prosím o kontrolu logu, kolegyně odklikala na NETU nějaké bezpečnostní upozornění po kterém spadl počítač. Po restartu to končí na modrém okně, do systému se jde dostat pouze přes nouzový režim

předem dík
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-05-2014
Ran by Uživatel (administrator) on PC-HANA on 30-05-2014 14:59:06
Running from C:\Users\Uživatel\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Safe Mode (with Networking)
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11465832 2010-09-14] (Realtek Semiconductor)
HKLM\...\Run: [Služba Acronis Scheduler2] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [391144 2010-12-17] (Acronis)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5574872 2011-07-01] (Acronis)
HKLM-x32\...\Run: [SAOB Monitor] => C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe [2536752 2011-06-14] (Acronis)
HKU\S-1-5-21-2695833900-3277720856-1120413341-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20924064 2014-02-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.14.1
FireFox:
========
FF ProfilePath: C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\egbqb5qp.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @software602.cz/602XML Filler - C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-05-12]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-05-12]
==================== Services (Whitelisted) =================
S2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-30 14:59 - 2014-05-30 14:59 - 00007256 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-05-30 14:57 - 2014-05-30 14:57 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-05-30 14:56 - 2014-05-30 14:59 - 00000000 ____D () C:\FRST
2014-05-30 14:55 - 2014-05-30 14:55 - 02066944 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-05-30 14:41 - 2014-05-30 14:41 - 00343744 _____ () C:\Windows\Minidump\053014-22916-01.dmp
2014-05-30 14:29 - 2014-05-30 14:29 - 00343744 _____ () C:\Windows\Minidump\053014-21559-01.dmp
2014-05-30 14:18 - 2014-05-30 14:18 - 00343800 _____ () C:\Windows\Minidump\053014-22011-01.dmp
2014-05-30 14:15 - 2014-05-30 14:15 - 00343800 _____ () C:\Windows\Minidump\053014-13072-01.dmp
2014-05-30 14:13 - 2014-05-30 14:13 - 00003608 ____N () C:\bootsqm.dat
2014-05-30 11:18 - 2014-05-30 11:18 - 00343800 _____ () C:\Windows\Minidump\053014-13899-01.dmp
2014-05-30 11:17 - 2014-05-30 11:17 - 01241432 _____ () C:\Windows\Minidump\053014-26520-01.dmp
2014-05-22 11:44 - 2014-05-22 11:44 - 00000000 ____D () C:\Users\Uživatel\Desktop\obj
2014-05-21 09:37 - 2014-05-21 09:37 - 00264192 _____ () C:\Users\Uživatel\Desktop\propiskyALBA .ppt
2014-05-20 09:06 - 2014-05-20 09:06 - 00150528 _____ () C:\Users\Uživatel\Desktop\Sou18501_01_Specifikace_dod1.xls
2014-05-20 09:05 - 2014-05-20 09:05 - 05559876 _____ () C:\Users\Uživatel\Desktop\Zadavaci_dokumentace.zip
2014-05-15 09:08 - 2014-05-26 13:57 - 00000000 ____D () C:\Users\Uživatel\Desktop\Penzijní fond hana
2014-05-14 16:17 - 2014-05-14 16:17 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-14 16:17 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 16:17 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 16:17 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 16:17 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 16:17 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 16:17 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 07:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 07:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 07:23 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 07:23 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 07:23 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 07:23 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 07:23 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 07:23 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 07:23 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 07:23 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 07:23 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 07:23 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 07:23 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 07:23 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 07:23 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 07:23 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 07:23 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 07:23 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 07:23 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 07:23 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 07:23 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 07:23 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 07:23 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-12 15:20 - 2014-05-15 07:25 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-12 12:39 - 2014-05-12 12:39 - 00016384 _____ () C:\Users\Uživatel\Desktop\spojení .msg
2014-05-12 11:00 - 2014-05-12 11:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-30 08:54 - 2014-04-30 08:54 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-04-30 08:54 - 2014-04-30 08:54 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
==================== One Month Modified Files and Folders =======
2014-05-30 14:59 - 2014-05-30 14:59 - 00007256 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-05-30 14:59 - 2014-05-30 14:56 - 00000000 ____D () C:\FRST
2014-05-30 14:59 - 2011-08-02 15:33 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Temp
2014-05-30 14:57 - 2014-05-30 14:57 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-05-30 14:55 - 2014-05-30 14:55 - 02066944 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-05-30 14:52 - 2011-08-02 15:33 - 01086584 _____ () C:\Windows\WindowsUpdate.log
2014-05-30 14:51 - 2011-08-04 16:19 - 00000000 ____D () C:\Zaloha z PC
2014-05-30 14:51 - 2011-08-03 12:00 - 00000000 ____D () C:\Users\Uživatel\Documents\Soubory aplikace Outlook
2014-05-30 14:41 - 2014-05-30 14:41 - 00343744 _____ () C:\Windows\Minidump\053014-22916-01.dmp
2014-05-30 14:41 - 2011-08-18 09:16 - 246976191 _____ () C:\Windows\MEMORY.DMP
2014-05-30 14:41 - 2011-08-18 09:16 - 00000000 ____D () C:\Windows\Minidump
2014-05-30 14:41 - 2010-11-21 05:47 - 00209660 _____ () C:\Windows\PFRO.log
2014-05-30 14:29 - 2014-05-30 14:29 - 00343744 _____ () C:\Windows\Minidump\053014-21559-01.dmp
2014-05-30 14:18 - 2014-05-30 14:18 - 00343800 _____ () C:\Windows\Minidump\053014-22011-01.dmp
2014-05-30 14:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-30 14:17 - 2009-07-14 06:51 - 00079997 _____ () C:\Windows\setupact.log
2014-05-30 14:15 - 2014-05-30 14:15 - 00343800 _____ () C:\Windows\Minidump\053014-13072-01.dmp
2014-05-30 14:13 - 2014-05-30 14:13 - 00003608 ____N () C:\bootsqm.dat
2014-05-30 11:18 - 2014-05-30 11:18 - 00343800 _____ () C:\Windows\Minidump\053014-13899-01.dmp
2014-05-30 11:17 - 2014-05-30 11:17 - 01241432 _____ () C:\Windows\Minidump\053014-26520-01.dmp
2014-05-30 11:08 - 2011-08-08 12:38 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Skype
2014-05-30 11:06 - 2012-08-09 07:39 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-30 10:41 - 2013-05-23 12:02 - 00000956 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-30 09:38 - 2014-03-11 10:44 - 00000000 ____D () C:\Users\Uživatel\Desktop\los
2014-05-30 08:44 - 2013-04-13 03:02 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-05-30 08:41 - 2013-05-23 12:02 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-30 07:41 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-30 07:41 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-29 09:30 - 2012-07-27 13:39 - 00000000 ____D () C:\Users\Uživatel\Desktop\Dodáky nové
2014-05-28 10:30 - 2011-08-29 10:24 - 00002967 _____ () C:\Users\Uživatel\Desktop\Temp.lnk
2014-05-28 10:03 - 2013-02-19 12:52 - 00000000 ____D () C:\Users\Uživatel\Desktop\Andy present
2014-05-26 13:57 - 2014-05-15 09:08 - 00000000 ____D () C:\Users\Uživatel\Desktop\Penzijní fond hana
2014-05-26 13:18 - 2014-01-13 15:04 - 00000000 ____D () C:\Users\Uživatel\Desktop\Jirka USA
2014-05-23 09:13 - 2014-02-24 15:10 - 00000000 ____D () C:\Users\Uživatel\Desktop\Jirka byt
2014-05-22 11:44 - 2014-05-22 11:44 - 00000000 ____D () C:\Users\Uživatel\Desktop\obj
2014-05-21 09:47 - 2012-07-10 12:24 - 00000000 ____D () C:\Users\Uživatel\Desktop\máti prodej RD + grand residence + stěhování
2014-05-21 09:37 - 2014-05-21 09:37 - 00264192 _____ () C:\Users\Uživatel\Desktop\propiskyALBA .ppt
2014-05-20 09:06 - 2014-05-20 09:06 - 00150528 _____ () C:\Users\Uživatel\Desktop\Sou18501_01_Specifikace_dod1.xls
2014-05-20 09:05 - 2014-05-20 09:05 - 05559876 _____ () C:\Users\Uživatel\Desktop\Zadavaci_dokumentace.zip
2014-05-15 08:29 - 2011-08-03 13:04 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-15 08:10 - 2011-08-02 15:33 - 00000000 ___RD () C:\Users\Uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 08:10 - 2011-08-02 15:33 - 00000000 ___RD () C:\Users\Uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 07:25 - 2014-05-12 15:20 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 16:18 - 2011-08-02 15:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 16:17 - 2014-05-14 16:17 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-14 16:16 - 2013-08-15 16:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 16:15 - 2011-08-03 10:42 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 11:06 - 2012-08-09 07:39 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 11:06 - 2012-08-09 07:39 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 11:06 - 2011-08-03 13:02 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 10:31 - 2013-09-26 11:39 - 00000000 ____D () C:\Users\Uživatel\Desktop\Tschibo
2014-05-13 07:29 - 2012-04-26 11:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 12:39 - 2014-05-12 12:39 - 00016384 _____ () C:\Users\Uživatel\Desktop\spojení .msg
2014-05-12 11:36 - 2012-09-17 09:55 - 00000000 ____D () C:\Users\Uživatel\Desktop\všechno možné
2014-05-12 11:00 - 2014-05-12 11:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-12 09:21 - 2011-08-02 15:33 - 00000000 ____D () C:\Users\Uživatel
2014-05-12 09:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-05-12 08:36 - 2013-05-23 12:02 - 00003952 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-12 08:36 - 2013-05-23 12:02 - 00003700 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-09 08:14 - 2014-05-14 07:23 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-14 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-06 06:40 - 2014-05-14 16:17 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-14 16:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-14 16:17 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-14 16:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-14 16:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 16:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-30 08:54 - 2014-04-30 08:54 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-04-30 08:54 - 2014-04-30 08:54 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
Some content of TEMP:
====================
C:\Users\Uživatel\AppData\Local\Temp\ca_A24.tmp.dll
C:\Users\Uživatel\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 08:04
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:931.41 GB) (Free:818.92 GB) NTFS
Available physical RAM: 2953.35 MB
Total physical RAM: 3839.24 MB
Percentage of memory in use: 23%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 932 GB) (Disk ID: F1F3E01F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\U�ivatel\Desktop" je 372 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================