 - 2014-04-22 23:53 - 00013722 _____ () C:\Users\Murdoc\Desktop\UsbFix [Clean 3] MURDOC-NTB.txt
2014-04-22 23:35 - 2014-04-22 23:52 - 00013722 _____ () C:\UsbFix [Clean 3] MURDOC-NTB.txt
2014-04-22 18:47 - 2014-04-22 18:47 - 00003089 _____ () C:\Users\Murdoc\Desktop\AdwCleaner[S0].txt
2014-04-22 18:38 - 2014-04-22 18:40 - 00000000 ____D () C:\AdwCleaner
2014-04-22 18:28 - 2014-04-22 18:28 - 00002769 _____ () C:\Users\Murdoc\Desktop\JRT.txt
2014-04-22 18:12 - 2014-04-22 18:12 - 00000000 ____D () C:\Windows\ERUNT
2014-04-22 17:56 - 2014-04-22 17:56 - 00010942 ____N () C:\UsbFix [Clean 2] MURDOC-NTB.txt
2014-04-22 17:33 - 2014-04-22 23:41 - 00000000 ____D () C:\UsbFix
2014-04-22 17:33 - 2014-04-22 17:34 - 00011768 ____N () C:\UsbFix [Clean 1] MURDOC-NTB.txt
2014-04-19 19:41 - 2014-04-19 19:41 - 00001081 _____ () C:\Users\Public\Desktop\USB Disk Security.lnk
2014-04-19 19:41 - 2014-04-19 19:41 - 00001069 _____ () C:\Users\Public\Desktop\Web Navigation.lnk
2014-04-19 19:41 - 2014-04-19 19:41 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Zbshareware Lab
2014-04-19 19:41 - 2014-04-19 19:41 - 00000000 ____D () C:\Program Files (x86)\USB Disk Security
2014-04-19 18:34 - 2014-04-22 11:28 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-18 19:29 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-18 19:29 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-18 19:29 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-18 19:29 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-18 19:28 - 2014-04-18 19:29 - 00005293 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 13:27 - 2014-04-18 13:27 - 04461568 _____ () C:\Users\Murdoc\Downloads\22D9.tmp
2014-04-17 11:53 - 2014-04-17 11:53 - 00010792 _____ () C:\Users\Murdoc\Desktop\Uem.xlsx
2014-04-12 18:00 - 2014-04-19 17:45 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Windows Live
2014-04-09 21:23 - 2014-04-09 21:23 - 00001069 _____ () C:\Users\Public\Desktop\ArchiCAD 16.lnk
2014-04-09 20:55 - 2011-12-16 05:40 - 00471952 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WibuXpm4J64.dll
2014-04-09 20:55 - 2011-12-16 05:40 - 00375184 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WibuXpm4J32.dll
2014-04-09 20:55 - 2009-12-03 07:00 - 00430080 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\wibuKJni64.dll
2014-04-09 20:55 - 2009-12-03 07:00 - 00418304 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkExt64.dll
2014-04-09 20:55 - 2009-12-03 07:00 - 00344576 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\wibuKJni.dll
2014-04-09 20:55 - 2009-12-03 07:00 - 00333824 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkExt32.dll
2014-04-09 20:55 - 2009-12-03 07:00 - 00022528 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.lde
2014-04-09 20:55 - 2009-12-03 07:00 - 00022528 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.lde
2014-04-09 20:55 - 2009-12-03 07:00 - 00022016 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.lfr
2014-04-09 20:55 - 2009-12-03 07:00 - 00022016 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.les
2014-04-09 20:55 - 2009-12-03 07:00 - 00022016 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.lbr
2014-04-09 20:55 - 2009-12-03 07:00 - 00022016 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.lfr
2014-04-09 20:55 - 2009-12-03 07:00 - 00022016 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.les
2014-04-09 20:55 - 2009-12-03 07:00 - 00021504 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.lit
2014-04-09 20:55 - 2009-12-03 07:00 - 00021504 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.lit
2014-04-09 20:55 - 2009-12-03 07:00 - 00020992 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.ljp
2014-04-09 20:55 - 2009-12-03 07:00 - 00020992 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.ljp
2014-04-09 20:55 - 2009-12-03 07:00 - 00020480 _____ () C:\Windows\SysWOW64\WkWin32.lhu
2014-04-09 20:55 - 2009-12-03 07:00 - 00020480 _____ () C:\Windows\system32\WkWin64.lhu
2014-04-09 20:55 - 2009-12-03 07:00 - 00015360 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.lcn
2014-04-09 20:55 - 2009-12-03 07:00 - 00015360 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.lcn
2014-04-09 20:54 - 2014-04-09 20:54 - 00000000 ____D () C:\Program Files\WIBU-SYSTEMS
2014-04-09 20:54 - 2014-04-09 20:54 - 00000000 ____D () C:\Program Files (x86)\WIBU-SYSTEMS
2014-04-09 20:54 - 2011-09-22 06:00 - 00097792 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\Drivers\WibuKey64.sys
2014-04-09 20:54 - 2009-12-03 07:00 - 00169984 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\WkWin64.dll
2014-04-09 20:54 - 2009-12-03 07:00 - 00150528 _____ (WIBU-SYSTEMS AG) C:\Windows\SysWOW64\WkWin32.dll
2014-04-09 20:54 - 2009-08-07 09:59 - 00016896 _____ (WIBU-SYSTEMS AG) C:\Windows\system32\Drivers\Wibukey2_64.sys
2014-04-07 23:02 - 2014-04-07 23:03 - 17293904 _____ () C:\Users\Murdoc\Documents\DIPLOMKA STUDIE 2.skp
2014-04-06 21:21 - 2014-04-06 21:21 - 00000000 ____D () C:\Program Files\Uninstall.AC
2014-04-06 20:52 - 2014-04-23 00:00 - 00001530 _____ () C:\Windows\setupact.log
2014-04-06 20:52 - 2014-04-19 18:50 - 00001268 _____ () C:\Windows\PFRO.log
2014-04-06 20:52 - 2014-04-06 20:52 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-06 19:13 - 2014-04-06 19:13 - 00001544 _____ () C:\Users\Murdoc\Desktop\Artlantis Studio.lnk
2014-03-28 13:28 - 2014-03-28 13:28 - 00001987 _____ () C:\Users\Murdoc\Desktop\ArchiCAD 17.lnk
2014-03-28 09:58 - 2014-03-28 10:02 - 00000000 ____D () C:\Program Files (x86)\PDF Editor 4
2014-03-28 09:58 - 2014-03-28 09:58 - 00082072 _____ () C:\Windows\cadkasdeinst01e.exe
2014-03-28 09:58 - 2014-03-28 09:58 - 00001041 _____ () C:\Users\UpdatusUser\Desktop\PDF Editor 3.3.lnk
2014-03-28 09:58 - 2014-03-28 09:58 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\CAD-KAS
2014-03-25 18:27 - 2014-03-25 18:27 - 00046450 _____ () C:\Users\Public\Documents\cc_20140325_172701.reg
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-03-25 10:58 - 2014-03-25 10:59 - 00062790 _____ () C:\Users\Murdoc\AppData\Local\1395737931063usageLogSubmitter.log
==================== One Month Modified Files and Folders =======
2014-04-23 13:03 - 2012-10-20 10:16 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Last.fm
2014-04-23 13:02 - 2014-04-23 13:02 - 00024148 _____ () C:\Users\Murdoc\Desktop\FRST.txt
2014-04-23 13:02 - 2014-04-23 13:01 - 00000000 ____D () C:\FRST
2014-04-23 13:00 - 2014-04-23 13:00 - 00112640 _____ (forum.viry.cz) C:\Users\Murdoc\Desktop\FRSTLauncher.exe
2014-04-23 13:00 - 2012-08-06 23:14 - 01914233 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 12:53 - 2014-04-23 12:53 - 02061312 _____ (Farbar) C:\Users\Murdoc\Desktop\FRST64.exe
2014-04-23 12:33 - 2012-08-07 00:06 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-23 12:06 - 2012-10-16 12:18 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 00:07 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 00:07 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 00:01 - 2014-04-23 00:01 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zařízení Bluetooth
2014-04-23 00:01 - 2013-01-06 18:08 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Dropbox
2014-04-23 00:00 - 2014-04-06 20:52 - 00001530 _____ () C:\Windows\setupact.log
2014-04-23 00:00 - 2013-06-24 20:31 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\LogMeIn Hamachi
2014-04-22 23:55 - 2012-08-07 00:06 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-22 23:54 - 2012-10-18 14:43 - 00000292 _____ () C:\Windows\Tasks\AutoKMS.job
2014-04-22 23:54 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-22 23:53 - 2014-04-22 23:53 - 00013722 _____ () C:\Users\Murdoc\Desktop\UsbFix [Clean 3] MURDOC-NTB.txt
2014-04-22 23:52 - 2014-04-22 23:35 - 00013722 _____ () C:\UsbFix [Clean 3] MURDOC-NTB.txt
2014-04-22 23:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-22 23:41 - 2014-04-22 17:33 - 00000000 ____D () C:\UsbFix
2014-04-22 23:41 - 2013-08-27 15:57 - 00150016 ___SH () C:\Users\Murdoc\Desktop\Thumbs.db
2014-04-22 23:33 - 2012-10-20 10:00 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\foobar2000
2014-04-22 19:12 - 2012-10-16 22:26 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\vlc
2014-04-22 18:47 - 2014-04-22 18:47 - 00003089 _____ () C:\Users\Murdoc\Desktop\AdwCleaner[S0].txt
2014-04-22 18:40 - 2014-04-22 18:38 - 00000000 ____D () C:\AdwCleaner
2014-04-22 18:28 - 2014-04-22 18:28 - 00002769 _____ () C:\Users\Murdoc\Desktop\JRT.txt
2014-04-22 18:12 - 2014-04-22 18:12 - 00000000 ____D () C:\Windows\ERUNT
2014-04-22 17:56 - 2014-04-22 17:56 - 00010942 ____N () C:\UsbFix [Clean 2] MURDOC-NTB.txt
2014-04-22 17:34 - 2014-04-22 17:33 - 00011768 ____N () C:\UsbFix [Clean 1] MURDOC-NTB.txt
2014-04-22 11:28 - 2014-04-19 18:34 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-19 19:41 - 2014-04-19 19:41 - 00001081 _____ () C:\Users\Public\Desktop\USB Disk Security.lnk
2014-04-19 19:41 - 2014-04-19 19:41 - 00001069 _____ () C:\Users\Public\Desktop\Web Navigation.lnk
2014-04-19 19:41 - 2014-04-19 19:41 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Zbshareware Lab
2014-04-19 19:41 - 2014-04-19 19:41 - 00000000 ____D () C:\Program Files (x86)\USB Disk Security
2014-04-19 19:40 - 2012-10-16 15:52 - 00000000 ____D () C:\- MOJE -
2014-04-19 18:50 - 2014-04-06 20:52 - 00001268 _____ () C:\Windows\PFRO.log
2014-04-19 18:42 - 2012-10-16 11:56 - 00000000 ___RD () C:\Users\Murdoc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 17:45 - 2014-04-12 18:00 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Windows Live
2014-04-18 19:30 - 2013-12-12 22:44 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 19:29 - 2014-04-18 19:28 - 00005293 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 19:29 - 2012-10-16 16:10 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-18 13:27 - 2014-04-18 13:27 - 04461568 _____ () C:\Users\Murdoc\Downloads\22D9.tmp
2014-04-17 11:53 - 2014-04-17 11:53 - 00010792 _____ () C:\Users\Murdoc\Desktop\Uem.xlsx
2014-04-15 14:37 - 2012-10-16 22:05 - 00000000 ____D () C:\Users\Murdoc\Graphisoft
2014-04-15 11:01 - 2012-08-06 22:57 - 00669736 _____ () C:\Windows\system32\perfh005.dat
2014-04-15 11:01 - 2012-08-06 22:57 - 00141336 _____ () C:\Windows\system32\perfc005.dat
2014-04-15 11:01 - 2009-07-14 07:13 - 01585238 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-14 20:13 - 2014-04-18 19:29 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-04-18 19:29 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-04-18 19:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-04-18 19:29 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 07:59 - 2012-10-16 22:56 - 00000000 ____D () C:\Users\Murdoc\Documents\BIMx
2014-04-10 08:08 - 2013-11-10 17:15 - 00002194 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-09 21:32 - 2012-10-16 22:05 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Graphisoft
2014-04-09 21:30 - 2012-10-16 16:16 - 00015406 _____ () C:\Windows\vpd.properties
2014-04-09 21:28 - 2012-10-16 16:10 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Install.GS
2014-04-09 21:23 - 2014-04-09 21:23 - 00001069 _____ () C:\Users\Public\Desktop\ArchiCAD 16.lnk
2014-04-09 20:55 - 2012-10-16 22:55 - 00000000 ____D () C:\Program Files (x86)\GRAPHISOFT
2014-04-09 20:55 - 2012-10-16 22:52 - 00000000 ____D () C:\Program Files\GRAPHISOFT
2014-04-09 20:54 - 2014-04-09 20:54 - 00000000 ____D () C:\Program Files\WIBU-SYSTEMS
2014-04-09 20:54 - 2014-04-09 20:54 - 00000000 ____D () C:\Program Files (x86)\WIBU-SYSTEMS
2014-04-09 20:54 - 2012-10-17 10:38 - 00000000 ____D () C:\Program Files (x86)\WIBUKEY
2014-04-09 20:36 - 2014-02-12 16:49 - 00000000 ____D () C:\ProgramData\ArcSoft
2014-04-08 14:42 - 2013-11-02 00:22 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\qtscrob
2014-04-08 09:44 - 2014-02-24 22:05 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\cache
2014-04-08 09:44 - 2013-11-18 23:24 - 00112582 _____ () C:\Windows\system32\webservice4.log
2014-04-07 23:03 - 2014-04-07 23:02 - 17293904 _____ () C:\Users\Murdoc\Documents\DIPLOMKA STUDIE 2.skp
2014-04-06 21:24 - 2013-06-03 13:50 - 00000000 ____D () C:\Program Files\Artlantis Studio 4
2014-04-06 21:21 - 2014-04-06 21:21 - 00000000 ____D () C:\Program Files\Uninstall.AC
2014-04-06 20:59 - 2013-12-01 11:07 - 00000054 _____ () C:\Users\Murdoc\Desktop\dary.txt
2014-04-06 20:52 - 2014-04-06 20:52 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-06 20:52 - 2013-07-27 08:49 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-06 20:52 - 2012-08-06 23:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-06 19:13 - 2014-04-06 19:13 - 00001544 _____ () C:\Users\Murdoc\Desktop\Artlantis Studio.lnk
2014-04-03 23:36 - 2012-10-16 12:15 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-04-03 13:28 - 2012-08-07 00:06 - 00003962 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 13:28 - 2012-08-07 00:06 - 00003710 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-02 23:27 - 2012-10-16 12:03 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Adobe
2014-03-30 23:17 - 2013-12-16 09:16 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Spotify
2014-03-30 23:06 - 2012-10-16 17:37 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\Skype
2014-03-30 17:52 - 2012-10-16 22:05 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Graphisoft
2014-03-28 13:28 - 2014-03-28 13:28 - 00001987 _____ () C:\Users\Murdoc\Desktop\ArchiCAD 17.lnk
2014-03-28 10:02 - 2014-03-28 09:58 - 00000000 ____D () C:\Program Files (x86)\PDF Editor 4
2014-03-28 09:58 - 2014-03-28 09:58 - 00082072 _____ () C:\Windows\cadkasdeinst01e.exe
2014-03-28 09:58 - 2014-03-28 09:58 - 00001041 _____ () C:\Users\UpdatusUser\Desktop\PDF Editor 3.3.lnk
2014-03-28 09:58 - 2014-03-28 09:58 - 00000000 ____D () C:\Users\Murdoc\AppData\Roaming\CAD-KAS
2014-03-25 18:27 - 2014-03-25 18:27 - 00046450 _____ () C:\Users\Public\Documents\cc_20140325_172701.reg
2014-03-25 18:25 - 2011-02-24 19:03 - 00000000 ____D () C:\Windows\Panther
2014-03-25 18:24 - 2012-11-22 09:20 - 00000833 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-25 18:24 - 2012-11-22 09:20 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-03-25 10:59 - 2014-03-25 10:58 - 00062790 _____ () C:\Users\Murdoc\AppData\Local\1395737931063usageLogSubmitter.log
2014-03-24 14:23 - 2013-12-16 09:23 - 00000000 ____D () C:\Users\Murdoc\AppData\Local\Spotify
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.1932.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Murdoc\Desktop" je 3 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================