díky
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by coolajda (administrator) on PC on 26-05-2014 18:07:21
Running from C:\Users\coolajda\Desktop
Platform: Windows 8.1 Pro (Update 1) (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\plugin-nm-server.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google Inc.) C:\Users\coolajda\AppData\Local\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 5520 series\Bin\ScanToPCActivationApp.exe
(Spotify Ltd) C:\Users\coolajda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 5520 series\Bin\HPNetworkCommunicatorCom.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\coolajda\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3109204692-2521638921-477205765-1001\...\Run: [Google Update] => C:\Users\coolajda\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-04-22] (Google Inc.)
HKU\S-1-5-21-3109204692-2521638921-477205765-1001\...\Run: [HP Deskjet 5520 series (NET)] => C:\Program Files\HP\HP Deskjet 5520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3109204692-2521638921-477205765-1001\...\Run: [Spotify Web Helper] => C:\Users\coolajda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-22] (Spotify Ltd)
HKU\S-1-5-21-3109204692-2521638921-477205765-1001\...\MountPoints2: {80da53d0-b983-11e3-8254-8c89a5c49d88} - "H:\WD SmartWare.exe" autoplay=true
Startup: C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe (Samsung Electronics.)
Startup: C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 5520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 5520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 5520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 5520 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 5520 series.lnk -> C:\Program Files\HP\HP Deskjet 5520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.cz/?rlz=1W4CHBA_csCZ571
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\..\Interfaces\{35778732-C998-4C49-AFDF-137E191CDCE7}: [NameServer]8.8.8.8,8.8.4.4
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\coolajda\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\coolajda\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\coolajda\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\coolajda\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\coolajda\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\coolajda\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF HKLM-x32\...\Firefox\Extensions: [
url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
url_advisor@kaspersky.com [2014-04-03]
FF HKLM-x32\...\Firefox\Extensions: [
virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
virtual_keyboard@kaspersky.com [2014-04-03]
FF HKLM-x32\...\Firefox\Extensions: [
content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
content_blocker@kaspersky.com [2014-04-03]
FF HKLM-x32\...\Firefox\Extensions: [
anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
anti_banner@kaspersky.com [2014-04-03]
FF HKLM-x32\...\Firefox\Extensions: [
online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
online_banking@kaspersky.com [2014-04-03]
Chrome:
=======
CHR HomePage: hxxp://
www.google.cz/
CHR StartupUrls: "hxxp://google.cz/"
CHR Extension: (Google Translate) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-04-01]
CHR Extension: (Dokumenty Google) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Disk Google) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-01]
CHR Extension: (Kaspersky Protection) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-04-03]
CHR Extension: (YouTube) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (Google Cast) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-04-19]
CHR Extension: (Vyhledávání Google) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (Kaspersky URL poradce) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-04-03]
CHR Extension: (Google+) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2014-04-01]
CHR Extension: (Ochrana financí) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-04-03]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2014-04-01]
CHR Extension: (No Name) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-05-21]
CHR Extension: (Google Keep) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-04-01]
CHR Extension: (goo.gl URL Shortener) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2014-04-01]
CHR Extension: (Mapy Google) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-04-01]
CHR Extension: (Clickable Links) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgamelhnfokapndfdodnmfiningckjia [2014-04-01]
CHR Extension: (Peněženka Google) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-01]
CHR Extension: (Gmail) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR Extension: (Anti-Banner) - C:\Users\coolajda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-04-03]
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] -
https://chrome.google.com/webstore/deta ... ddbepgkeaa [2014-04-03]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-20]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-20]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-20]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-20]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-20]
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-20] (Kaspersky Lab ZAO)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-04-03] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2014-04-03] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [115296 2014-04-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2014-04-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-10-20] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-04-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-20] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [65120 2014-04-03] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-04-03] (Kaspersky Lab ZAO)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2014-05-06] (Intel Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-26 18:07 - 2014-05-26 18:07 - 00017326 _____ () C:\Users\coolajda\Desktop\FRST.txt
2014-05-26 18:06 - 2014-05-26 18:07 - 00000000 ____D () C:\FRST
2014-05-26 18:05 - 2014-05-26 18:05 - 00112640 _____ (forum.viry.cz) C:\Users\coolajda\Desktop\Nepotvrzeno 926930.crdownload
2014-05-26 18:05 - 2014-05-26 18:05 - 00112640 _____ (forum.viry.cz) C:\Users\coolajda\Desktop\FRSTLauncher.exe
2014-05-26 18:03 - 2014-05-26 18:03 - 02066944 _____ (Farbar) C:\Users\coolajda\Desktop\FRST64.exe
2014-05-23 19:41 - 2014-05-23 19:46 - 00005362 _____ () C:\
MiFlash-1400866863@PC.log
2014-05-23 18:13 - 2014-05-23 18:13 - 00000582 _____ () C:\
MiFlash-1400861589@PC.log
2014-05-23 18:09 - 2014-05-23 18:09 - 00000582 _____ () C:\
MiFlash-1400861353@PC.log
2014-05-23 18:05 - 2014-05-23 18:14 - 00000000 ____D () C:\aries_images_4.5.9_4.1_cn
2014-05-23 08:32 - 2014-05-23 08:32 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\dvdcss
2014-05-22 13:26 - 2014-05-22 13:26 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\Mozilla
2014-05-22 10:12 - 2014-05-23 18:12 - 00001689 _____ () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\MiFlash.lnk
2014-05-22 10:12 - 2014-05-22 10:12 - 00000582 _____ () C:\
MiFlash-1400746329@PC.log
2014-05-22 10:12 - 2014-05-22 10:12 - 00000000 ____D () C:\Qualcomm
2014-05-22 10:12 - 2014-05-22 10:12 - 00000000 ____D () C:\Google
2014-05-22 10:12 - 2012-11-07 16:04 - 01249792 _____ (XiaoMi Corporation) C:\MiFlash.exe
2014-05-22 10:12 - 2012-11-07 16:01 - 00106496 _____ (XiaoMi Corporation) C:\Windows\SysWOW64\qcCoInstaller.dll
2014-05-22 10:12 - 2012-07-31 05:17 - 00121856 _____ (Microsoft Corporation) C:\xmllite.dll
2014-05-22 10:11 - 2014-05-22 10:11 - 20265684 _____ (XiaoMi Corporation) C:\MiPhone2.11.6.exe
2014-05-14 13:23 - 2014-05-14 13:23 - 00001102 _____ () C:\Users\coolajda\Desktop\MeGUI.exe – zástupce.lnk
2014-05-14 13:22 - 2014-05-15 12:34 - 00000000 ____D () C:\Users\coolajda\Desktop\MeGUI_2418_x86
2014-05-14 07:52 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 07:52 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 07:52 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 07:52 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 07:52 - 2014-04-11 12:03 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2014-05-14 07:52 - 2014-04-11 12:03 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-05-14 07:52 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2014-05-14 07:52 - 2014-04-11 08:04 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-05-14 07:52 - 2014-04-11 07:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe
2014-05-14 07:52 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-05-14 07:52 - 2014-04-11 05:54 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2014-05-14 07:52 - 2014-04-11 05:36 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-05-14 07:52 - 2014-04-11 05:24 - 13288960 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-05-14 07:52 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-05-14 07:52 - 2014-04-11 05:05 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 07:52 - 2014-04-11 05:05 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-05-14 07:52 - 2014-04-11 05:02 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 07:52 - 2014-04-11 05:02 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-05-14 07:52 - 2014-04-11 05:01 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-05-14 07:52 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-05-14 07:52 - 2014-04-11 04:59 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-05-14 07:52 - 2014-04-11 04:57 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-05-14 07:52 - 2014-04-11 04:56 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-05-14 07:52 - 2014-04-11 04:55 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-05-14 07:52 - 2014-04-11 04:53 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-05-14 07:52 - 2014-04-11 04:52 - 03464192 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-05-14 07:52 - 2014-04-11 04:46 - 01705472 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-05-14 07:52 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2014-05-14 07:52 - 2014-04-11 04:34 - 00754688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-14 07:52 - 2014-04-11 04:29 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2014-05-14 07:52 - 2014-04-11 04:25 - 00921088 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-14 07:52 - 2014-03-24 04:30 - 00257880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-05-14 07:52 - 2014-03-24 04:30 - 00123224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2014-05-14 07:52 - 2014-03-24 04:27 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-05-14 07:52 - 2014-03-13 09:42 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-05-14 07:52 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-05-14 07:51 - 2014-04-09 00:46 - 00086688 _____ (Microsoft Corporation) C:\Windows\system32\mrt_map.dll
2014-05-14 07:51 - 2014-04-09 00:46 - 00028320 _____ (Microsoft Corporation) C:\Windows\system32\mrt100.dll
2014-05-14 07:51 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt_map.dll
2014-05-14 07:51 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt100.dll
2014-05-14 07:51 - 2014-03-27 11:12 - 21225584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 07:51 - 2014-03-27 09:48 - 18679728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 12:58 - 2014-05-13 12:58 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2014-05-12 22:26 - 2014-05-12 22:26 - 00000710 _____ () C:\Users\coolajda\Desktop\mluvené slovo – zástupce.lnk
2014-05-12 22:09 - 2014-05-12 22:17 - 00000000 ____D () C:\Users\coolajda\Desktop\knihy
2014-05-12 16:03 - 2014-05-12 16:03 - 00000000 ____D () C:\Users\coolajda\Documents\my games
2014-05-11 14:22 - 2014-05-14 16:40 - 00000000 ____D () C:\Users\coolajda\Desktop\Photos
2014-05-10 07:00 - 2014-05-10 07:00 - 00000000 ____D () C:\Users\jakub_000\Documents\my games
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Unity
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Deployment
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Apps\2.0
2014-05-09 13:27 - 2014-05-09 13:27 - 00000201 _____ () C:\Users\lopol_000\Desktop\Borderlands 2.url
2014-05-09 13:15 - 2014-05-09 13:15 - 00000000 ____D () C:\Users\lopol_000\Documents\my games
2014-05-06 08:12 - 2014-05-06 08:12 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2014-05-06 08:12 - 2014-05-06 08:12 - 00100312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2014-05-06 08:12 - 2014-05-06 08:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-05-04 11:32 - 2014-05-04 11:32 - 00000000 ____D () C:\Users\jakub_000\AppData\Roaming\vlc
2014-05-04 11:32 - 2014-05-04 11:32 - 00000000 ____D () C:\Users\jakub_000\AppData\Roaming\LibreOffice
2014-05-02 15:18 - 2014-05-26 15:42 - 00000501 _____ () C:\Users\lopol_000\Desktop\Farmička.website
2014-05-02 07:08 - 2014-05-02 07:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-02 07:08 - 2014-05-02 07:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 12:27 - 2014-05-22 09:05 - 00000000 ____D () C:\Users\coolajda\AppData\Local\Spotify
2014-04-29 12:27 - 2014-04-29 12:27 - 00001854 _____ () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-04-29 12:26 - 2014-05-22 10:03 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\Spotify
2014-04-29 11:40 - 2014-04-29 11:40 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-04-29 11:40 - 2014-04-29 11:40 - 00000000 ____D () C:\Program Files\Realtek
2014-04-29 11:39 - 2014-04-29 11:39 - 03872984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-04-29 11:39 - 2014-04-29 11:39 - 02825432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02792152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02037336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01958616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-04-29 11:39 - 2014-04-29 11:39 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01033304 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01024216 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00946392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00757301 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-04-29 11:39 - 2014-04-29 11:39 - 00628504 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00624344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBTHX32.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00397592 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00032344 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\MBfilt64.sys
2014-04-29 11:39 - 2014-04-29 11:39 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-04-29 11:37 - 2014-04-29 11:37 - 00839896 _____ (Realtek ) C:\Windows\system32\Drivers\Rt630x64.sys
2014-04-29 11:37 - 2014-04-29 11:37 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\IObit
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\ProgramData\IObit
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-04-29 11:28 - 2014-04-29 11:28 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
2014-04-29 11:28 - 2014-04-29 11:28 - 00000000 ____D () C:\Users\coolajda\AppData\Local\eSupport.com
2014-04-29 11:28 - 2014-04-29 11:28 - 00000000 ____D () C:\Program Files (x86)\eSupport.com
2014-04-26 19:44 - 2014-05-26 09:47 - 00187392 ___SH () C:\Users\coolajda\Desktop\Thumbs.db
==================== One Month Modified Files and Folders =======
2014-05-26 18:07 - 2014-05-26 18:07 - 00017326 _____ () C:\Users\coolajda\Desktop\FRST.txt
2014-05-26 18:07 - 2014-05-26 18:06 - 00000000 ____D () C:\FRST
2014-05-26 18:06 - 2014-04-01 11:08 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3109204692-2521638921-477205765-1001
2014-05-26 18:05 - 2014-05-26 18:05 - 00112640 _____ (forum.viry.cz) C:\Users\coolajda\Desktop\Nepotvrzeno 926930.crdownload
2014-05-26 18:05 - 2014-05-26 18:05 - 00112640 _____ (forum.viry.cz) C:\Users\coolajda\Desktop\FRSTLauncher.exe
2014-05-26 18:03 - 2014-05-26 18:03 - 02066944 _____ (Farbar) C:\Users\coolajda\Desktop\FRST64.exe
2014-05-26 18:03 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-05-26 17:06 - 2014-04-03 10:25 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-05-26 17:06 - 2014-04-01 11:49 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-26 17:06 - 2014-04-01 11:09 - 00000000 __RDO () C:\Users\coolajda\SkyDrive
2014-05-26 16:59 - 2014-04-01 11:49 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-26 16:25 - 2014-04-22 13:15 - 00000980 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001UA.job
2014-05-26 16:06 - 2014-04-01 11:02 - 01889555 _____ () C:\Windows\WindowsUpdate.log
2014-05-26 15:53 - 2014-04-02 13:04 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3109204692-2521638921-477205765-1004
2014-05-26 15:48 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-05-26 15:42 - 2014-05-02 15:18 - 00000501 _____ () C:\Users\lopol_000\Desktop\Farmička.website
2014-05-26 15:37 - 2014-04-02 13:00 - 00000000 __RDO () C:\Users\lopol_000\SkyDrive
2014-05-26 14:46 - 2014-04-05 08:02 - 00000000 ____D () C:\Users\coolajda\AppData\Local\JDownloader v2.0
2014-05-26 13:37 - 2014-04-01 16:03 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3109204692-2521638921-477205765-1005
2014-05-26 13:32 - 2014-04-01 15:59 - 00000000 __RDO () C:\Users\jakub_000\SkyDrive
2014-05-26 09:47 - 2014-04-26 19:44 - 00187392 ___SH () C:\Users\coolajda\Desktop\Thumbs.db
2014-05-25 19:25 - 2014-04-22 13:15 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001Core.job
2014-05-24 22:03 - 2014-04-17 19:20 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\vlc
2014-05-24 07:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-23 19:49 - 2013-08-22 16:46 - 00027924 _____ () C:\Windows\setupact.log
2014-05-23 19:46 - 2014-05-23 19:41 - 00005362 _____ () C:\
MiFlash-1400866863@PC.log
2014-05-23 18:14 - 2014-05-23 18:05 - 00000000 ____D () C:\aries_images_4.5.9_4.1_cn
2014-05-23 18:13 - 2014-05-23 18:13 - 00000582 _____ () C:\
MiFlash-1400861589@PC.log
2014-05-23 18:12 - 2014-05-22 10:12 - 00001689 _____ () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\MiFlash.lnk
2014-05-23 18:09 - 2014-05-23 18:09 - 00000582 _____ () C:\
MiFlash-1400861353@PC.log
2014-05-23 08:32 - 2014-05-23 08:32 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\dvdcss
2014-05-22 17:10 - 2014-04-01 11:01 - 01745984 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-22 17:10 - 2013-09-30 05:56 - 00738682 _____ () C:\Windows\system32\perfh005.dat
2014-05-22 17:10 - 2013-09-30 05:56 - 00151404 _____ () C:\Windows\system32\perfc005.dat
2014-05-22 13:26 - 2014-05-22 13:26 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\Mozilla
2014-05-22 10:12 - 2014-05-22 10:12 - 00000582 _____ () C:\
MiFlash-1400746329@PC.log
2014-05-22 10:12 - 2014-05-22 10:12 - 00000000 ____D () C:\Qualcomm
2014-05-22 10:12 - 2014-05-22 10:12 - 00000000 ____D () C:\Google
2014-05-22 10:11 - 2014-05-22 10:11 - 20265684 _____ (XiaoMi Corporation) C:\MiPhone2.11.6.exe
2014-05-22 10:03 - 2014-04-29 12:26 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\Spotify
2014-05-22 09:05 - 2014-04-29 12:27 - 00000000 ____D () C:\Users\coolajda\AppData\Local\Spotify
2014-05-19 11:14 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-19 09:23 - 2013-08-22 15:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-05-16 12:38 - 2014-04-01 15:56 - 00000000 ___RD () C:\Users\jakub_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 12:38 - 2014-04-01 15:56 - 00000000 ___RD () C:\Users\jakub_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 18:51 - 2014-04-02 12:57 - 00000000 ___RD () C:\Users\lopol_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 18:51 - 2014-04-02 12:57 - 00000000 ___RD () C:\Users\lopol_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 12:34 - 2014-05-14 13:22 - 00000000 ____D () C:\Users\coolajda\Desktop\MeGUI_2418_x86
2014-05-15 10:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-05-15 07:41 - 2014-04-01 11:03 - 00000000 ___RD () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 07:41 - 2014-04-01 11:03 - 00000000 ___RD () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-14 23:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 16:40 - 2014-05-11 14:22 - 00000000 ____D () C:\Users\coolajda\Desktop\Photos
2014-05-14 13:23 - 2014-05-14 13:23 - 00001102 _____ () C:\Users\coolajda\Desktop\MeGUI.exe – zástupce.lnk
2014-05-14 08:01 - 2014-04-02 07:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 08:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-14 08:00 - 2014-04-02 07:51 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 08:00 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-13 12:58 - 2014-05-13 12:58 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2014-05-12 22:26 - 2014-05-12 22:26 - 00000710 _____ () C:\Users\coolajda\Desktop\mluvené slovo – zástupce.lnk
2014-05-12 22:17 - 2014-05-12 22:09 - 00000000 ____D () C:\Users\coolajda\Desktop\knihy
2014-05-12 16:03 - 2014-05-12 16:03 - 00000000 ____D () C:\Users\coolajda\Documents\my games
2014-05-12 16:01 - 2014-04-01 11:57 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2014-05-10 07:00 - 2014-05-10 07:00 - 00000000 ____D () C:\Users\jakub_000\Documents\my games
2014-05-10 06:59 - 2014-04-01 15:56 - 00000000 ____D () C:\Users\jakub_000\AppData\Local\Packages
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Unity
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Deployment
2014-05-09 18:15 - 2014-05-09 18:15 - 00000000 ____D () C:\Users\lopol_000\AppData\Local\Apps\2.0
2014-05-09 13:27 - 2014-05-09 13:27 - 00000201 _____ () C:\Users\lopol_000\Desktop\Borderlands 2.url
2014-05-09 13:15 - 2014-05-09 13:15 - 00000000 ____D () C:\Users\lopol_000\Documents\my games
2014-05-08 12:54 - 2014-04-01 11:49 - 00003934 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 12:54 - 2014-04-01 11:49 - 00003698 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-07 19:20 - 2014-04-22 13:15 - 00003932 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001UA
2014-05-07 19:20 - 2014-04-22 13:15 - 00003552 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001Core
2014-05-06 22:32 - 2014-04-01 11:19 - 00000000 ____D () C:\Users\coolajda\AppData\Local\HP
2014-05-06 08:12 - 2014-05-06 08:12 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2014-05-06 08:12 - 2014-05-06 08:12 - 00100312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2014-05-06 08:12 - 2014-05-06 08:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-05-06 06:40 - 2014-05-14 07:52 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 05:25 - 2014-05-14 07:52 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:00 - 2014-05-14 07:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 07:52 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-04 11:32 - 2014-05-04 11:32 - 00000000 ____D () C:\Users\jakub_000\AppData\Roaming\vlc
2014-05-04 11:32 - 2014-05-04 11:32 - 00000000 ____D () C:\Users\jakub_000\AppData\Roaming\LibreOffice
2014-05-02 07:08 - 2014-05-02 07:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-02 07:08 - 2014-05-02 07:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-01 22:30 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:30 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-29 12:27 - 2014-04-29 12:27 - 00001854 _____ () C:\Users\coolajda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-04-29 11:51 - 2014-04-01 11:49 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-29 11:40 - 2014-04-29 11:40 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-04-29 11:40 - 2014-04-29 11:40 - 00000000 ____D () C:\Program Files\Realtek
2014-04-29 11:39 - 2014-04-29 11:39 - 03872984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-04-29 11:39 - 2014-04-29 11:39 - 02825432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02792152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 02037336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01958616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-04-29 11:39 - 2014-04-29 11:39 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01033304 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 01024216 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00946392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00757301 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-04-29 11:39 - 2014-04-29 11:39 - 00628504 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00624344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBTHX32.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00397592 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-04-29 11:39 - 2014-04-29 11:39 - 00032344 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\MBfilt64.sys
2014-04-29 11:39 - 2014-04-29 11:39 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-04-29 11:37 - 2014-04-29 11:37 - 00839896 _____ (Realtek ) C:\Windows\system32\Drivers\Rt630x64.sys
2014-04-29 11:37 - 2014-04-29 11:37 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\Users\coolajda\AppData\Roaming\IObit
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\ProgramData\IObit
2014-04-29 11:36 - 2014-04-29 11:36 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-04-29 11:28 - 2014-04-29 11:28 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
2014-04-29 11:28 - 2014-04-29 11:28 - 00000000 ____D () C:\Users\coolajda\AppData\Local\eSupport.com
2014-04-29 11:28 - 2014-04-29 11:28 - 00000000 ____D () C:\Program Files (x86)\eSupport.com
Some content of TEMP:
====================
C:\Users\coolajda\AppData\Local\Temp\proxy_vole5329865772162295256.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-18 09:20
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (Windows) (Fixed) (Total:118.73 GB) (Free:82.89 GB) NTFS
Drive d: (Steam) (Fixed) (Total:102.88 GB) (Free:75.92 GB) NTFS
Drive e: (sklad) (Fixed) (Total:492.44 GB) (Free:329.15 GB) NTFS
Drive h: (WD SmartWare) (CDROM) (Total:0.43 GB) (Free:0 GB) UDF
Drive i: (velkej sklad) (Fixed) (Total:930.86 GB) (Free:538.67 GB) NTFS
Available physical RAM: 6086.47 MB
Total physical RAM: 7875.94 MB
Percentage of memory in use: 22%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 596 GB) (Disk ID: 00000000)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 00000000)
Disk: 2 (MBR Code: Windows XP) (Size: 931 GB) (Disk ID: 0002AE3F)
Partition 1: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001Core.job => C:\Users\coolajda\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3109204692-2521638921-477205765-1001UA.job => C:\Users\coolajda\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Users\coolajda\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\jakub_000\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\lopol_000\SkyDrive:ms-properties
==================== Security Center ==================
AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\coolajda\Desktop" je 191 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================