vir coinminer.box
Napsal: 31 kvě 2014 21:14
Dobrý den teda spíš večer. Prosím o kontrolu mého PC. Antivir mne informoval, že mám vir coinminer.box v C:\Users\Jirka\AppData\Roaming\WinUpdate\c\windrv.exe. Tak jsem ho dal do karantény. Pak jsem si všiml, že se něco stahuje z internetu, přestože jsem nic nestahoval. Nepodařilo se mi zjistit co a kam se stahovalo. Snad jen, že to bylo na C:\, protože se zmenšil volný prostor na HDD. Tak jsem spustil smartsniff a tam jsem našel IP 90.182.215.68 z které se stáhlo více než 150MB. Začátek jsem nestihl, takže nevím přesně kolik toho bylo. Udělal jsem scan pomocí MBAM a ADWCLEANERU a vyčistl PC. Teď už mi MBAM a AVG nic nenašlo, ale chtěl bych mít jistotu. Používám totiž internetbanking. Vkládám log z FRST, RSIT. Mám Win7 pro64. Předem dík za pomoc.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-05-2014
Ran by Jirka (administrator) on JIRKA-PC on 31-05-2014 21:02:30
Running from C:\Users\Jirka\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe
(O&O Software GmbH) D:\Test-programy\Defrag\oodag.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TuneUp Software) D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
(AVG) D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(O&O Software GmbH) D:\Test-programy\Defrag\oodtray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Ultima Prime & Pawel Porwisz) D:\TotalCmd UP 5.2\TC UP.exe
(Ghisler Software GmbH) D:\TotalCmd UP 5.2\TOTALCMD.EXE
(NirSoft) D:\Test-programy\smartsniff\smsniff.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [OODefragTray] => D:\Test-programy\Defrag\oodtray.exe [4464936 2014-01-24] (O&O Software GmbH)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2770432 2010-02-10] (VIA)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2567192 2014-05-30] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {55a2a431-6da5-11e3-985e-e0cb4e4e44b9} - M:\Startme.exe
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {c04cd1e2-4d57-11e3-a81e-e0cb4e4e44b9} - setup.exe
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {c04cd1ec-4d57-11e3-a81e-e0cb4e4e44b9} - K:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\O&O Defrag Tray.lnk
ShortcutTarget: O&O Defrag Tray.lnk -> C:\Windows\Installer\{177DE549-9107-4370-A840-9FC4AE8BC2BE}\app_icon.ico ()
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - {837F75D4-345A-4D43-B46B-BEF00F4FDEEB} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKLM-x32 - EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 77.48.100.254
FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=Quicksearch_13415&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - d:\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - d:\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - D:\Video-programy\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: sony.com/MediaGoDetector - D:\Mobil-programy\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\firmycz.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\mapycz.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\zbocz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27]
FF Extension: Quick Translator - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi [2013-11-15]
FF Extension: Download Status Bar - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2014-01-24]
FF Extension: Download Statusbar - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-11-14]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598 [2014-05-30]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.)
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1473792 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-07-17] (DeviceVM, Inc.)
R2 MBAMScheduler; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 OODefragAgent; D:\Test-programy\Defrag\oodag.exe [1657128 2014-01-24] (O&O Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-04-13] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 TuneUp.UtilitiesSvc; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2103096 2013-12-18] (TuneUp Software)
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1808408 2014-05-30] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-05-30] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-14] (Disc Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-05-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 SliceDisk5; G:\záloha D\Obnova dat\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-11-14] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
U3 a0hp2e4z; C:\Windows\System32\Drivers\a0hp2e4z.sys [0 ] (Advanced Micro Devices)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-31 21:02 - 2014-05-31 21:02 - 00014620 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-05-31 21:01 - 2014-05-31 21:02 - 00000000 ____D () C:\FRST
2014-05-31 20:50 - 2014-05-31 20:55 - 00112640 _____ () C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-05-31 20:48 - 2014-05-31 20:47 - 02066944 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-05-31 02:11 - 2014-05-31 02:17 - 00000000 ____D () C:\AdwCleaner
2014-05-31 00:52 - 2014-05-31 20:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-31 00:52 - 2014-05-31 00:52 - 00000865 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-31 00:52 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-31 00:52 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-31 00:52 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-30 22:21 - 2014-05-30 22:21 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-05-30 20:09 - 2014-05-30 20:09 - 00652388 _____ () C:\Users\Jirka\scrypt130511Juniperglg2tc6016w256l4pOpenCL1_2AMDAPP1445_5.bin
2014-05-27 19:17 - 2014-05-27 19:17 - 00000000 ____D () C:\ProgramData\ATI
2014-05-27 19:15 - 2014-05-27 19:15 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201405271915053641.log
2014-05-27 19:15 - 2014-05-27 19:15 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-05-27 19:14 - 2014-05-27 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-27 19:12 - 2014-05-27 19:12 - 00000000 ____D () C:\Program Files\AMD
2014-05-27 19:09 - 2014-05-27 19:09 - 00000000 ____D () C:\AMD
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\Users\Public\Desktop\Wolfenstein The New Order.lnk
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein The New Order.lnk
2014-05-27 17:47 - 2014-05-27 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-18 17:31 - 2014-05-18 17:31 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\O&O Software
2014-05-18 17:23 - 2014-05-18 17:24 - 00000703 _____ () C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFZilla
2014-05-18 17:23 - 2013-06-09 09:38 - 00000053 _____ () C:\Users\Jirka\AppData\Roaming\setting.ini
2014-05-18 17:23 - 2013-06-09 09:30 - 00000043 _____ () C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
2014-05-18 17:23 - 2013-06-08 13:43 - 00000030 _____ () C:\Users\Jirka\AppData\Roaming\setup.ini
2014-05-18 17:23 - 2013-02-23 12:15 - 00000003 _____ () C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
2014-05-18 17:23 - 2012-07-07 13:04 - 00000003 _____ () C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
2014-05-18 17:23 - 2008-07-07 13:22 - 00000014 _____ () C:\Users\Jirka\AppData\Roaming\options.ini
2014-05-18 17:08 - 2013-06-09 10:34 - 00000043 _____ () C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
2014-05-13 20:55 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-13 20:55 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-13 20:55 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-13 20:55 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-13 20:55 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-13 20:55 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-13 20:52 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-13 20:52 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-13 20:52 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-13 20:52 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 20:51 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-13 20:51 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-13 20:51 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-13 20:51 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-13 20:51 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-13 20:51 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-13 20:51 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-13 20:51 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-13 20:51 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-13 20:51 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-13 20:51 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-13 20:51 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-13 20:51 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 14:37 - 2014-05-12 14:43 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:39 - 00000000 ____D () C:\Users\Jirka\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-10 19:48 - 2014-05-10 19:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 21:24 - 2014-05-07 21:24 - 00000650 _____ () C:\Users\Jirka\Desktop\MyHeritage Family Tree Builder.lnk
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com
2014-05-07 21:24 - 2012-08-02 08:56 - 00606208 _____ (Lorenzi Davide) C:\Windows\SysWOW64\HexUniRTFBox.ocx
2014-05-07 21:24 - 2010-06-17 19:49 - 02029056 _____ (Bytescout) C:\Windows\SysWOW64\PDFDocScout.DLL
2014-05-07 21:24 - 2004-12-07 11:11 - 00258352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unicows.dll
2014-05-07 21:24 - 2003-07-06 14:07 - 00372736 _____ (Intel Corporation) C:\Windows\SysWOW64\ijl15.dll
2014-05-07 21:24 - 2002-03-07 01:19 - 00454656 _____ () C:\Windows\SysWOW64\PaintX.dll
2014-05-07 21:24 - 1998-06-24 01:00 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmapi32.ocx
2014-05-07 20:27 - 2014-05-07 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 7.5
2014-05-07 20:04 - 2014-05-31 20:22 - 00000270 _____ () C:\Windows\Tasks\AmigabitDataRecovery.job
2014-05-07 20:04 - 2014-05-07 20:09 - 00002640 _____ () C:\Windows\System32\Tasks\AmigabitDataRecovery
2014-05-07 20:04 - 2014-05-07 20:04 - 00000023 _____ () C:\Windows\SysWOW64\AmigabitDataRecoveryStd.dll
2014-05-07 20:04 - 2014-05-07 20:04 - 00000000 ____D () C:\ProgramData\Amigabit
2014-05-07 20:00 - 2014-05-07 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amigabit
2014-05-01 21:11 - 2014-05-07 20:53 - 00014935 _____ () C:\Users\Jirka\Documents\rodokmen.xlsx
==================== One Month Modified Files and Folders =======
2014-05-31 21:02 - 2014-05-31 21:02 - 00014620 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-05-31 21:02 - 2014-05-31 21:01 - 00000000 ____D () C:\FRST
2014-05-31 21:02 - 2013-11-14 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Temp
2014-05-31 21:00 - 2013-11-15 18:00 - 00022478 _____ () C:\Users\Jirka\Network_Meter_Data.js
2014-05-31 20:55 - 2014-05-31 20:50 - 00112640 _____ () C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-05-31 20:49 - 2013-11-14 17:47 - 01119489 _____ () C:\Windows\WindowsUpdate.log
2014-05-31 20:47 - 2014-05-31 20:48 - 02066944 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-05-31 20:32 - 2014-05-31 00:52 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-31 20:32 - 2013-11-14 18:53 - 00000177 ____H () C:\dvmexp.idx
2014-05-31 20:29 - 2009-07-14 06:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-31 20:29 - 2009-07-14 06:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-31 20:28 - 2013-11-14 19:11 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-31 20:23 - 2013-11-15 17:49 - 00012246 _____ () C:\Users\Jirka\IP_Log_Data.js
2014-05-31 20:23 - 2009-07-14 06:51 - 00102914 _____ () C:\Windows\setupact.log
2014-05-31 20:22 - 2014-05-07 20:04 - 00000270 _____ () C:\Windows\Tasks\AmigabitDataRecovery.job
2014-05-31 20:22 - 2010-11-21 05:47 - 00150728 _____ () C:\Windows\PFRO.log
2014-05-31 20:22 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-05-31 20:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-31 14:27 - 2013-11-15 19:00 - 00000027 _____ () C:\Users\Jirka\AppData\Roaming\Network Meter_Usage.ini
2014-05-31 02:17 - 2014-05-31 02:11 - 00000000 ____D () C:\AdwCleaner
2014-05-31 01:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-05-31 00:52 - 2014-05-31 00:52 - 00000865 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-30 22:21 - 2014-05-30 22:21 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-05-30 22:21 - 2013-11-14 19:21 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-05-30 22:21 - 2013-11-14 19:21 - 00003745 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-05-30 22:21 - 2013-11-14 19:21 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-30 20:09 - 2014-05-30 20:09 - 00652388 _____ () C:\Users\Jirka\scrypt130511Juniperglg2tc6016w256l4pOpenCL1_2AMDAPP1445_5.bin
2014-05-30 20:09 - 2013-11-14 17:47 - 00000000 ____D () C:\Users\Jirka
2014-05-30 19:30 - 2013-11-14 18:30 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Raptr
2014-05-30 15:17 - 2013-11-14 18:45 - 00000000 ___HD () C:\ASUS.001
2014-05-27 19:17 - 2014-05-27 19:17 - 00000000 ____D () C:\ProgramData\ATI
2014-05-27 19:17 - 2013-11-14 18:30 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-05-27 19:15 - 2014-05-27 19:15 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201405271915053641.log
2014-05-27 19:15 - 2014-05-27 19:15 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-05-27 19:15 - 2013-11-14 18:29 - 00000000 ____D () C:\ProgramData\AMD
2014-05-27 19:14 - 2014-05-27 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-27 19:14 - 2013-11-14 18:05 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-05-27 19:12 - 2014-05-27 19:12 - 00000000 ____D () C:\Program Files\AMD
2014-05-27 19:11 - 2013-11-14 18:17 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-27 19:09 - 2014-05-27 19:09 - 00000000 ____D () C:\AMD
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\Users\Public\Desktop\Wolfenstein The New Order.lnk
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein The New Order.lnk
2014-05-27 17:47 - 2014-05-27 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-26 16:38 - 2010-11-21 11:27 - 00677382 _____ () C:\Windows\system32\perfh005.dat
2014-05-26 16:38 - 2010-11-21 11:27 - 00146300 _____ () C:\Windows\system32\perfc005.dat
2014-05-26 16:38 - 2009-07-14 07:13 - 01610842 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-23 17:31 - 2013-11-15 23:41 - 00047713 _____ () C:\Users\Jirka\Documents\Stav účtu.xlsx
2014-05-22 20:21 - 2014-04-03 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-22 20:21 - 2013-11-14 19:21 - 00000983 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-05-18 19:55 - 2013-11-18 15:53 - 00000000 ____D () C:\Users\Jirka\Documents\FIFA 14
2014-05-18 18:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-18 17:31 - 2014-05-18 17:31 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:31 - 2013-11-18 15:04 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\AIMP3
2014-05-18 17:31 - 2013-11-15 23:42 - 00000000 ____D () C:\Users\Jirka\Desktop\Nová složka
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\O&O Software
2014-05-18 17:27 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-18 17:24 - 2014-05-18 17:23 - 00000703 _____ () C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFZilla
2014-05-18 15:29 - 2013-11-14 22:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-18 15:29 - 2013-11-14 22:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 21:38 - 2014-04-15 23:12 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-05-17 21:32 - 2013-11-15 23:41 - 00119480 _____ () C:\Users\Jirka\Documents\Elektroměr.xlsx
2014-05-16 20:31 - 2013-12-14 20:53 - 00001036 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk
2014-05-16 20:31 - 2013-12-14 20:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014
2014-05-14 15:39 - 2013-11-14 17:47 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 15:39 - 2013-11-14 17:47 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 00:51 - 2014-04-25 14:59 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 00:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-13 23:04 - 2013-11-15 23:41 - 00078722 _____ () C:\Users\Jirka\Documents\telefony.xlsx
2014-05-13 20:54 - 2013-11-15 17:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-13 20:53 - 2013-11-15 17:58 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 14:43 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Graphisoft
2014-05-12 14:39 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-12 11:54 - 2013-11-14 19:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 07:26 - 2014-05-31 00:52 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-31 00:52 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-31 00:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 19:48 - 2014-05-10 19:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 19:35 - 2013-11-14 19:14 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-05-09 08:14 - 2014-05-13 20:52 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-13 20:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 21:24 - 2014-05-07 21:24 - 00000650 _____ () C:\Users\Jirka\Desktop\MyHeritage Family Tree Builder.lnk
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com
2014-05-07 20:53 - 2014-05-01 21:11 - 00014935 _____ () C:\Users\Jirka\Documents\rodokmen.xlsx
2014-05-07 20:27 - 2014-05-07 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 7.5
2014-05-07 20:09 - 2014-05-07 20:04 - 00002640 _____ () C:\Windows\System32\Tasks\AmigabitDataRecovery
2014-05-07 20:04 - 2014-05-07 20:04 - 00000023 _____ () C:\Windows\SysWOW64\AmigabitDataRecoveryStd.dll
2014-05-07 20:04 - 2014-05-07 20:04 - 00000000 ____D () C:\ProgramData\Amigabit
2014-05-07 20:00 - 2014-05-07 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amigabit
2014-05-06 06:40 - 2014-05-13 20:55 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-13 20:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-13 20:55 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-13 20:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-13 20:55 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-13 20:55 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-01 18:42 - 2013-11-15 23:41 - 00031064 _____ () C:\Users\Jirka\Documents\Plynoměr.xlsx
Files to move or delete:
====================
C:\Users\Jirka\AppData\Roaming\options.ini
C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
C:\Users\Jirka\AppData\Roaming\setup.ini
C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
C:\Users\Jirka\IP_Log_Data.js
C:\Users\Jirka\Network_Meter_Data.js
Some content of TEMP:
====================
C:\Users\Jirka\AppData\Local\Temp\dj_unifysw.exe
C:\Users\Jirka\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Jirka\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Jirka\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Jirka\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Jirka\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Jirka\AppData\Local\Temp\oi_{CF0AEB0D-7BCF-4A72-BB4E-F22BD77898A4}.exe
C:\Users\Jirka\AppData\Local\Temp\ose00000.exe
C:\Users\Jirka\AppData\Local\Temp\Quarantine.exe
C:\Users\Jirka\AppData\Local\Temp\raptrpatch.exe
C:\Users\Jirka\AppData\Local\Temp\raptr_stub.exe
C:\Users\Jirka\AppData\Local\Temp\rjcjhzqb.dll
C:\Users\Jirka\AppData\Local\Temp\y3vimgwd.dll
C:\Users\Jirka\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 21:04
==================== End Of Log ============================
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jirka at 2014-05-31 21:33:32
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 60 GB (57%) free of 105 GB
Total RAM: 8191 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:33:45, on 31.5.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Windows\SysWOW64\ctfmon.exe
D:\TotalCmd UP 5.2\TC UP.exe
D:\TotalCmd UP 5.2\totalcmd.exe
D:\Test-programy\smartsniff\smsniff.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Jirka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - D:\Test-programy\Defrag\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Riverbed Technology, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.7 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9398 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=1cc99f68-6216-411c-8897-b06757e43c7c /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\8090592a-788d-4308-ac44-304e6e565738-17c-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\log\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"taskhost.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgfws.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\ASUS.SYS\config\DVMExportService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe"
taskeng.exe {3C2F3DA3-1A6F-4766-BA5F-1737C7245005}
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe"
D:\Test-programy\Defrag\oodag.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe"
"D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe" /TUStart /pid:2904
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe "-1794882372-1609259297-17882294341239277025-2076732291174763680303607726626507278
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=bd49e368-eeb6-4a69-a996-f276df3b1c4c /coreSdkOptions=4114 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\4e981a1c-8628-4a28-8c56-f56fc134517f-bc8-oopp.tmp" /loggerName=AVG.NS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\"
"D:\Test-programy\Defrag\oodtray.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\Logitech\SetPoint\SetPoint.exe"
"C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe"
KHALMNPR.EXE /API
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"D:\TotalCmd UP 5.2\TC UP.exe"
totalcmd.exe /i="D:\TotalCmd UP 5.2\wincmd.ini"
"D:\Test-programy\smartsniff\smsniff.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Users\Jirka\Desktop\FRST64.exe"
notepad "C:\Users\Jirka\Desktop\FRST.txt"
notepad "C:\Users\Jirka\Desktop\Addition.txt"
"F:\download\antivir\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\AmigabitDataRecovery.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-03-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-03-17 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2009-06-17 130576]
"OODefragTray"=D:\Test-programy\Defrag\oodtray.exe [2014-01-24 4464936]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Jirka\AppData\Roaming\Seznam.cz\szninstall.exe -c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Jirka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\PROGRA~2\Raptr\raptrstub.exe [2014-05-15 55360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-10-31 449760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Drivers]
C:\Users\Jirka\AppData\Roaming\WinUpdate\g\windrv.exe [2014-04-29 6656]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-02-10 2770432]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-05-13 5181456]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"vProt"=C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2014-05-30 2567192]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
O&O Defrag Tray.lnk - C:\Windows\Installer\{177DE549-9107-4370-A840-9FC4AE8BC2BE}\app_icon.ico
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20 76816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-05-31 21:33:32 ----D---- C:\rsit
2014-05-31 21:33:32 ----D---- C:\Program Files\trend micro
2014-05-31 21:01:06 ----D---- C:\FRST
2014-05-31 02:11:41 ----D---- C:\AdwCleaner
2014-05-31 00:52:55 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-05-31 00:52:16 ----D---- C:\ProgramData\Malwarebytes
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-05-30 22:21:33 ----D---- C:\ProgramData\AVG Secure Search
2014-05-29 20:49:58 ----SHD---- C:\Config.Msi
2014-05-27 19:17:11 ----D---- C:\ProgramData\ATI
2014-05-27 19:15:13 ----D---- C:\Program Files (x86)\AMD AVT
2014-05-27 19:12:40 ----D---- C:\Program Files\AMD
2014-05-27 19:09:56 ----D---- C:\AMD
2014-05-27 17:47:35 ----D---- C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-18 17:31:15 ----D---- C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setup.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setting.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options.ini
2014-05-18 17:08:05 ----A---- C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
2014-05-13 20:55:18 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-13 20:55:18 ----A---- C:\Windows\system32\mshtml.dll
2014-05-13 20:55:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-05-13 20:55:17 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-05-13 20:52:10 ----A---- C:\Windows\system32\shell32.dll
2014-05-13 20:52:09 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-05-13 20:52:06 ----A---- C:\Windows\system32\aepdu.dll
2014-05-13 20:52:05 ----A---- C:\Windows\system32\aeinv.dll
2014-05-13 20:51:56 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-13 20:51:56 ----A---- C:\Windows\system32\kerberos.dll
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-05-13 20:51:54 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-05-13 20:51:54 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\winlogon.exe
2014-05-13 20:51:54 ----A---- C:\Windows\system32\TSpkg.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\objsel.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-13 20:51:54 ----A---- C:\Windows\system32\msv1_0.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\wincredprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\wdigest.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\sspicli.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\schannel.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\secur32.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\lsass.exe
2014-05-13 20:51:53 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-13 20:51:53 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-13 20:51:53 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\dimsroam.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\credssp.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\cngprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\capiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\adprovider.dll
2014-05-13 14:20:26 ----A---- C:\Windows\system32\drivers\avgldx64.sys
2014-05-13 14:20:06 ----A---- C:\Windows\system32\drivers\avgtdia.sys
2014-05-13 14:06:06 ----A---- C:\Windows\system32\drivers\avgloga.sys
2014-05-13 14:05:40 ----A---- C:\Windows\system32\drivers\avgidsha.sys
2014-05-13 14:05:08 ----A---- C:\Windows\system32\drivers\avgdiska.sys
2014-05-13 14:05:06 ----A---- C:\Windows\system32\drivers\avgmfx64.sys
2014-05-13 14:04:56 ----A---- C:\Windows\system32\drivers\avgidsdrivera.sys
2014-05-13 14:04:30 ----A---- C:\Windows\system32\drivers\avgrkx64.sys
2014-05-12 14:37:59 ----D---- C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-10 19:48:33 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-05-07 21:24:33 ----D---- C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\unicows.dll
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\PDFDocScout.DLL
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\PaintX.dll
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\ijl15.dll
2014-05-07 20:04:54 ----D---- C:\ProgramData\Amigabit
2014-05-07 20:04:54 ----A---- C:\Windows\SYSWOW64\AmigabitDataRecoveryStd.dll
======List of files/folders modified in the last 1 months======
2014-05-31 21:33:32 ----RD---- C:\Program Files
2014-05-31 21:32:33 ----D---- C:\Windows\Temp
2014-05-31 21:03:04 ----AD---- C:\Windows
2014-05-31 20:36:14 ----D---- C:\Windows\system32\config
2014-05-31 20:28:36 ----D---- C:\ProgramData\MFAData
2014-05-31 20:22:01 ----D---- C:\Windows\system32\drivers
2014-05-31 20:22:01 ----D---- C:\Windows\Offline Web Pages
2014-05-31 14:27:40 ----A---- C:\Users\Jirka\AppData\Roaming\Network Meter_Usage.ini
2014-05-31 02:19:50 ----D---- C:\Windows\Prefetch
2014-05-31 01:13:15 ----D---- C:\Windows\system32\catroot2
2014-05-31 01:12:16 ----D---- C:\Windows\schemas
2014-05-31 00:52:16 ----HD---- C:\ProgramData
2014-05-30 22:21:28 ----D---- C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-30 19:30:58 ----D---- C:\Users\Jirka\AppData\Roaming\Raptr
2014-05-30 15:17:56 ----HD---- C:\ASUS.001
2014-05-29 20:49:58 ----SHD---- C:\Windows\Installer
2014-05-29 20:46:09 ----D---- C:\Windows\SysWOW64
2014-05-29 20:46:09 ----D---- C:\Windows\System32
2014-05-27 22:49:15 ----D---- C:\Windows\system32\catroot
2014-05-27 19:19:01 ----D---- C:\Windows\Microsoft.NET
2014-05-27 19:17:01 ----D---- C:\Program Files (x86)\Raptr
2014-05-27 19:15:14 ----D---- C:\ProgramData\AMD
2014-05-27 19:15:13 ----RD---- C:\Program Files (x86)
2014-05-27 19:14:41 ----D---- C:\Program Files\ATI Technologies
2014-05-27 19:13:31 ----SHD---- C:\$Recycle.Bin
2014-05-27 19:12:52 ----D---- C:\Windows\inf
2014-05-27 19:12:51 ----D---- C:\Windows\system32\DriverStore
2014-05-27 19:11:23 ----D---- C:\ProgramData\Package Cache
2014-05-27 19:11:18 ----SHD---- C:\System Volume Information
2014-05-26 16:38:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-18 18:33:51 ----D---- C:\Windows\rescache
2014-05-18 17:31:40 ----D---- C:\Users\Jirka\AppData\Roaming\AIMP3
2014-05-18 15:29:48 ----D---- C:\Windows\Tasks
2014-05-18 15:29:48 ----D---- C:\Windows\system32\Tasks
2014-05-18 15:29:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-05-16 20:18:35 ----RSD---- C:\Windows\assembly
2014-05-14 15:38:55 ----D---- C:\Windows\winsxs
2014-05-14 00:51:41 ----SD---- C:\Windows\system32\CompatTel
2014-05-14 00:51:40 ----D---- C:\Windows\system32\cs-CZ
2014-05-14 00:51:40 ----D---- C:\Windows\PolicyDefinitions
2014-05-13 20:54:58 ----D---- C:\Windows\system32\MRT
2014-05-13 20:53:33 ----A---- C:\Windows\system32\MRT.exe
2014-05-12 11:54:13 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 19:35:48 ----D---- C:\Users\Jirka\AppData\Roaming\Mozilla
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-05-13 191768]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2014-05-13 323352]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2014-05-13 130328]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-05-13 31512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-11-14 381440]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-04-06 13368]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-05-13 152344]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2013-09-26 57144]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2014-05-13 236312]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-05-13 235800]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2014-05-13 273176]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-05-30 50464]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-14 283064]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2009-06-17 74256]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2009-06-17 13328]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2009-06-17 55312]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2009-06-17 57872]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-05-31 122584]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 63704]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-21 239616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [2013-08-21 14112]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-01-11 1290752]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-08-23 120336]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-12-26 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-12-26 27760]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2013-03-01 36600]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SliceDisk5;SliceDisk5; \??\G:\záloha D\Obnova dat\A-FF Find and Mount\slicedisk-x64.sys [2011-02-25 31824]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Sony so0103 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-04-18 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 344064]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [2014-05-13 1473792]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2014-05-13 3644432]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2014-05-13 292424]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-07-17 319488]
R2 MBAMService;MBAMService; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
R2 MBAMScheduler;MBAMScheduler; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 OODefragAgent;O&O Defrag; D:\Test-programy\Defrag\oodag.exe [2014-01-24 1657128]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-04-13 75136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2013-12-18 2103096]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 vToolbarUpdater18.1.7;vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [2014-05-30 1808408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 160784]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-10 119408]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2013-03-01 118520]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-10-30 566696]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-14 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-05-2014
Ran by Jirka (administrator) on JIRKA-PC on 31-05-2014 21:02:30
Running from C:\Users\Jirka\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe
(O&O Software GmbH) D:\Test-programy\Defrag\oodag.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TuneUp Software) D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Malwarebytes Corporation) D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
(AVG) D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(O&O Software GmbH) D:\Test-programy\Defrag\oodtray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Ultima Prime & Pawel Porwisz) D:\TotalCmd UP 5.2\TC UP.exe
(Ghisler Software GmbH) D:\TotalCmd UP 5.2\TOTALCMD.EXE
(NirSoft) D:\Test-programy\smartsniff\smsniff.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [OODefragTray] => D:\Test-programy\Defrag\oodtray.exe [4464936 2014-01-24] (O&O Software GmbH)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2770432 2010-02-10] (VIA)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2567192 2014-05-30] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {55a2a431-6da5-11e3-985e-e0cb4e4e44b9} - M:\Startme.exe
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {c04cd1e2-4d57-11e3-a81e-e0cb4e4e44b9} - setup.exe
HKU\S-1-5-21-945404864-676078813-3515532490-1001\...\MountPoints2: {c04cd1ec-4d57-11e3-a81e-e0cb4e4e44b9} - K:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\O&O Defrag Tray.lnk
ShortcutTarget: O&O Defrag Tray.lnk -> C:\Windows\Installer\{177DE549-9107-4370-A840-9FC4AE8BC2BE}\app_icon.ico ()
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - {837F75D4-345A-4D43-B46B-BEF00F4FDEEB} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKLM-x32 - EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 77.48.100.254
FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=Quicksearch_13415&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - d:\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - d:\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - D:\Video-programy\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: sony.com/MediaGoDetector - D:\Mobil-programy\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\firmycz.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\mapycz.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\searchplugins\zbocz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27]
FF Extension: Quick Translator - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi [2013-11-15]
FF Extension: Download Status Bar - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2014-01-24]
FF Extension: Download Statusbar - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\dxdpsqkh.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-11-14]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598 [2014-05-30]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.)
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1473792 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-07-17] (DeviceVM, Inc.)
R2 MBAMScheduler; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 OODefragAgent; D:\Test-programy\Defrag\oodag.exe [1657128 2014-01-24] (O&O Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-04-13] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 TuneUp.UtilitiesSvc; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2103096 2013-12-18] (TuneUp Software)
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1808408 2014-05-30] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-05-30] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-14] (Disc Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-05-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 SliceDisk5; G:\záloha D\Obnova dat\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-11-14] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
U3 a0hp2e4z; C:\Windows\System32\Drivers\a0hp2e4z.sys [0 ] (Advanced Micro Devices)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-31 21:02 - 2014-05-31 21:02 - 00014620 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-05-31 21:01 - 2014-05-31 21:02 - 00000000 ____D () C:\FRST
2014-05-31 20:50 - 2014-05-31 20:55 - 00112640 _____ () C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-05-31 20:48 - 2014-05-31 20:47 - 02066944 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-05-31 02:11 - 2014-05-31 02:17 - 00000000 ____D () C:\AdwCleaner
2014-05-31 00:52 - 2014-05-31 20:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-31 00:52 - 2014-05-31 00:52 - 00000865 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-31 00:52 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-31 00:52 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-31 00:52 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-30 22:21 - 2014-05-30 22:21 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-05-30 20:09 - 2014-05-30 20:09 - 00652388 _____ () C:\Users\Jirka\scrypt130511Juniperglg2tc6016w256l4pOpenCL1_2AMDAPP1445_5.bin
2014-05-27 19:17 - 2014-05-27 19:17 - 00000000 ____D () C:\ProgramData\ATI
2014-05-27 19:15 - 2014-05-27 19:15 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201405271915053641.log
2014-05-27 19:15 - 2014-05-27 19:15 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-05-27 19:14 - 2014-05-27 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-27 19:12 - 2014-05-27 19:12 - 00000000 ____D () C:\Program Files\AMD
2014-05-27 19:09 - 2014-05-27 19:09 - 00000000 ____D () C:\AMD
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\Users\Public\Desktop\Wolfenstein The New Order.lnk
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein The New Order.lnk
2014-05-27 17:47 - 2014-05-27 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-18 17:31 - 2014-05-18 17:31 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\O&O Software
2014-05-18 17:23 - 2014-05-18 17:24 - 00000703 _____ () C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFZilla
2014-05-18 17:23 - 2013-06-09 09:38 - 00000053 _____ () C:\Users\Jirka\AppData\Roaming\setting.ini
2014-05-18 17:23 - 2013-06-09 09:30 - 00000043 _____ () C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
2014-05-18 17:23 - 2013-06-08 13:43 - 00000030 _____ () C:\Users\Jirka\AppData\Roaming\setup.ini
2014-05-18 17:23 - 2013-02-23 12:15 - 00000003 _____ () C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
2014-05-18 17:23 - 2012-07-07 13:04 - 00000003 _____ () C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
2014-05-18 17:23 - 2008-07-07 13:22 - 00000014 _____ () C:\Users\Jirka\AppData\Roaming\options.ini
2014-05-18 17:08 - 2013-06-09 10:34 - 00000043 _____ () C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
2014-05-13 20:55 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-13 20:55 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-13 20:55 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-13 20:55 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-13 20:55 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-13 20:55 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-13 20:52 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-13 20:52 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-13 20:52 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-13 20:52 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 20:51 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-13 20:51 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-13 20:51 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-13 20:51 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-13 20:51 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-13 20:51 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-13 20:51 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-13 20:51 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-13 20:51 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-13 20:51 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-13 20:51 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-13 20:51 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-13 20:51 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-13 20:51 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-13 20:51 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-13 20:51 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-13 20:51 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 14:37 - 2014-05-12 14:43 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:39 - 00000000 ____D () C:\Users\Jirka\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-10 19:48 - 2014-05-10 19:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 21:24 - 2014-05-07 21:24 - 00000650 _____ () C:\Users\Jirka\Desktop\MyHeritage Family Tree Builder.lnk
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com
2014-05-07 21:24 - 2012-08-02 08:56 - 00606208 _____ (Lorenzi Davide) C:\Windows\SysWOW64\HexUniRTFBox.ocx
2014-05-07 21:24 - 2010-06-17 19:49 - 02029056 _____ (Bytescout) C:\Windows\SysWOW64\PDFDocScout.DLL
2014-05-07 21:24 - 2004-12-07 11:11 - 00258352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unicows.dll
2014-05-07 21:24 - 2003-07-06 14:07 - 00372736 _____ (Intel Corporation) C:\Windows\SysWOW64\ijl15.dll
2014-05-07 21:24 - 2002-03-07 01:19 - 00454656 _____ () C:\Windows\SysWOW64\PaintX.dll
2014-05-07 21:24 - 1998-06-24 01:00 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmapi32.ocx
2014-05-07 20:27 - 2014-05-07 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 7.5
2014-05-07 20:04 - 2014-05-31 20:22 - 00000270 _____ () C:\Windows\Tasks\AmigabitDataRecovery.job
2014-05-07 20:04 - 2014-05-07 20:09 - 00002640 _____ () C:\Windows\System32\Tasks\AmigabitDataRecovery
2014-05-07 20:04 - 2014-05-07 20:04 - 00000023 _____ () C:\Windows\SysWOW64\AmigabitDataRecoveryStd.dll
2014-05-07 20:04 - 2014-05-07 20:04 - 00000000 ____D () C:\ProgramData\Amigabit
2014-05-07 20:00 - 2014-05-07 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amigabit
2014-05-01 21:11 - 2014-05-07 20:53 - 00014935 _____ () C:\Users\Jirka\Documents\rodokmen.xlsx
==================== One Month Modified Files and Folders =======
2014-05-31 21:02 - 2014-05-31 21:02 - 00014620 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-05-31 21:02 - 2014-05-31 21:01 - 00000000 ____D () C:\FRST
2014-05-31 21:02 - 2013-11-14 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Temp
2014-05-31 21:00 - 2013-11-15 18:00 - 00022478 _____ () C:\Users\Jirka\Network_Meter_Data.js
2014-05-31 20:55 - 2014-05-31 20:50 - 00112640 _____ () C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-05-31 20:49 - 2013-11-14 17:47 - 01119489 _____ () C:\Windows\WindowsUpdate.log
2014-05-31 20:47 - 2014-05-31 20:48 - 02066944 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-05-31 20:32 - 2014-05-31 00:52 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-31 20:32 - 2013-11-14 18:53 - 00000177 ____H () C:\dvmexp.idx
2014-05-31 20:29 - 2009-07-14 06:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-31 20:29 - 2009-07-14 06:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-31 20:28 - 2013-11-14 19:11 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-31 20:23 - 2013-11-15 17:49 - 00012246 _____ () C:\Users\Jirka\IP_Log_Data.js
2014-05-31 20:23 - 2009-07-14 06:51 - 00102914 _____ () C:\Windows\setupact.log
2014-05-31 20:22 - 2014-05-07 20:04 - 00000270 _____ () C:\Windows\Tasks\AmigabitDataRecovery.job
2014-05-31 20:22 - 2010-11-21 05:47 - 00150728 _____ () C:\Windows\PFRO.log
2014-05-31 20:22 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-05-31 20:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-31 14:27 - 2013-11-15 19:00 - 00000027 _____ () C:\Users\Jirka\AppData\Roaming\Network Meter_Usage.ini
2014-05-31 02:17 - 2014-05-31 02:11 - 00000000 ____D () C:\AdwCleaner
2014-05-31 01:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-05-31 00:52 - 2014-05-31 00:52 - 00000865 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-31 00:52 - 2014-05-31 00:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-30 22:21 - 2014-05-30 22:21 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-05-30 22:21 - 2013-11-14 19:21 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-05-30 22:21 - 2013-11-14 19:21 - 00003745 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-05-30 22:21 - 2013-11-14 19:21 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-30 20:09 - 2014-05-30 20:09 - 00652388 _____ () C:\Users\Jirka\scrypt130511Juniperglg2tc6016w256l4pOpenCL1_2AMDAPP1445_5.bin
2014-05-30 20:09 - 2013-11-14 17:47 - 00000000 ____D () C:\Users\Jirka
2014-05-30 19:30 - 2013-11-14 18:30 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Raptr
2014-05-30 15:17 - 2013-11-14 18:45 - 00000000 ___HD () C:\ASUS.001
2014-05-27 19:17 - 2014-05-27 19:17 - 00000000 ____D () C:\ProgramData\ATI
2014-05-27 19:17 - 2013-11-14 18:30 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-05-27 19:15 - 2014-05-27 19:15 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201405271915053641.log
2014-05-27 19:15 - 2014-05-27 19:15 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-05-27 19:15 - 2013-11-14 18:29 - 00000000 ____D () C:\ProgramData\AMD
2014-05-27 19:14 - 2014-05-27 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-27 19:14 - 2013-11-14 18:05 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-05-27 19:12 - 2014-05-27 19:12 - 00000000 ____D () C:\Program Files\AMD
2014-05-27 19:11 - 2013-11-14 18:17 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-27 19:09 - 2014-05-27 19:09 - 00000000 ____D () C:\AMD
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\Users\Public\Desktop\Wolfenstein The New Order.lnk
2014-05-27 18:13 - 2014-05-27 18:13 - 00000485 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein The New Order.lnk
2014-05-27 17:47 - 2014-05-27 17:47 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-26 16:38 - 2010-11-21 11:27 - 00677382 _____ () C:\Windows\system32\perfh005.dat
2014-05-26 16:38 - 2010-11-21 11:27 - 00146300 _____ () C:\Windows\system32\perfc005.dat
2014-05-26 16:38 - 2009-07-14 07:13 - 01610842 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-23 17:31 - 2013-11-15 23:41 - 00047713 _____ () C:\Users\Jirka\Documents\Stav účtu.xlsx
2014-05-22 20:21 - 2014-04-03 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-22 20:21 - 2013-11-14 19:21 - 00000983 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-05-18 19:55 - 2013-11-18 15:53 - 00000000 ____D () C:\Users\Jirka\Documents\FIFA 14
2014-05-18 18:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-18 17:31 - 2014-05-18 17:31 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:31 - 2013-11-18 15:04 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\AIMP3
2014-05-18 17:31 - 2013-11-15 23:42 - 00000000 ____D () C:\Users\Jirka\Desktop\Nová složka
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\O&O Software
2014-05-18 17:27 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-18 17:24 - 2014-05-18 17:23 - 00000703 _____ () C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFZilla
2014-05-18 15:29 - 2013-11-14 22:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-18 15:29 - 2013-11-14 22:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 21:38 - 2014-04-15 23:12 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-05-17 21:32 - 2013-11-15 23:41 - 00119480 _____ () C:\Users\Jirka\Documents\Elektroměr.xlsx
2014-05-16 20:31 - 2013-12-14 20:53 - 00001036 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk
2014-05-16 20:31 - 2013-12-14 20:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014
2014-05-14 15:39 - 2013-11-14 17:47 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 15:39 - 2013-11-14 17:47 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 00:51 - 2014-04-25 14:59 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 00:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-13 23:04 - 2013-11-15 23:41 - 00078722 _____ () C:\Users\Jirka\Documents\telefony.xlsx
2014-05-13 20:54 - 2013-11-15 17:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-13 20:53 - 2013-11-15 17:58 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 14:43 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Graphisoft
2014-05-12 14:39 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\Graphisoft
2014-05-12 14:37 - 2014-05-12 14:37 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-12 11:54 - 2013-11-14 19:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 07:26 - 2014-05-31 00:52 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-31 00:52 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-31 00:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 19:48 - 2014-05-10 19:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 19:35 - 2013-11-14 19:14 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-05-09 08:14 - 2014-05-13 20:52 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-13 20:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 21:24 - 2014-05-07 21:24 - 00000650 _____ () C:\Users\Jirka\Desktop\MyHeritage Family Tree Builder.lnk
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24 - 2014-05-07 21:24 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com
2014-05-07 20:53 - 2014-05-01 21:11 - 00014935 _____ () C:\Users\Jirka\Documents\rodokmen.xlsx
2014-05-07 20:27 - 2014-05-07 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 7.5
2014-05-07 20:09 - 2014-05-07 20:04 - 00002640 _____ () C:\Windows\System32\Tasks\AmigabitDataRecovery
2014-05-07 20:04 - 2014-05-07 20:04 - 00000023 _____ () C:\Windows\SysWOW64\AmigabitDataRecoveryStd.dll
2014-05-07 20:04 - 2014-05-07 20:04 - 00000000 ____D () C:\ProgramData\Amigabit
2014-05-07 20:00 - 2014-05-07 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amigabit
2014-05-06 06:40 - 2014-05-13 20:55 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-13 20:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-13 20:55 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-13 20:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-13 20:55 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-13 20:55 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-01 18:42 - 2013-11-15 23:41 - 00031064 _____ () C:\Users\Jirka\Documents\Plynoměr.xlsx
Files to move or delete:
====================
C:\Users\Jirka\AppData\Roaming\options.ini
C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
C:\Users\Jirka\AppData\Roaming\setup.ini
C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
C:\Users\Jirka\IP_Log_Data.js
C:\Users\Jirka\Network_Meter_Data.js
Some content of TEMP:
====================
C:\Users\Jirka\AppData\Local\Temp\dj_unifysw.exe
C:\Users\Jirka\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Jirka\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Jirka\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Jirka\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Jirka\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Jirka\AppData\Local\Temp\oi_{CF0AEB0D-7BCF-4A72-BB4E-F22BD77898A4}.exe
C:\Users\Jirka\AppData\Local\Temp\ose00000.exe
C:\Users\Jirka\AppData\Local\Temp\Quarantine.exe
C:\Users\Jirka\AppData\Local\Temp\raptrpatch.exe
C:\Users\Jirka\AppData\Local\Temp\raptr_stub.exe
C:\Users\Jirka\AppData\Local\Temp\rjcjhzqb.dll
C:\Users\Jirka\AppData\Local\Temp\y3vimgwd.dll
C:\Users\Jirka\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 21:04
==================== End Of Log ============================
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jirka at 2014-05-31 21:33:32
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 60 GB (57%) free of 105 GB
Total RAM: 8191 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:33:45, on 31.5.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Windows\SysWOW64\ctfmon.exe
D:\TotalCmd UP 5.2\TC UP.exe
D:\TotalCmd UP 5.2\totalcmd.exe
D:\Test-programy\smartsniff\smsniff.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Jirka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - D:\Test-programy\Defrag\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Riverbed Technology, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.7 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9398 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=1cc99f68-6216-411c-8897-b06757e43c7c /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\8090592a-788d-4308-ac44-304e6e565738-17c-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\log\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"taskhost.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgfws.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\ASUS.SYS\config\DVMExportService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe"
taskeng.exe {3C2F3DA3-1A6F-4766-BA5F-1737C7245005}
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe"
D:\Test-programy\Defrag\oodag.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe"
"D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe" /TUStart /pid:2904
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe "-1794882372-1609259297-17882294341239277025-2076732291174763680303607726626507278
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=bd49e368-eeb6-4a69-a996-f276df3b1c4c /coreSdkOptions=4114 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\4e981a1c-8628-4a28-8c56-f56fc134517f-bc8-oopp.tmp" /loggerName=AVG.NS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\"
"D:\Test-programy\Defrag\oodtray.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\Logitech\SetPoint\SetPoint.exe"
"C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe"
KHALMNPR.EXE /API
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"D:\TotalCmd UP 5.2\TC UP.exe"
totalcmd.exe /i="D:\TotalCmd UP 5.2\wincmd.ini"
"D:\Test-programy\smartsniff\smsniff.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Users\Jirka\Desktop\FRST64.exe"
notepad "C:\Users\Jirka\Desktop\FRST.txt"
notepad "C:\Users\Jirka\Desktop\Addition.txt"
"F:\download\antivir\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\AmigabitDataRecovery.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-03-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-03-17 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2009-06-17 130576]
"OODefragTray"=D:\Test-programy\Defrag\oodtray.exe [2014-01-24 4464936]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Jirka\AppData\Roaming\Seznam.cz\szninstall.exe -c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Jirka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\PROGRA~2\Raptr\raptrstub.exe [2014-05-15 55360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-10-31 449760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Drivers]
C:\Users\Jirka\AppData\Roaming\WinUpdate\g\windrv.exe [2014-04-29 6656]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-02-10 2770432]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-05-13 5181456]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"vProt"=C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2014-05-30 2567192]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
O&O Defrag Tray.lnk - C:\Windows\Installer\{177DE549-9107-4370-A840-9FC4AE8BC2BE}\app_icon.ico
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20 76816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-05-31 21:33:32 ----D---- C:\rsit
2014-05-31 21:33:32 ----D---- C:\Program Files\trend micro
2014-05-31 21:01:06 ----D---- C:\FRST
2014-05-31 02:11:41 ----D---- C:\AdwCleaner
2014-05-31 00:52:55 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-05-31 00:52:16 ----D---- C:\ProgramData\Malwarebytes
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-05-31 00:52:16 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-05-30 22:21:33 ----D---- C:\ProgramData\AVG Secure Search
2014-05-29 20:49:58 ----SHD---- C:\Config.Msi
2014-05-27 19:17:11 ----D---- C:\ProgramData\ATI
2014-05-27 19:15:13 ----D---- C:\Program Files (x86)\AMD AVT
2014-05-27 19:12:40 ----D---- C:\Program Files\AMD
2014-05-27 19:09:56 ----D---- C:\AMD
2014-05-27 17:47:35 ----D---- C:\Users\Jirka\AppData\Roaming\WinUpdate
2014-05-18 17:31:15 ----D---- C:\Users\Jirka\AppData\Roaming\YCanPDF
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setup_pdfcombine.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setup.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\setting.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\pdfsound.dll
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options_pdfrotator.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options_pdfcombine.ini
2014-05-18 17:23:25 ----A---- C:\Users\Jirka\AppData\Roaming\options.ini
2014-05-18 17:08:05 ----A---- C:\Users\Jirka\AppData\Roaming\setup_pdfrotator.ini
2014-05-13 20:55:18 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-13 20:55:18 ----A---- C:\Windows\system32\mshtml.dll
2014-05-13 20:55:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-05-13 20:55:17 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-05-13 20:52:10 ----A---- C:\Windows\system32\shell32.dll
2014-05-13 20:52:09 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-05-13 20:52:06 ----A---- C:\Windows\system32\aepdu.dll
2014-05-13 20:52:05 ----A---- C:\Windows\system32\aeinv.dll
2014-05-13 20:51:56 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-13 20:51:56 ----A---- C:\Windows\system32\kerberos.dll
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-05-13 20:51:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-05-13 20:51:54 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-05-13 20:51:54 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\winlogon.exe
2014-05-13 20:51:54 ----A---- C:\Windows\system32\TSpkg.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\objsel.dll
2014-05-13 20:51:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-13 20:51:54 ----A---- C:\Windows\system32\msv1_0.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\wincredprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\wdigest.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\sspicli.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\schannel.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\secur32.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\lsass.exe
2014-05-13 20:51:53 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-13 20:51:53 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-13 20:51:53 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\dimsroam.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\credssp.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\cngprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\capiprovider.dll
2014-05-13 20:51:53 ----A---- C:\Windows\system32\adprovider.dll
2014-05-13 14:20:26 ----A---- C:\Windows\system32\drivers\avgldx64.sys
2014-05-13 14:20:06 ----A---- C:\Windows\system32\drivers\avgtdia.sys
2014-05-13 14:06:06 ----A---- C:\Windows\system32\drivers\avgloga.sys
2014-05-13 14:05:40 ----A---- C:\Windows\system32\drivers\avgidsha.sys
2014-05-13 14:05:08 ----A---- C:\Windows\system32\drivers\avgdiska.sys
2014-05-13 14:05:06 ----A---- C:\Windows\system32\drivers\avgmfx64.sys
2014-05-13 14:04:56 ----A---- C:\Windows\system32\drivers\avgidsdrivera.sys
2014-05-13 14:04:30 ----A---- C:\Windows\system32\drivers\avgrkx64.sys
2014-05-12 14:37:59 ----D---- C:\Users\Jirka\AppData\Roaming\Graphisoft
2014-05-10 19:48:33 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-05-07 21:24:33 ----D---- C:\Users\Jirka\AppData\Roaming\The Complete Genealogy Reporter - FTB
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\unicows.dll
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\PDFDocScout.DLL
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\PaintX.dll
2014-05-07 21:24:33 ----A---- C:\Windows\SYSWOW64\ijl15.dll
2014-05-07 20:04:54 ----D---- C:\ProgramData\Amigabit
2014-05-07 20:04:54 ----A---- C:\Windows\SYSWOW64\AmigabitDataRecoveryStd.dll
======List of files/folders modified in the last 1 months======
2014-05-31 21:33:32 ----RD---- C:\Program Files
2014-05-31 21:32:33 ----D---- C:\Windows\Temp
2014-05-31 21:03:04 ----AD---- C:\Windows
2014-05-31 20:36:14 ----D---- C:\Windows\system32\config
2014-05-31 20:28:36 ----D---- C:\ProgramData\MFAData
2014-05-31 20:22:01 ----D---- C:\Windows\system32\drivers
2014-05-31 20:22:01 ----D---- C:\Windows\Offline Web Pages
2014-05-31 14:27:40 ----A---- C:\Users\Jirka\AppData\Roaming\Network Meter_Usage.ini
2014-05-31 02:19:50 ----D---- C:\Windows\Prefetch
2014-05-31 01:13:15 ----D---- C:\Windows\system32\catroot2
2014-05-31 01:12:16 ----D---- C:\Windows\schemas
2014-05-31 00:52:16 ----HD---- C:\ProgramData
2014-05-30 22:21:28 ----D---- C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-30 19:30:58 ----D---- C:\Users\Jirka\AppData\Roaming\Raptr
2014-05-30 15:17:56 ----HD---- C:\ASUS.001
2014-05-29 20:49:58 ----SHD---- C:\Windows\Installer
2014-05-29 20:46:09 ----D---- C:\Windows\SysWOW64
2014-05-29 20:46:09 ----D---- C:\Windows\System32
2014-05-27 22:49:15 ----D---- C:\Windows\system32\catroot
2014-05-27 19:19:01 ----D---- C:\Windows\Microsoft.NET
2014-05-27 19:17:01 ----D---- C:\Program Files (x86)\Raptr
2014-05-27 19:15:14 ----D---- C:\ProgramData\AMD
2014-05-27 19:15:13 ----RD---- C:\Program Files (x86)
2014-05-27 19:14:41 ----D---- C:\Program Files\ATI Technologies
2014-05-27 19:13:31 ----SHD---- C:\$Recycle.Bin
2014-05-27 19:12:52 ----D---- C:\Windows\inf
2014-05-27 19:12:51 ----D---- C:\Windows\system32\DriverStore
2014-05-27 19:11:23 ----D---- C:\ProgramData\Package Cache
2014-05-27 19:11:18 ----SHD---- C:\System Volume Information
2014-05-26 16:38:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-18 18:33:51 ----D---- C:\Windows\rescache
2014-05-18 17:31:40 ----D---- C:\Users\Jirka\AppData\Roaming\AIMP3
2014-05-18 15:29:48 ----D---- C:\Windows\Tasks
2014-05-18 15:29:48 ----D---- C:\Windows\system32\Tasks
2014-05-18 15:29:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-05-16 20:18:35 ----RSD---- C:\Windows\assembly
2014-05-14 15:38:55 ----D---- C:\Windows\winsxs
2014-05-14 00:51:41 ----SD---- C:\Windows\system32\CompatTel
2014-05-14 00:51:40 ----D---- C:\Windows\system32\cs-CZ
2014-05-14 00:51:40 ----D---- C:\Windows\PolicyDefinitions
2014-05-13 20:54:58 ----D---- C:\Windows\system32\MRT
2014-05-13 20:53:33 ----A---- C:\Windows\system32\MRT.exe
2014-05-12 11:54:13 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 19:35:48 ----D---- C:\Users\Jirka\AppData\Roaming\Mozilla
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-05-13 191768]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2014-05-13 323352]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2014-05-13 130328]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-05-13 31512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-11-14 381440]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-04-06 13368]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-05-13 152344]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2013-09-26 57144]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2014-05-13 236312]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-05-13 235800]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2014-05-13 273176]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-05-30 50464]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-14 283064]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2009-06-17 74256]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2009-06-17 13328]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2009-06-17 55312]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2009-06-17 57872]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-05-31 122584]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 63704]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-21 239616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [2013-08-21 14112]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-01-11 1290752]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-08-23 120336]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-12-26 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-12-26 27760]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2013-03-01 36600]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SliceDisk5;SliceDisk5; \??\G:\záloha D\Obnova dat\A-FF Find and Mount\slicedisk-x64.sys [2011-02-25 31824]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Sony so0103 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-04-18 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 344064]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [2014-05-13 1473792]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2014-05-13 3644432]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2014-05-13 292424]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-07-17 319488]
R2 MBAMService;MBAMService; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
R2 MBAMScheduler;MBAMScheduler; D:\Test-programy\antivir\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 OODefragAgent;O&O Defrag; D:\Test-programy\Defrag\oodag.exe [2014-01-24 1657128]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-04-13 75136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\Test-programy\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2013-12-18 2103096]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 vToolbarUpdater18.1.7;vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [2014-05-30 1808408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 160784]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-10 119408]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2013-03-01 118520]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-10-30 566696]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-14 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------