Prosím o kontrolu - vyskakovaci reklamni okno
Napsal: 19 zář 2014 18:54
Dobry den,
uz jsem vyzkousel CCleaner, ADWcleaner, ComboFix a porad se reklamnich oken, ktere se spusti pres celou obrazovku zbavit.
Tady je log z FRSTu.
Dekuji
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Mara (administrator) on MAROUSKOVNIK on 19-09-2014 19:50:04
Running from C:\Users\Mara\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\VivoBook.exe
(ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [msgbdnaSrv] => C:\Windows\inf\msgbdna.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [msphyeSrv] => C:\Windows\inf\msphye.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [msljggxfSrv] => C:\Windows\inf\msljggxf.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [MSStp] => C:\Windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM-x32\...\Run: [mnctiqthhSrv] => C:\Windows\SysWOW64\mnctiqthh.vbe [7670 2014-03-05] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mskeetgSrv] => C:\Windows\SysWOW64\mskeetg.vbe [649 2014-06-23] ()
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1437255118-3724227524-3503180372-1001\...\Run: [AdobeBridge] => C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe [11989960 2010-03-09] (Adobe Systems, Inc.)
HKU\S-1-5-21-1437255118-3724227524-3503180372-1001\...\Run: [uTorrent] => C:\Users\Mara\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-08-26] (BitTorrent Inc.)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\2020Player_IKEA@2020Technologies.com [2014-05-07]
FF Extension: Apps Hat - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com [2014-09-16]
FF Extension: Flash and Video Download - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-09-19]
FF Extension: Firebug - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\firebug@software.joehewitt.com.xpi [2014-08-04]
FF Extension: WinToFlash Suggestor - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\{285ACFBB-8E53-4feb-90E6-F02A128927F3}.xpi [2012-04-09]
Chrome:
=======
CHR HomePage: Default ->
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/", "hxxp://www.google.cz/", "hxxp://www.idnes.cz/"
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR DefaultSearchKeyword: Default -> A8458D7A91BFD45AC1418A24BA23B3592582F283479ACE85664C029CC62C2F05
CHR DefaultSearchURL: Default -> 46547644521F67599EC57EB4DBE401A642E6E301E9DF3A054AD6623D41259A23
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Talk Plugin) - C:\Users\Blb\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll No File
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Blb\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-09-16]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-17]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-17]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-17]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-09-16]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R3 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [226944 2012-12-28] (Qualcomm Atheros Commnucations)
R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 WakeupService; C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe [45488 2012-12-20] (ASUSTek Computer Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R3 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-28] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 adusbser; C:\Windows\system32\DRIVERS\adusbser.sys [154112 2009-11-06] (AnyDATA.NET INC.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-11-23] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-28] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
U0 msahci; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-19 19:50 - 2014-09-19 19:50 - 00018167 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-09-19 19:49 - 2014-09-19 19:50 - 00000000 ____D () C:\FRST
2014-09-19 19:48 - 2014-09-19 19:49 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-09-19 19:48 - 2014-09-19 19:48 - 02105856 _____ (Farbar) C:\Users\Mara\Desktop\FRST64.exe
2014-09-19 19:36 - 2014-09-19 19:36 - 00018486 _____ () C:\ComboFix.txt
2014-09-19 19:21 - 2014-09-19 19:36 - 00000000 ____D () C:\Qoobox
2014-09-19 19:21 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-19 19:21 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-19 19:21 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-19 19:20 - 2014-09-19 19:33 - 00000000 ____D () C:\Windows\erdnt
2014-09-19 19:19 - 2014-09-19 19:19 - 05578824 ____R (Swearware) C:\Users\Mara\Desktop\ComboFix.exe
2014-09-19 14:53 - 2014-09-19 14:53 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00001385 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-09-19 14:52 - 2014-09-19 16:53 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-09-19 14:52 - 2014-09-19 14:58 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-19 14:52 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Mara\Desktop\spybot-2.4.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 00384529 _____ () C:\Users\Mara\Desktop\Lista_centrum.exe
2014-09-19 14:47 - 2014-09-19 14:48 - 00733368 _____ () C:\Users\Mara\Desktop\spybot-search-and-destroy-lista-centrumcz.exe
2014-09-16 22:51 - 2014-09-16 22:51 - 01373475 _____ () C:\Users\Mara\Desktop\adwcleaner_3.310.exe
2014-09-16 22:18 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Queen - The Ultimate Best Of Queen (2011) [mp3][www.lokotorrents.com]
2014-09-16 22:17 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Justin TImberlake - The 20-20 Experience (Deluxe Edition) 2013 Pop 320kbps CBR MP3 [VX]
2014-09-16 22:04 - 2014-09-16 22:05 - 00000000 ____D () C:\Users\Mara\Desktop\XSCAPE (Deluxe)
2014-09-16 22:02 - 2014-09-16 22:02 - 00000000 ____D () C:\Users\Mara\Desktop\Coldplay - Ghost Stories [2014] [Deluxe Edition] [Mp3-320]-V3nom [GLT]
2014-09-16 22:00 - 2014-09-16 22:01 - 00000000 ____D () C:\Users\Mara\Desktop\Chris Brown - X [Deluxe@320] 2014
2014-09-16 21:54 - 2014-09-16 21:54 - 00000000 ____D () C:\Users\Mara\Desktop\Filmy
2014-09-16 19:41 - 2014-09-19 19:20 - 00325337 _____ () C:\Windows\WindowsUpdate.log
2014-09-16 19:36 - 2014-09-16 19:37 - 00000000 ____D () C:\Users\Mara\Documents\wintoflash_0.7.0026beta
2014-09-16 19:31 - 2014-09-19 19:31 - 00001356 _____ () C:\Windows\Tasks\AXYC.job
2014-09-16 19:31 - 2014-09-16 19:31 - 01513832 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\AXYC.exe
2014-09-16 19:31 - 2014-09-16 19:31 - 00004370 _____ () C:\Windows\System32\Tasks\AXYC
2014-09-16 19:30 - 2014-09-19 19:30 - 00001706 _____ () C:\Windows\Tasks\QBTNOXC.job
2014-09-16 19:30 - 2014-09-16 19:30 - 01969000 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
2014-09-16 19:30 - 2014-09-16 19:30 - 00004718 _____ () C:\Windows\System32\Tasks\QBTNOXC
2014-09-16 19:21 - 2014-09-16 19:25 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-16 19:17 - 2014-09-16 19:24 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-09-16 19:17 - 2014-09-16 19:24 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-09-16 19:17 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashRpt
2014-09-16 18:03 - 2014-09-16 18:42 - 693682871 _____ () C:\Users\Mara\Desktop\Microsoft-Windows-XP-Professional-SP3-CZ-x86-Integrovane-Januar-2010.zip
2014-09-16 18:02 - 2014-09-16 18:36 - 602720256 _____ () C:\Users\Mara\Desktop\Windows.XP.Home.SP3.v5.1.2600.Czech-mXx.iso
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe Mini Bridge CS5
2014-09-11 08:56 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 08:56 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 08:56 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 08:56 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 08:56 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 08:56 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 08:56 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 08:56 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 08:56 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 08:56 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 08:56 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 08:56 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 08:56 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 08:56 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 08:56 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 08:56 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 08:56 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 08:56 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 08:56 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 08:55 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 08:55 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 08:31 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:31 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:29 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:29 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-11 08:27 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:27 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:27 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:27 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:27 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:26 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-11 08:26 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-10 16:12 - 2014-09-10 16:12 - 03813555 _____ () C:\Users\Mara\Desktop\NEVDAMA promoteaser.psd
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Mara\AppData\Roaming\AXYC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Mara\AppData\Roaming\QBTNOXC
2014-08-28 08:13 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 18:31 - 2014-08-26 18:31 - 00000794 _____ () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-08-21 11:58 - 2014-09-02 21:32 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-21 11:58 - 2014-09-02 21:32 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-21 11:25 - 2014-08-21 11:25 - 01819937 _____ () C:\Users\Mara\Desktop\lyze rozdelany.psd
2014-08-21 11:25 - 2014-08-21 11:25 - 00452080 _____ () C:\Users\Mara\Desktop\lyze rozdelany 2.psd
2014-08-20 09:12 - 2014-08-20 09:12 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-20 09:12 - 2014-08-20 09:12 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\Program Files\CCleaner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-19 19:50 - 2014-09-19 19:50 - 00018167 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-09-19 19:50 - 2014-09-19 19:49 - 00000000 ____D () C:\FRST
2014-09-19 19:49 - 2014-09-19 19:48 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-09-19 19:48 - 2014-09-19 19:48 - 02105856 _____ (Farbar) C:\Users\Mara\Desktop\FRST64.exe
2014-09-19 19:40 - 2014-01-17 22:03 - 00000974 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-19 19:36 - 2014-09-19 19:36 - 00018486 _____ () C:\ComboFix.txt
2014-09-19 19:36 - 2014-09-19 19:21 - 00000000 ____D () C:\Qoobox
2014-09-19 19:36 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-09-19 19:33 - 2014-09-19 19:20 - 00000000 ____D () C:\Windows\erdnt
2014-09-19 19:32 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-19 19:31 - 2014-09-16 19:31 - 00001356 _____ () C:\Windows\Tasks\AXYC.job
2014-09-19 19:30 - 2014-09-16 19:30 - 00001706 _____ () C:\Windows\Tasks\QBTNOXC.job
2014-09-19 19:20 - 2014-09-16 19:41 - 00325337 _____ () C:\Windows\WindowsUpdate.log
2014-09-19 19:19 - 2014-09-19 19:19 - 05578824 ____R (Swearware) C:\Users\Mara\Desktop\ComboFix.exe
2014-09-19 19:13 - 2014-07-08 16:34 - 00000000 ____D () C:\AdwCleaner
2014-09-19 19:09 - 2014-01-18 12:38 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\uTorrent
2014-09-19 19:08 - 2014-01-17 23:15 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashDumps
2014-09-19 19:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-19 16:53 - 2014-09-19 14:52 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-09-19 15:38 - 2014-02-28 11:45 - 00001456 _____ () C:\Users\Mara\AppData\Local\Adobe Save for Web 12.0 Prefs
2014-09-19 14:58 - 2014-09-19 14:52 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-19 14:53 - 2014-09-19 14:53 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00001385 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-09-19 14:51 - 2014-09-19 14:51 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Mara\Desktop\spybot-2.4.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 00384529 _____ () C:\Users\Mara\Desktop\Lista_centrum.exe
2014-09-19 14:48 - 2014-09-19 14:47 - 00733368 _____ () C:\Users\Mara\Desktop\spybot-search-and-destroy-lista-centrumcz.exe
2014-09-19 14:37 - 2014-01-17 21:15 - 00000062 _____ () C:\Users\Mara\AppData\Roaming\sp_data.sys
2014-09-19 14:36 - 2013-03-18 20:09 - 00003260 _____ () C:\Windows\System32\Tasks\ASUS Patch for Touch Panel
2014-09-19 14:36 - 2013-03-18 20:00 - 00003542 _____ () C:\Windows\System32\Tasks\ASUS Touchpad Launcher (x64)
2014-09-19 14:36 - 2013-03-18 19:59 - 00003056 _____ () C:\Windows\System32\Tasks\ASUS P4G
2014-09-19 14:36 - 2013-03-18 19:59 - 00003004 _____ () C:\Windows\System32\Tasks\ASUS Splendid ColorU
2014-09-19 14:36 - 2013-03-18 19:59 - 00002988 _____ () C:\Windows\System32\Tasks\ASUS Splendid ACMON
2014-09-19 14:36 - 2013-03-18 19:57 - 00003028 _____ () C:\Windows\System32\Tasks\ASUS USB Charger Plus
2014-09-19 14:36 - 2013-03-18 19:56 - 00003114 _____ () C:\Windows\System32\Tasks\ASUS Live Update
2014-09-19 14:35 - 2014-01-17 22:03 - 00000970 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-19 14:34 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-18 15:31 - 2014-04-04 10:41 - 00000132 _____ () C:\Users\Mara\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-09-18 08:12 - 2014-07-07 18:45 - 00000027 _____ () C:\Users\Mara\AppData\Roaming\mshlxdyx.dat
2014-09-17 16:00 - 2012-08-02 20:06 - 00727488 _____ () C:\Windows\system32\perfh005.dat
2014-09-17 16:00 - 2012-08-02 20:06 - 00148006 _____ () C:\Windows\system32\perfc005.dat
2014-09-17 16:00 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-16 22:58 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-16 22:51 - 2014-09-16 22:51 - 01373475 _____ () C:\Users\Mara\Desktop\adwcleaner_3.310.exe
2014-09-16 22:18 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Queen - The Ultimate Best Of Queen (2011) [mp3][www.lokotorrents.com]
2014-09-16 22:18 - 2014-09-16 22:17 - 00000000 ____D () C:\Users\Mara\Desktop\Justin TImberlake - The 20-20 Experience (Deluxe Edition) 2013 Pop 320kbps CBR MP3 [VX]
2014-09-16 22:05 - 2014-09-16 22:04 - 00000000 ____D () C:\Users\Mara\Desktop\XSCAPE (Deluxe)
2014-09-16 22:02 - 2014-09-16 22:02 - 00000000 ____D () C:\Users\Mara\Desktop\Coldplay - Ghost Stories [2014] [Deluxe Edition] [Mp3-320]-V3nom [GLT]
2014-09-16 22:01 - 2014-09-16 22:00 - 00000000 ____D () C:\Users\Mara\Desktop\Chris Brown - X [Deluxe@320] 2014
2014-09-16 21:54 - 2014-09-16 21:54 - 00000000 ____D () C:\Users\Mara\Desktop\Filmy
2014-09-16 21:51 - 2014-01-26 10:48 - 00000000 ____D () C:\Users\Mara\Desktop\we
2014-09-16 19:37 - 2014-09-16 19:36 - 00000000 ____D () C:\Users\Mara\Documents\wintoflash_0.7.0026beta
2014-09-16 19:31 - 2014-09-16 19:31 - 01513832 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\AXYC.exe
2014-09-16 19:31 - 2014-09-16 19:31 - 00004370 _____ () C:\Windows\System32\Tasks\AXYC
2014-09-16 19:30 - 2014-09-16 19:30 - 01969000 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
2014-09-16 19:30 - 2014-09-16 19:30 - 00004718 _____ () C:\Windows\System32\Tasks\QBTNOXC
2014-09-16 19:25 - 2014-09-16 19:21 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-16 19:24 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-09-16 19:24 - 2014-09-16 19:17 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-09-16 19:24 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-09-16 19:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-09-16 19:17 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashRpt
2014-09-16 18:42 - 2014-09-16 18:03 - 693682871 _____ () C:\Users\Mara\Desktop\Microsoft-Windows-XP-Professional-SP3-CZ-x86-Integrovane-Januar-2010.zip
2014-09-16 18:36 - 2014-09-16 18:02 - 602720256 _____ () C:\Users\Mara\Desktop\Windows.XP.Home.SP3.v5.1.2600.Czech-mXx.iso
2014-09-16 12:01 - 2014-01-17 22:51 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1437255118-3724227524-3503180372-1001
2014-09-16 10:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 09:38 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-15 08:26 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-14 09:30 - 2014-01-19 00:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 09:25 - 2014-01-19 00:58 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-13 07:11 - 2014-01-18 23:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe Mini Bridge CS5
2014-09-12 16:57 - 2014-01-17 21:13 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe
2014-09-10 16:12 - 2014-09-10 16:12 - 03813555 _____ () C:\Users\Mara\Desktop\NEVDAMA promoteaser.psd
2014-09-07 02:00 - 2014-06-25 09:14 - 00000378 _____ () C:\Windows\Tasks\AdobeAAMUpdater-1.0-Marouskovnik-Mara.job
2014-09-02 21:32 - 2014-08-21 11:58 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-21 11:58 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Mara\AppData\Roaming\AXYC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Mara\AppData\Roaming\QBTNOXC
2014-08-31 12:44 - 2014-07-22 10:33 - 05329560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:27 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 11:47 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-28 08:05 - 2014-09-11 08:27 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:27 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:27 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 18:31 - 2014-08-26 18:31 - 00000794 _____ () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-08-23 08:47 - 2014-08-28 08:13 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 11:53 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-08-21 11:25 - 2014-08-21 11:25 - 01819937 _____ () C:\Users\Mara\Desktop\lyze rozdelany.psd
2014-08-21 11:25 - 2014-08-21 11:25 - 00452080 _____ () C:\Users\Mara\Desktop\lyze rozdelany 2.psd
2014-08-20 09:12 - 2014-08-20 09:12 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-20 09:12 - 2014-08-20 09:12 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\Program Files\CCleaner
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-Marouskovnik-Mara.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\AXYC.job => C:\Users\Mara\AppData\Roaming\AXYC.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\QBTNOXC.job => C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mara\Desktop" je 13887 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSPRP
"C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe /S [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4
c:\windows\temp\DisableS3S464\sethigh.cmd [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
C:\Windows\system32\hkcmd.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
C:\Windows\system32\igfxtray.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe
"C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
uz jsem vyzkousel CCleaner, ADWcleaner, ComboFix a porad se reklamnich oken, ktere se spusti pres celou obrazovku zbavit.
Tady je log z FRSTu.
Dekuji
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Mara (administrator) on MAROUSKOVNIK on 19-09-2014 19:50:04
Running from C:\Users\Mara\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\VivoBook.exe
(ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [msgbdnaSrv] => C:\Windows\inf\msgbdna.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [msphyeSrv] => C:\Windows\inf\msphye.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [msljggxfSrv] => C:\Windows\inf\msljggxf.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [MSStp] => C:\Windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM-x32\...\Run: [mnctiqthhSrv] => C:\Windows\SysWOW64\mnctiqthh.vbe [7670 2014-03-05] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mskeetgSrv] => C:\Windows\SysWOW64\mskeetg.vbe [649 2014-06-23] ()
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1437255118-3724227524-3503180372-1001\...\Run: [AdobeBridge] => C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe [11989960 2010-03-09] (Adobe Systems, Inc.)
HKU\S-1-5-21-1437255118-3724227524-3503180372-1001\...\Run: [uTorrent] => C:\Users\Mara\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-08-26] (BitTorrent Inc.)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\2020Player_IKEA@2020Technologies.com [2014-05-07]
FF Extension: Apps Hat - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com [2014-09-16]
FF Extension: Flash and Video Download - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-09-19]
FF Extension: Firebug - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\firebug@software.joehewitt.com.xpi [2014-08-04]
FF Extension: WinToFlash Suggestor - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\xnivlz3b.default\Extensions\{285ACFBB-8E53-4feb-90E6-F02A128927F3}.xpi [2012-04-09]
Chrome:
=======
CHR HomePage: Default ->
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/", "hxxp://www.google.cz/", "hxxp://www.idnes.cz/"
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR DefaultSearchKeyword: Default -> A8458D7A91BFD45AC1418A24BA23B3592582F283479ACE85664C029CC62C2F05
CHR DefaultSearchURL: Default -> 46547644521F67599EC57EB4DBE401A642E6E301E9DF3A054AD6623D41259A23
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Talk Plugin) - C:\Users\Blb\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll No File
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Blb\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-09-16]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-17]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-17]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-17]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-09-16]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R3 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [226944 2012-12-28] (Qualcomm Atheros Commnucations)
R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 WakeupService; C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe [45488 2012-12-20] (ASUSTek Computer Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R3 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-28] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 adusbser; C:\Windows\system32\DRIVERS\adusbser.sys [154112 2009-11-06] (AnyDATA.NET INC.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-11-23] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-28] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
U0 msahci; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-19 19:50 - 2014-09-19 19:50 - 00018167 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-09-19 19:49 - 2014-09-19 19:50 - 00000000 ____D () C:\FRST
2014-09-19 19:48 - 2014-09-19 19:49 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-09-19 19:48 - 2014-09-19 19:48 - 02105856 _____ (Farbar) C:\Users\Mara\Desktop\FRST64.exe
2014-09-19 19:36 - 2014-09-19 19:36 - 00018486 _____ () C:\ComboFix.txt
2014-09-19 19:21 - 2014-09-19 19:36 - 00000000 ____D () C:\Qoobox
2014-09-19 19:21 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-19 19:21 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-19 19:21 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-19 19:21 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-19 19:20 - 2014-09-19 19:33 - 00000000 ____D () C:\Windows\erdnt
2014-09-19 19:19 - 2014-09-19 19:19 - 05578824 ____R (Swearware) C:\Users\Mara\Desktop\ComboFix.exe
2014-09-19 14:53 - 2014-09-19 14:53 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00001385 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-09-19 14:52 - 2014-09-19 16:53 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-09-19 14:52 - 2014-09-19 14:58 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-19 14:52 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Mara\Desktop\spybot-2.4.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 00384529 _____ () C:\Users\Mara\Desktop\Lista_centrum.exe
2014-09-19 14:47 - 2014-09-19 14:48 - 00733368 _____ () C:\Users\Mara\Desktop\spybot-search-and-destroy-lista-centrumcz.exe
2014-09-16 22:51 - 2014-09-16 22:51 - 01373475 _____ () C:\Users\Mara\Desktop\adwcleaner_3.310.exe
2014-09-16 22:18 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Queen - The Ultimate Best Of Queen (2011) [mp3][www.lokotorrents.com]
2014-09-16 22:17 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Justin TImberlake - The 20-20 Experience (Deluxe Edition) 2013 Pop 320kbps CBR MP3 [VX]
2014-09-16 22:04 - 2014-09-16 22:05 - 00000000 ____D () C:\Users\Mara\Desktop\XSCAPE (Deluxe)
2014-09-16 22:02 - 2014-09-16 22:02 - 00000000 ____D () C:\Users\Mara\Desktop\Coldplay - Ghost Stories [2014] [Deluxe Edition] [Mp3-320]-V3nom [GLT]
2014-09-16 22:00 - 2014-09-16 22:01 - 00000000 ____D () C:\Users\Mara\Desktop\Chris Brown - X [Deluxe@320] 2014
2014-09-16 21:54 - 2014-09-16 21:54 - 00000000 ____D () C:\Users\Mara\Desktop\Filmy
2014-09-16 19:41 - 2014-09-19 19:20 - 00325337 _____ () C:\Windows\WindowsUpdate.log
2014-09-16 19:36 - 2014-09-16 19:37 - 00000000 ____D () C:\Users\Mara\Documents\wintoflash_0.7.0026beta
2014-09-16 19:31 - 2014-09-19 19:31 - 00001356 _____ () C:\Windows\Tasks\AXYC.job
2014-09-16 19:31 - 2014-09-16 19:31 - 01513832 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\AXYC.exe
2014-09-16 19:31 - 2014-09-16 19:31 - 00004370 _____ () C:\Windows\System32\Tasks\AXYC
2014-09-16 19:30 - 2014-09-19 19:30 - 00001706 _____ () C:\Windows\Tasks\QBTNOXC.job
2014-09-16 19:30 - 2014-09-16 19:30 - 01969000 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
2014-09-16 19:30 - 2014-09-16 19:30 - 00004718 _____ () C:\Windows\System32\Tasks\QBTNOXC
2014-09-16 19:21 - 2014-09-16 19:25 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-16 19:17 - 2014-09-16 19:24 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-09-16 19:17 - 2014-09-16 19:24 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-09-16 19:17 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashRpt
2014-09-16 18:03 - 2014-09-16 18:42 - 693682871 _____ () C:\Users\Mara\Desktop\Microsoft-Windows-XP-Professional-SP3-CZ-x86-Integrovane-Januar-2010.zip
2014-09-16 18:02 - 2014-09-16 18:36 - 602720256 _____ () C:\Users\Mara\Desktop\Windows.XP.Home.SP3.v5.1.2600.Czech-mXx.iso
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe Mini Bridge CS5
2014-09-11 08:56 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 08:56 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 08:56 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 08:56 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 08:56 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 08:56 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 08:56 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 08:56 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 08:56 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 08:56 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 08:56 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 08:56 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 08:56 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 08:56 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 08:56 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 08:56 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 08:56 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 08:56 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 08:56 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 08:56 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 08:56 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 08:56 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 08:56 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 08:55 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 08:55 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 08:31 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:31 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:29 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:29 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-11 08:27 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:27 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:27 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:27 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:27 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:27 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:27 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:26 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-11 08:26 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-10 16:12 - 2014-09-10 16:12 - 03813555 _____ () C:\Users\Mara\Desktop\NEVDAMA promoteaser.psd
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Mara\AppData\Roaming\AXYC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Mara\AppData\Roaming\QBTNOXC
2014-08-28 08:13 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 18:31 - 2014-08-26 18:31 - 00000794 _____ () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-08-21 11:58 - 2014-09-02 21:32 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-21 11:58 - 2014-09-02 21:32 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-21 11:25 - 2014-08-21 11:25 - 01819937 _____ () C:\Users\Mara\Desktop\lyze rozdelany.psd
2014-08-21 11:25 - 2014-08-21 11:25 - 00452080 _____ () C:\Users\Mara\Desktop\lyze rozdelany 2.psd
2014-08-20 09:12 - 2014-08-20 09:12 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-20 09:12 - 2014-08-20 09:12 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\Program Files\CCleaner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-19 19:50 - 2014-09-19 19:50 - 00018167 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-09-19 19:50 - 2014-09-19 19:49 - 00000000 ____D () C:\FRST
2014-09-19 19:49 - 2014-09-19 19:48 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-09-19 19:48 - 2014-09-19 19:48 - 02105856 _____ (Farbar) C:\Users\Mara\Desktop\FRST64.exe
2014-09-19 19:40 - 2014-01-17 22:03 - 00000974 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-19 19:36 - 2014-09-19 19:36 - 00018486 _____ () C:\ComboFix.txt
2014-09-19 19:36 - 2014-09-19 19:21 - 00000000 ____D () C:\Qoobox
2014-09-19 19:36 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-09-19 19:33 - 2014-09-19 19:20 - 00000000 ____D () C:\Windows\erdnt
2014-09-19 19:32 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-19 19:31 - 2014-09-16 19:31 - 00001356 _____ () C:\Windows\Tasks\AXYC.job
2014-09-19 19:30 - 2014-09-16 19:30 - 00001706 _____ () C:\Windows\Tasks\QBTNOXC.job
2014-09-19 19:20 - 2014-09-16 19:41 - 00325337 _____ () C:\Windows\WindowsUpdate.log
2014-09-19 19:19 - 2014-09-19 19:19 - 05578824 ____R (Swearware) C:\Users\Mara\Desktop\ComboFix.exe
2014-09-19 19:13 - 2014-07-08 16:34 - 00000000 ____D () C:\AdwCleaner
2014-09-19 19:09 - 2014-01-18 12:38 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\uTorrent
2014-09-19 19:08 - 2014-01-17 23:15 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashDumps
2014-09-19 19:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-19 16:53 - 2014-09-19 14:52 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-09-19 15:38 - 2014-02-28 11:45 - 00001456 _____ () C:\Users\Mara\AppData\Local\Adobe Save for Web 12.0 Prefs
2014-09-19 14:58 - 2014-09-19 14:52 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-19 14:53 - 2014-09-19 14:53 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00001385 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-09-19 14:53 - 2014-09-19 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-09-19 14:51 - 2014-09-19 14:51 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Mara\Desktop\spybot-2.4.exe
2014-09-19 14:51 - 2014-09-19 14:51 - 00384529 _____ () C:\Users\Mara\Desktop\Lista_centrum.exe
2014-09-19 14:48 - 2014-09-19 14:47 - 00733368 _____ () C:\Users\Mara\Desktop\spybot-search-and-destroy-lista-centrumcz.exe
2014-09-19 14:37 - 2014-01-17 21:15 - 00000062 _____ () C:\Users\Mara\AppData\Roaming\sp_data.sys
2014-09-19 14:36 - 2013-03-18 20:09 - 00003260 _____ () C:\Windows\System32\Tasks\ASUS Patch for Touch Panel
2014-09-19 14:36 - 2013-03-18 20:00 - 00003542 _____ () C:\Windows\System32\Tasks\ASUS Touchpad Launcher (x64)
2014-09-19 14:36 - 2013-03-18 19:59 - 00003056 _____ () C:\Windows\System32\Tasks\ASUS P4G
2014-09-19 14:36 - 2013-03-18 19:59 - 00003004 _____ () C:\Windows\System32\Tasks\ASUS Splendid ColorU
2014-09-19 14:36 - 2013-03-18 19:59 - 00002988 _____ () C:\Windows\System32\Tasks\ASUS Splendid ACMON
2014-09-19 14:36 - 2013-03-18 19:57 - 00003028 _____ () C:\Windows\System32\Tasks\ASUS USB Charger Plus
2014-09-19 14:36 - 2013-03-18 19:56 - 00003114 _____ () C:\Windows\System32\Tasks\ASUS Live Update
2014-09-19 14:35 - 2014-01-17 22:03 - 00000970 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-19 14:34 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-18 15:31 - 2014-04-04 10:41 - 00000132 _____ () C:\Users\Mara\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-09-18 08:12 - 2014-07-07 18:45 - 00000027 _____ () C:\Users\Mara\AppData\Roaming\mshlxdyx.dat
2014-09-17 16:00 - 2012-08-02 20:06 - 00727488 _____ () C:\Windows\system32\perfh005.dat
2014-09-17 16:00 - 2012-08-02 20:06 - 00148006 _____ () C:\Windows\system32\perfc005.dat
2014-09-17 16:00 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-16 22:58 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-16 22:51 - 2014-09-16 22:51 - 01373475 _____ () C:\Users\Mara\Desktop\adwcleaner_3.310.exe
2014-09-16 22:18 - 2014-09-16 22:18 - 00000000 ____D () C:\Users\Mara\Desktop\Queen - The Ultimate Best Of Queen (2011) [mp3][www.lokotorrents.com]
2014-09-16 22:18 - 2014-09-16 22:17 - 00000000 ____D () C:\Users\Mara\Desktop\Justin TImberlake - The 20-20 Experience (Deluxe Edition) 2013 Pop 320kbps CBR MP3 [VX]
2014-09-16 22:05 - 2014-09-16 22:04 - 00000000 ____D () C:\Users\Mara\Desktop\XSCAPE (Deluxe)
2014-09-16 22:02 - 2014-09-16 22:02 - 00000000 ____D () C:\Users\Mara\Desktop\Coldplay - Ghost Stories [2014] [Deluxe Edition] [Mp3-320]-V3nom [GLT]
2014-09-16 22:01 - 2014-09-16 22:00 - 00000000 ____D () C:\Users\Mara\Desktop\Chris Brown - X [Deluxe@320] 2014
2014-09-16 21:54 - 2014-09-16 21:54 - 00000000 ____D () C:\Users\Mara\Desktop\Filmy
2014-09-16 21:51 - 2014-01-26 10:48 - 00000000 ____D () C:\Users\Mara\Desktop\we
2014-09-16 19:37 - 2014-09-16 19:36 - 00000000 ____D () C:\Users\Mara\Documents\wintoflash_0.7.0026beta
2014-09-16 19:31 - 2014-09-16 19:31 - 01513832 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\AXYC.exe
2014-09-16 19:31 - 2014-09-16 19:31 - 00004370 _____ () C:\Windows\System32\Tasks\AXYC
2014-09-16 19:30 - 2014-09-16 19:30 - 01969000 _____ (Object Browser) C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
2014-09-16 19:30 - 2014-09-16 19:30 - 00004718 _____ () C:\Windows\System32\Tasks\QBTNOXC
2014-09-16 19:25 - 2014-09-16 19:21 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-16 19:24 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-09-16 19:24 - 2014-09-16 19:17 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-09-16 19:24 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-09-16 19:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-09-16 19:17 - 2014-09-16 19:17 - 00000000 ____D () C:\Users\Mara\AppData\Local\CrashRpt
2014-09-16 18:42 - 2014-09-16 18:03 - 693682871 _____ () C:\Users\Mara\Desktop\Microsoft-Windows-XP-Professional-SP3-CZ-x86-Integrovane-Januar-2010.zip
2014-09-16 18:36 - 2014-09-16 18:02 - 602720256 _____ () C:\Users\Mara\Desktop\Windows.XP.Home.SP3.v5.1.2600.Czech-mXx.iso
2014-09-16 12:01 - 2014-01-17 22:51 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1437255118-3724227524-3503180372-1001
2014-09-16 10:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 09:38 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-15 08:26 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-14 09:30 - 2014-01-19 00:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 09:25 - 2014-01-19 00:58 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-13 07:11 - 2014-01-18 23:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-09-12 17:06 - 2014-09-12 17:06 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe Mini Bridge CS5
2014-09-12 16:57 - 2014-01-17 21:13 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Adobe
2014-09-10 16:12 - 2014-09-10 16:12 - 03813555 _____ () C:\Users\Mara\Desktop\NEVDAMA promoteaser.psd
2014-09-07 02:00 - 2014-06-25 09:14 - 00000378 _____ () C:\Windows\Tasks\AdobeAAMUpdater-1.0-Marouskovnik-Mara.job
2014-09-02 21:32 - 2014-08-21 11:58 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-21 11:58 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Mara\AppData\Roaming\AXYC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Mara\AppData\Roaming\QBTNOXC
2014-08-31 12:44 - 2014-07-22 10:33 - 05329560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:27 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 11:47 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-28 08:05 - 2014-09-11 08:27 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:27 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:27 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:27 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:27 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 18:31 - 2014-08-26 18:31 - 00000794 _____ () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-08-23 08:47 - 2014-08-28 08:13 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 11:53 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-08-21 11:25 - 2014-08-21 11:25 - 01819937 _____ () C:\Users\Mara\Desktop\lyze rozdelany.psd
2014-08-21 11:25 - 2014-08-21 11:25 - 00452080 _____ () C:\Users\Mara\Desktop\lyze rozdelany 2.psd
2014-08-20 09:12 - 2014-08-20 09:12 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-20 09:12 - 2014-08-20 09:12 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-20 09:12 - 2014-08-20 09:12 - 00000000 ____D () C:\Program Files\CCleaner
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-Marouskovnik-Mara.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\AXYC.job => C:\Users\Mara\AppData\Roaming\AXYC.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\QBTNOXC.job => C:\Users\Mara\AppData\Roaming\QBTNOXC.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mara\Desktop" je 13887 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSPRP
"C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe /S [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4
c:\windows\temp\DisableS3S464\sethigh.cmd [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
C:\Windows\system32\hkcmd.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
C:\Windows\system32\igfxtray.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe
"C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================