HTML/Fraud.BQ, Win32/InstallMonetizer.AQ a Win32/Hao123.A
Napsal: 24 kvě 2014 06:51
Ahoj, Eset mi zachytil a vyléčil tyto viry, ale od té doby je můj NTB zpomalený a nejdou spustit některé programy (např. CCleaner). Požádám Vás o kontrolu, zda v systému není ještě nějaká ta potvora. Díky...
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-05-2014
Ran by Acer (administrator) on ACERR-NTB on 24-05-2014 07:34:41
Running from C:\Users\Acer\Desktop
Platform: Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [10592256 2014-03-18] (Broadcom Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876304 2013-01-18] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13267016 2013-01-29] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1276488 2013-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-01-18] (IvoSoft)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4148664 2013-10-07] (ESET)
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2014-03-18] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL =
SearchScopes: HKCU - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL =
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default
FF Homepage: http://www.idnes.cz
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default\Extensions\cs@dictionaries.addons.mozilla.org [2014-03-21]
FF Extension: Adblock Plus - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-20]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: ESET Endpoint Security Extension - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2014-03-21]
==================== Services (Whitelisted) =================
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2012-10-01] (Broadcom Corporation.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-20] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-17] (Acer Incorporated)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [42048 2013-10-07] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1025584 2013-10-07] (ESET)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [191368 2013-10-07] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-01-18] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2014-03-18] (Dritek System INC.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [6068736 2014-03-18] (Broadcom Corporation)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2012-10-01] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6835784 2012-10-13] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219184 2013-10-25] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [185224 2013-09-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [155896 2013-09-09] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [147096 2013-09-09] (ESET)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2014-03-18] (Dritek System Inc.)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-24 07:34 - 2014-05-24 07:34 - 00012369 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-05-24 07:34 - 2014-05-24 07:34 - 00000000 ____D () C:\FRST
2014-05-24 07:32 - 2014-05-24 07:32 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-05-24 07:28 - 2014-05-24 07:29 - 02067456 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-05-24 07:25 - 2014-05-24 07:32 - 00000000 ____D () C:\rsit
2014-05-24 07:25 - 2014-05-24 07:25 - 00000000 ____D () C:\Program Files\trend micro
2014-05-24 07:24 - 2014-05-24 07:24 - 00935175 _____ () C:\Users\Acer\Desktop\RSITx64.exe
2014-05-23 12:35 - 2014-05-23 17:17 - 00000000 ____D () C:\Users\Acer\Desktop\B958
2014-05-23 12:32 - 2014-05-23 12:33 - 00000000 ____D () C:\Users\Acer\Desktop\B958_Huawei
2014-05-23 12:29 - 2014-05-23 12:30 - 00000000 ____D () C:\Users\Acer\Desktop\B895
2014-05-22 20:41 - 2014-05-22 20:41 - 00000000 ____D () C:\Users\Acer\Desktop\B948 Sin
2014-05-22 19:25 - 2014-05-22 19:25 - 00000000 ____D () C:\Users\Acer\Desktop\B937
2014-05-21 19:12 - 2014-05-21 19:33 - 00000000 ____D () C:\Users\Acer\Documents\Wave
2014-05-21 12:24 - 2014-05-21 12:24 - 00000000 ____D () C:\Users\Acer\Desktop\B952 orig
2014-05-21 10:27 - 2014-05-21 10:27 - 00000000 ____D () C:\Users\Acer\Desktop\B894_2
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\Desktop\B894
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\AppData\Local\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\totalcmd
2014-05-21 08:13 - 2014-05-21 08:13 - 00000000 ____D () C:\Users\Acer\Desktop\B952
2014-05-21 07:52 - 2014-05-21 07:52 - 36283976 _____ () C:\Users\Acer\Desktop\HiSuiteSetup_v1.8.10.26.06.zip
2014-05-21 07:44 - 2014-05-21 07:44 - 00000000 ____D () C:\Users\Acer\Desktop\G300 downgrade
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Users\Acer\Documents\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-19 14:47 - 2014-05-24 07:18 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\pdfforge
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Local\ESET
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-19 14:47 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-19 14:47 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-19 14:47 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-19 14:47 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 10:46 - 2014-03-28 21:19 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-05-14 10:46 - 2014-03-28 10:23 - 19759104 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 10:46 - 2014-03-28 08:18 - 17562112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 10:46 - 2014-03-24 00:11 - 00269592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-05-14 10:45 - 2014-05-06 07:14 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 10:45 - 2014-05-06 07:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 10:45 - 2014-05-06 05:48 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 10:45 - 2014-05-06 05:48 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 10:45 - 2014-05-06 05:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 10:45 - 2014-05-06 05:26 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 10:45 - 2014-04-12 11:27 - 00172888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 10:45 - 2014-04-12 11:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 10:45 - 2014-04-12 11:09 - 01043968 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 10:45 - 2014-04-12 11:07 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00961536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 10:45 - 2014-04-12 09:22 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 10:45 - 2014-04-12 09:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 10:45 - 2014-04-12 08:58 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\workerdd.dll
2014-05-14 10:45 - 2014-03-28 10:23 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-05-14 10:45 - 2014-03-11 05:32 - 06987096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 10:45 - 2014-03-11 05:25 - 00100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 10:45 - 2014-03-11 02:41 - 00559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 10:45 - 2014-03-11 02:41 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 10:45 - 2014-03-11 02:41 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 10:45 - 2014-03-11 02:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 10:45 - 2014-03-11 02:38 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00419328 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 10:45 - 2014-03-10 05:05 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 10:45 - 2014-03-10 03:27 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 10:45 - 2014-03-04 01:07 - 00570216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-05-14 10:45 - 2014-03-01 11:47 - 01258496 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-05-14 10:45 - 2014-03-01 11:47 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2014-05-14 10:45 - 2014-03-01 10:07 - 01075200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2014-05-14 10:45 - 2014-03-01 08:59 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-05-14 10:45 - 2014-02-27 01:18 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-05-14 10:45 - 2014-02-15 06:15 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-05-14 10:10 - 2014-05-14 10:10 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-05-14 09:47 - 2014-05-14 09:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-05-14 09:46 - 2014-05-14 09:47 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2014-05-13 13:48 - 2014-05-13 13:48 - 00006144 _____ () C:\Users\Acer\Desktop\Ceny_štítek.xls
2014-05-12 11:18 - 2014-05-12 11:20 - 00044281 _____ () C:\Users\Acer\Desktop\Platby.ods
2014-05-10 10:24 - 2014-05-19 09:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 11:09 - 2014-05-14 08:48 - 00031232 _____ () C:\Users\Acer\Desktop\Zbozi_MO.xls
2014-05-07 09:18 - 2014-05-07 09:18 - 00061558 _____ () C:\Users\Acer\Desktop\Analýza dokladů.ods
2014-05-06 10:43 - 2014-04-19 11:39 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-05-06 10:43 - 2014-04-19 10:45 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-06 10:43 - 2014-04-19 10:45 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-06 10:43 - 2014-04-19 08:57 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-06 10:43 - 2014-04-19 08:57 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-05 08:15 - 2014-05-09 08:10 - 00020124 _____ () C:\Users\Acer\Desktop\Nesouhlas.odt
2014-04-29 10:44 - 2014-05-24 07:18 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-05-24 07:34 - 2014-05-24 07:34 - 00012369 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-05-24 07:34 - 2014-05-24 07:34 - 00000000 ____D () C:\FRST
2014-05-24 07:32 - 2014-05-24 07:32 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-05-24 07:32 - 2014-05-24 07:25 - 00000000 ____D () C:\rsit
2014-05-24 07:29 - 2014-05-24 07:28 - 02067456 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-05-24 07:25 - 2014-05-24 07:25 - 00000000 ____D () C:\Program Files\trend micro
2014-05-24 07:24 - 2014-05-24 07:24 - 00935175 _____ () C:\Users\Acer\Desktop\RSITx64.exe
2014-05-24 07:24 - 2014-03-20 15:55 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\ClassicShell
2014-05-24 07:18 - 2014-05-19 14:47 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-24 07:18 - 2014-04-29 10:44 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
2014-05-24 07:09 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-23 18:30 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-23 17:17 - 2014-05-23 12:35 - 00000000 ____D () C:\Users\Acer\Desktop\B958
2014-05-23 16:51 - 2014-03-18 00:41 - 00751374 _____ () C:\Windows\system32\perfh005.dat
2014-05-23 16:51 - 2014-03-18 00:41 - 00154566 _____ () C:\Windows\system32\perfc005.dat
2014-05-23 16:51 - 2012-07-26 09:28 - 01776480 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-23 14:48 - 2014-03-20 15:09 - 00000000 ____D () C:\Tim
2014-05-23 12:33 - 2014-05-23 12:32 - 00000000 ____D () C:\Users\Acer\Desktop\B958_Huawei
2014-05-23 12:30 - 2014-05-23 12:29 - 00000000 ____D () C:\Users\Acer\Desktop\B895
2014-05-23 06:29 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-23 06:28 - 2014-03-18 00:47 - 00053284 _____ () C:\Windows\system32\wpbbin.exe
2014-05-23 06:28 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-22 20:41 - 2014-05-22 20:41 - 00000000 ____D () C:\Users\Acer\Desktop\B948 Sin
2014-05-22 19:25 - 2014-05-22 19:25 - 00000000 ____D () C:\Users\Acer\Desktop\B937
2014-05-21 19:33 - 2014-05-21 19:12 - 00000000 ____D () C:\Users\Acer\Documents\Wave
2014-05-21 12:24 - 2014-05-21 12:24 - 00000000 ____D () C:\Users\Acer\Desktop\B952 orig
2014-05-21 10:27 - 2014-05-21 10:27 - 00000000 ____D () C:\Users\Acer\Desktop\B894_2
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\Desktop\B894
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\AppData\Local\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\totalcmd
2014-05-21 08:13 - 2014-05-21 08:13 - 00000000 ____D () C:\Users\Acer\Desktop\B952
2014-05-21 07:52 - 2014-05-21 07:52 - 36283976 _____ () C:\Users\Acer\Desktop\HiSuiteSetup_v1.8.10.26.06.zip
2014-05-21 07:44 - 2014-05-21 07:44 - 00000000 ____D () C:\Users\Acer\Desktop\G300 downgrade
2014-05-20 09:36 - 2014-03-20 15:10 - 00002120 _____ () C:\Users\Acer\Desktop\vision32.lnk
2014-05-20 09:36 - 2014-03-20 15:10 - 00002031 _____ () C:\Users\Acer\Desktop\Tim.lnk
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Users\Acer\Documents\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\pdfforge
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Local\ESET
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-19 09:21 - 2014-05-10 10:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-16 13:49 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-05-16 12:07 - 2014-03-18 18:29 - 00000000 ___RD () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 12:07 - 2014-03-18 18:29 - 00000000 ___RD () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 12:06 - 2014-04-13 08:31 - 00305240 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-16 12:06 - 2014-03-20 15:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 12:38 - 2014-03-20 15:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 12:36 - 2014-03-20 15:58 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 12:36 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-14 10:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-14 10:10 - 2014-05-14 10:10 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-05-14 09:47 - 2014-05-14 09:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-05-14 09:47 - 2014-05-14 09:46 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2014-05-14 08:48 - 2014-05-07 11:09 - 00031232 _____ () C:\Users\Acer\Desktop\Zbozi_MO.xls
2014-05-13 13:48 - 2014-05-13 13:48 - 00006144 _____ () C:\Users\Acer\Desktop\Ceny_štítek.xls
2014-05-12 11:20 - 2014-05-12 11:18 - 00044281 _____ () C:\Users\Acer\Desktop\Platby.ods
2014-05-09 19:32 - 2014-04-09 08:09 - 00002190 ____H () C:\Users\Acer\Documents\Default.rdp
2014-05-09 08:10 - 2014-05-05 08:15 - 00020124 _____ () C:\Users\Acer\Desktop\Nesouhlas.odt
2014-05-07 09:18 - 2014-05-07 09:18 - 00061558 _____ () C:\Users\Acer\Desktop\Analýza dokladů.ods
2014-05-07 07:38 - 2014-04-14 11:32 - 00123694 _____ () C:\Users\Acer\Desktop\Obrat prodejen 2011-2014 duben.ods
2014-05-06 07:14 - 2014-05-14 10:45 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 07:14 - 2014-05-14 10:45 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 05:48 - 2014-05-14 10:45 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:48 - 2014-05-14 10:45 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-06 05:37 - 2014-05-14 10:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:26 - 2014-05-14 10:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 22:37 - 2013-03-07 00:24 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:37 - 2013-03-07 00:24 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-25 17:44 - 2014-05-19 14:47 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-04-25 17:44 - 2014-05-19 14:47 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-04-25 17:44 - 2014-05-19 14:47 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-04-25 17:44 - 2014-05-19 14:47 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-14 10:45] - [2014-04-12 11:10] - 0578048 ____A (Microsoft Corporation) 75DD70A14145499C9F7D903CF9A8C91B
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Acer\Desktop" je 6156 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-05-2014
Ran by Acer (administrator) on ACERR-NTB on 24-05-2014 07:34:41
Running from C:\Users\Acer\Desktop
Platform: Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [10592256 2014-03-18] (Broadcom Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876304 2013-01-18] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13267016 2013-01-29] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1276488 2013-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-01-18] (IvoSoft)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4148664 2013-10-07] (ESET)
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2014-03-18] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - DefaultScope {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL =
SearchScopes: HKCU - {9BE538B0-98BE-4950-BA4E-8074A6EFE854} URL =
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default
FF Homepage: http://www.idnes.cz
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default\Extensions\cs@dictionaries.addons.mozilla.org [2014-03-21]
FF Extension: Adblock Plus - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\luu8yumh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-20]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: ESET Endpoint Security Extension - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2014-03-21]
==================== Services (Whitelisted) =================
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2012-10-01] (Broadcom Corporation.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-20] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-17] (Acer Incorporated)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [42048 2013-10-07] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1025584 2013-10-07] (ESET)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [191368 2013-10-07] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-01-18] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2014-03-18] (Dritek System INC.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [6068736 2014-03-18] (Broadcom Corporation)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2012-10-01] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6835784 2012-10-13] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219184 2013-10-25] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [185224 2013-09-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [155896 2013-09-09] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [147096 2013-09-09] (ESET)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2014-03-18] (Dritek System Inc.)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-24 07:34 - 2014-05-24 07:34 - 00012369 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-05-24 07:34 - 2014-05-24 07:34 - 00000000 ____D () C:\FRST
2014-05-24 07:32 - 2014-05-24 07:32 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-05-24 07:28 - 2014-05-24 07:29 - 02067456 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-05-24 07:25 - 2014-05-24 07:32 - 00000000 ____D () C:\rsit
2014-05-24 07:25 - 2014-05-24 07:25 - 00000000 ____D () C:\Program Files\trend micro
2014-05-24 07:24 - 2014-05-24 07:24 - 00935175 _____ () C:\Users\Acer\Desktop\RSITx64.exe
2014-05-23 12:35 - 2014-05-23 17:17 - 00000000 ____D () C:\Users\Acer\Desktop\B958
2014-05-23 12:32 - 2014-05-23 12:33 - 00000000 ____D () C:\Users\Acer\Desktop\B958_Huawei
2014-05-23 12:29 - 2014-05-23 12:30 - 00000000 ____D () C:\Users\Acer\Desktop\B895
2014-05-22 20:41 - 2014-05-22 20:41 - 00000000 ____D () C:\Users\Acer\Desktop\B948 Sin
2014-05-22 19:25 - 2014-05-22 19:25 - 00000000 ____D () C:\Users\Acer\Desktop\B937
2014-05-21 19:12 - 2014-05-21 19:33 - 00000000 ____D () C:\Users\Acer\Documents\Wave
2014-05-21 12:24 - 2014-05-21 12:24 - 00000000 ____D () C:\Users\Acer\Desktop\B952 orig
2014-05-21 10:27 - 2014-05-21 10:27 - 00000000 ____D () C:\Users\Acer\Desktop\B894_2
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\Desktop\B894
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\AppData\Local\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\totalcmd
2014-05-21 08:13 - 2014-05-21 08:13 - 00000000 ____D () C:\Users\Acer\Desktop\B952
2014-05-21 07:52 - 2014-05-21 07:52 - 36283976 _____ () C:\Users\Acer\Desktop\HiSuiteSetup_v1.8.10.26.06.zip
2014-05-21 07:44 - 2014-05-21 07:44 - 00000000 ____D () C:\Users\Acer\Desktop\G300 downgrade
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Users\Acer\Documents\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-19 14:47 - 2014-05-24 07:18 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\pdfforge
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Local\ESET
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-19 14:47 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-19 14:47 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-19 14:47 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-19 14:47 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 10:46 - 2014-03-28 21:19 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-05-14 10:46 - 2014-03-28 10:23 - 19759104 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 10:46 - 2014-03-28 08:18 - 17562112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 10:46 - 2014-03-24 00:11 - 00269592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-05-14 10:45 - 2014-05-06 07:14 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 10:45 - 2014-05-06 07:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 10:45 - 2014-05-06 05:48 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 10:45 - 2014-05-06 05:48 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 10:45 - 2014-05-06 05:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 10:45 - 2014-05-06 05:26 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 10:45 - 2014-04-12 11:27 - 00172888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 10:45 - 2014-04-12 11:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 10:45 - 2014-04-12 11:09 - 01043968 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 10:45 - 2014-04-12 11:09 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-05-14 10:45 - 2014-04-12 11:08 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 10:45 - 2014-04-12 11:07 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00961536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 10:45 - 2014-04-12 09:23 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 10:45 - 2014-04-12 09:22 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 10:45 - 2014-04-12 09:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 10:45 - 2014-04-12 08:58 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\workerdd.dll
2014-05-14 10:45 - 2014-03-28 10:23 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-05-14 10:45 - 2014-03-11 05:32 - 06987096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 10:45 - 2014-03-11 05:25 - 00100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 10:45 - 2014-03-11 02:41 - 00559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 10:45 - 2014-03-11 02:41 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 10:45 - 2014-03-11 02:41 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 10:45 - 2014-03-11 02:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 10:45 - 2014-03-11 02:38 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00419328 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 10:45 - 2014-03-11 02:38 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 10:45 - 2014-03-10 05:05 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 10:45 - 2014-03-10 03:27 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 10:45 - 2014-03-04 01:07 - 00570216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-05-14 10:45 - 2014-03-01 11:47 - 01258496 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-05-14 10:45 - 2014-03-01 11:47 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2014-05-14 10:45 - 2014-03-01 10:07 - 01075200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2014-05-14 10:45 - 2014-03-01 08:59 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-05-14 10:45 - 2014-02-27 01:18 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-05-14 10:45 - 2014-02-27 01:18 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-05-14 10:45 - 2014-02-15 06:15 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-05-14 10:10 - 2014-05-14 10:10 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-05-14 09:47 - 2014-05-14 09:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-05-14 09:46 - 2014-05-14 09:47 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2014-05-13 13:48 - 2014-05-13 13:48 - 00006144 _____ () C:\Users\Acer\Desktop\Ceny_štítek.xls
2014-05-12 11:18 - 2014-05-12 11:20 - 00044281 _____ () C:\Users\Acer\Desktop\Platby.ods
2014-05-10 10:24 - 2014-05-19 09:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 11:09 - 2014-05-14 08:48 - 00031232 _____ () C:\Users\Acer\Desktop\Zbozi_MO.xls
2014-05-07 09:18 - 2014-05-07 09:18 - 00061558 _____ () C:\Users\Acer\Desktop\Analýza dokladů.ods
2014-05-06 10:43 - 2014-04-19 11:39 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-05-06 10:43 - 2014-04-19 10:45 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-06 10:43 - 2014-04-19 10:45 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-06 10:43 - 2014-04-19 08:57 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-06 10:43 - 2014-04-19 08:57 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-05 08:15 - 2014-05-09 08:10 - 00020124 _____ () C:\Users\Acer\Desktop\Nesouhlas.odt
2014-04-29 10:44 - 2014-05-24 07:18 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-05-24 07:34 - 2014-05-24 07:34 - 00012369 _____ () C:\Users\Acer\Desktop\FRST.txt
2014-05-24 07:34 - 2014-05-24 07:34 - 00000000 ____D () C:\FRST
2014-05-24 07:32 - 2014-05-24 07:32 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-05-24 07:32 - 2014-05-24 07:25 - 00000000 ____D () C:\rsit
2014-05-24 07:29 - 2014-05-24 07:28 - 02067456 _____ (Farbar) C:\Users\Acer\Desktop\FRST64.exe
2014-05-24 07:25 - 2014-05-24 07:25 - 00000000 ____D () C:\Program Files\trend micro
2014-05-24 07:24 - 2014-05-24 07:24 - 00935175 _____ () C:\Users\Acer\Desktop\RSITx64.exe
2014-05-24 07:24 - 2014-03-20 15:55 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\ClassicShell
2014-05-24 07:18 - 2014-05-19 14:47 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-24 07:18 - 2014-04-29 10:44 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps
2014-05-24 07:09 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-23 18:30 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-23 17:17 - 2014-05-23 12:35 - 00000000 ____D () C:\Users\Acer\Desktop\B958
2014-05-23 16:51 - 2014-03-18 00:41 - 00751374 _____ () C:\Windows\system32\perfh005.dat
2014-05-23 16:51 - 2014-03-18 00:41 - 00154566 _____ () C:\Windows\system32\perfc005.dat
2014-05-23 16:51 - 2012-07-26 09:28 - 01776480 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-23 14:48 - 2014-03-20 15:09 - 00000000 ____D () C:\Tim
2014-05-23 12:33 - 2014-05-23 12:32 - 00000000 ____D () C:\Users\Acer\Desktop\B958_Huawei
2014-05-23 12:30 - 2014-05-23 12:29 - 00000000 ____D () C:\Users\Acer\Desktop\B895
2014-05-23 06:29 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-23 06:28 - 2014-03-18 00:47 - 00053284 _____ () C:\Windows\system32\wpbbin.exe
2014-05-23 06:28 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-22 20:41 - 2014-05-22 20:41 - 00000000 ____D () C:\Users\Acer\Desktop\B948 Sin
2014-05-22 19:25 - 2014-05-22 19:25 - 00000000 ____D () C:\Users\Acer\Desktop\B937
2014-05-21 19:33 - 2014-05-21 19:12 - 00000000 ____D () C:\Users\Acer\Documents\Wave
2014-05-21 12:24 - 2014-05-21 12:24 - 00000000 ____D () C:\Users\Acer\Desktop\B952 orig
2014-05-21 10:27 - 2014-05-21 10:27 - 00000000 ____D () C:\Users\Acer\Desktop\B894_2
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\Desktop\B894
2014-05-21 10:11 - 2014-05-21 10:11 - 00000000 ____D () C:\Users\Acer\AppData\Local\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\GHISLER
2014-05-21 10:10 - 2014-05-21 10:10 - 00000000 ____D () C:\totalcmd
2014-05-21 08:13 - 2014-05-21 08:13 - 00000000 ____D () C:\Users\Acer\Desktop\B952
2014-05-21 07:52 - 2014-05-21 07:52 - 36283976 _____ () C:\Users\Acer\Desktop\HiSuiteSetup_v1.8.10.26.06.zip
2014-05-21 07:44 - 2014-05-21 07:44 - 00000000 ____D () C:\Users\Acer\Desktop\G300 downgrade
2014-05-20 09:36 - 2014-03-20 15:10 - 00002120 _____ () C:\Users\Acer\Desktop\vision32.lnk
2014-05-20 09:36 - 2014-03-20 15:10 - 00002031 _____ () C:\Users\Acer\Desktop\Tim.lnk
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Users\Acer\Documents\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-19 14:48 - 2014-05-19 14:48 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\pdfforge
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\Users\Acer\AppData\Local\ESET
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-19 14:47 - 2014-05-19 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-19 09:21 - 2014-05-10 10:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-16 13:49 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-05-16 12:07 - 2014-03-18 18:29 - 00000000 ___RD () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 12:07 - 2014-03-18 18:29 - 00000000 ___RD () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 12:06 - 2014-04-13 08:31 - 00305240 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-16 12:06 - 2014-03-20 15:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-16 12:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 12:38 - 2014-03-20 15:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 12:36 - 2014-03-20 15:58 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 12:36 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-14 10:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-14 10:10 - 2014-05-14 10:10 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-05-14 09:47 - 2014-05-14 09:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-05-14 09:47 - 2014-05-14 09:46 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2014-05-14 08:48 - 2014-05-07 11:09 - 00031232 _____ () C:\Users\Acer\Desktop\Zbozi_MO.xls
2014-05-13 13:48 - 2014-05-13 13:48 - 00006144 _____ () C:\Users\Acer\Desktop\Ceny_štítek.xls
2014-05-12 11:20 - 2014-05-12 11:18 - 00044281 _____ () C:\Users\Acer\Desktop\Platby.ods
2014-05-09 19:32 - 2014-04-09 08:09 - 00002190 ____H () C:\Users\Acer\Documents\Default.rdp
2014-05-09 08:10 - 2014-05-05 08:15 - 00020124 _____ () C:\Users\Acer\Desktop\Nesouhlas.odt
2014-05-07 09:18 - 2014-05-07 09:18 - 00061558 _____ () C:\Users\Acer\Desktop\Analýza dokladů.ods
2014-05-07 07:38 - 2014-04-14 11:32 - 00123694 _____ () C:\Users\Acer\Desktop\Obrat prodejen 2011-2014 duben.ods
2014-05-06 07:14 - 2014-05-14 10:45 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 07:14 - 2014-05-14 10:45 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 05:48 - 2014-05-14 10:45 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:48 - 2014-05-14 10:45 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-06 05:37 - 2014-05-14 10:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:26 - 2014-05-14 10:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 22:37 - 2013-03-07 00:24 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:37 - 2013-03-07 00:24 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-25 17:44 - 2014-05-19 14:47 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-04-25 17:44 - 2014-05-19 14:47 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-04-25 17:44 - 2014-05-19 14:47 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-04-25 17:44 - 2014-05-19 14:47 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-14 10:45] - [2014-04-12 11:10] - 0578048 ____A (Microsoft Corporation) 75DD70A14145499C9F7D903CF9A8C91B
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Acer\Desktop" je 6156 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================