nenačitáva jeden z diskov (F), spomalený PC
Napsal: 05 črc 2015 02:13
Dobrý den, chcel by som Vás poprosiť o kontrolu logu. Dôvod: PC je spomalený a mrzne. Nenačitava jeden z diskov (disk C a disk D načíta, disk F nenačítava... overil som to nie je to hardwarová chyba). Vopred ďakujem za pomoc
LOG z FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2015
Ran by Henrich (administrator) on DOMA-9C5ACA6348 on 05-07-2015 03:00:18
Running from C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha
Loaded Profiles: Henrich (Available Profiles: Henrich & postgres)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\WINDOWS\twain_32\Samsung\SCX4600\Scan2Pc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\ASTSRV.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20145368 2013-12-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1980416 2013-12-18] (Wondershare)
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [Samsung PanelMgr] => C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe [688128 2011-07-13] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [4600 Scan2PC] => C:\WINDOWS\Twain_32\Samsung\SCX4600\Scan2pc.exe [1990144 2011-06-24] ()
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-12-17] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5088456 2014-10-01] (ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478752 2012-12-18] (Adobe Systems Inc.)
HKLM\...\Run: [IObit Malware Fighter] => C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [5767488 2015-01-16] (IObit)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2425632 2014-11-07] (IObit)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3129560 2014-02-24] (Disc Soft Ltd)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\MountPoints2: {535f715d-8f9d-11e2-8764-806d6172696f} - E:\Run.exe
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [1034240 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
BootExecute: bootdeletebootdelete
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seeklatin.com/
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.sk/
SearchScopes: HKLM -> {7BDD16DA-7640-4368-AA75-C04518F5F635} URL = ${SEARCH_URL}{searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {09EFB0A3-79FA-49BA-A497-EC6794EA6AFC} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {19294AB0-B218-408F-8F1C-D1B0A14C947F} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {39F81375-11FA-4ABC-B863-B6334A4902F3} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {3B1B7753-8C53-44BF-A98D-74584C74CDC9} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {445C3016-616E-4A0B-B1C2-7377CF97EC50} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {5CEB7A10-FB9B-4944-88EA-1E6E8707EA19} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {63FA79C9-B640-4FCB-B521-B649B2407500} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {7E8FA1FB-109E-4CB0-8B5C-C05123927A76} URL = http://search.seznam.cz/?q={searchTerms ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {A37D5BAA-FCA3-4168-913B-FA4464D4E2E4} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {B34C8B52-8174-4F9D-8AED-61ECB15FB22A} URL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {C7E886B6-EA2F-4397-8D2E-CFEC691E4C6F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {CF3B62E1-F1E5-4F44-A093-2B695FAD5863} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-11-23] (IObit)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-22] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-22] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-11-23] (IObit)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 2625641765
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 10.201.1.2 10.201.1.254
Tcpip\..\Interfaces\{22C53D6C-ACEA-4068-8049-A6CF21C3AD9D}: [DhcpNameServer] 10.201.1.2 10.201.1.254
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-03-30] (Google)
FF Plugin: @java.com/DTPlugin,version=10.72.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.72.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2013-02-16] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Extension: General Crawler - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com [2013-05-04]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-24]
FF HKLM\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF Extension: Wondershare Video Converter Ultimate - C:\Program Files\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2014-05-08]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2015-04-14]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-02-01]
CHR Extension: (Translator for all languages) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\amdeidgbmcliegnpcbbkhlflkbdpomhk [2015-04-28]
CHR Extension: (Google Drive) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-12]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-28]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2015-04-14]
CHR Extension: (AdBlock) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-02-01]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ihmgiclibbndffejedjimfjmfoabpcke [2015-05-14]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-24]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-01]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\noaijdpnepcgjemiklgfkcfbkokogabh [2015-04-28]
CHR Extension: (Gmail) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-28]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23]
CHR HKLM\...\Chrome\Extension: [fknfdieimobmimhdkfkheeejenmdjhoe] - No Path Or update_url value
CHR HKU\S-1-5-21-299502267-1085031214-839522115-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [815392 2014-11-04] (IObit)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2014-02-24] (Macrovision Europe Ltd.) [File not signed]
R2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [344864 2015-01-13] (IObit)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-12-22] (Oracle Corporation)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2724128 2015-01-16] (IObit)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S2 nvda; C:\Program Files\NVDA\nvda_service.exe [40040 2014-11-27] (NV Access Limited)
S2 postgresql-8.4; c:\postgreSQL\bin\pg_ctl.exe [81920 2013-04-02] (PostgreSQL Global Development Group) [File not signed]
S3 Samsung UPD Service2; C:\WINDOWS\system32\SUPDSvc2.exe [129536 2012-04-06] (Samsung Electronics)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2014-03-17] (Creative)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2013-12-13] (Advanced Micro Devices)
R3 anvsnddrv; C:\WINDOWS\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [38400 2009-02-16] (Samsung Electronics Co., Ltd.) [File not signed]
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-03] (Disc Soft Ltd)
R3 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [191928 2014-10-10] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-10-10] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [176448 2014-10-10] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [39464 2014-10-10] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [63160 2014-10-10] (ESET)
R1 Eve; C:\WINDOWS\System32\DRIVERS\eve.sys [33624 2013-03-28] ()
R3 FileMonitor; C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [247968 2014-11-10] (IObit)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2014-12-22] (REALiX(tm))
S3 MAGicKB; C:\WINDOWS\System32\DRIVERS\MAGicKB.sys [24608 2011-05-11] (Freedom Scientific, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2014-03-17] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2010-07-16] (CACE Technologies, Inc.)
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [70912 2013-12-13] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [168040 2013-12-13] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2013-12-13] (NVIDIA Corporation)
S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [16472 2010-08-16] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [11104 2010-08-16] ()
R3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys [31776 2014-11-10] (IObit.com)
S3 snpstd2; C:\WINDOWS\System32\DRIVERS\snpstd2.sys [334080 2004-07-28] ()
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2014-03-23] (Duplex Secure Ltd.)
S3 ssudserd; C:\WINDOWS\System32\DRIVERS\ssudserd.sys [184192 2014-06-16] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
R1 tStLib; C:\WINDOWS\System32\drivers\tStLib.sys [55224 2014-03-18] (StdLib)
R3 UrlFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys [17360 2014-11-10] (IObit.com)
R3 WsAudio_Device; C:\WINDOWS\System32\drivers\VirtualAudio.sys [27496 2013-03-25] (Wondershare)
U3 an4e6sh3; C:\WINDOWS\system32\Drivers\an4e6sh3.sys [0 ] (NVIDIA Corporation) <==== ATTENTION (zero byte File/Folder)
S3 a2acc; No ImagePath
S1 A2DDA; \??\C:\EEK\bin\a2ddax86.sys [X]
S1 a2injectiondriver; No ImagePath
S1 a2util; No ImagePath
S3 cleanhlp; \??\C:\EEK\bin\cleanhlp32.sys [X]
S3 cpuz137; \??\C:\DOCUME~1\HENRIC~2.DOM\LOCALS~1\Temp\cpuz137\cpuz137_x32.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S2 SSPORT; No ImagePath
S2 StarOpen; No ImagePath
S3 TotRec8; No ImagePath
S3 WinRing0_1_2_0; No ImagePath
S2 zumbus; system32\DRIVERS\zumbus.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-05 03:00 - 2015-07-05 03:00 - 00024926 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRST.txt
2015-07-05 02:58 - 2015-07-05 03:00 - 00000000 ____D C:\FRST
2015-07-05 02:57 - 2015-07-05 02:57 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRSTLauncher (4).exe
2015-07-05 02:56 - 2015-07-05 02:56 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 91789.crdownload
2015-07-05 02:55 - 2015-07-05 02:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 544349.crdownload
2015-07-05 02:55 - 2015-07-05 02:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 54180.crdownload
2015-07-05 02:54 - 2015-07-05 02:54 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 304155.crdownload
2015-07-05 02:52 - 2015-07-05 02:52 - 01636352 _____ (Farbar) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRST.exe
2015-07-05 02:51 - 2015-07-05 02:51 - 00000048 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nový objekt - Textový dokument.txt
2015-07-04 16:08 - 2015-07-04 16:09 - 00421376 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Z_Londýna-šokující.pps
2015-07-04 10:53 - 2015-07-04 11:34 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\fotky
2015-07-02 11:54 - 2015-07-02 11:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Advanced SystemCare 8
2015-07-02 11:54 - 2015-07-02 11:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Advanced SystemCare 8
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 __RHD C:\Documents and Settings\postgres\Data aplikací
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy\Příslušenství
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy\Po spuštění
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Šablony
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Okolní tiskárny
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Okolní síť
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\ws-enabler
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\uuNisAAles
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\uNNissaales
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\unisaleess
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\Uniasales
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\PriceMionus
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\PriCeMinnus
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\Play
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\HitsBlender
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\GrabRez
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\DownLite
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\BikeXperience
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\bestadblocker
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Plocha
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Oblíbené položky
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Local Settings\Temp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Dokumenty
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Data aplikací\Macromedia
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\EZDownloader
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\GlarySoft
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Dokumenty\NativeFus_Log
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Davar3
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Trusted Publisher
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Trusted Publisher
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SNT
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SNT
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SetApp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SetApp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SaveLots
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SaveLots
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ParetoLogic
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ParetoLogic
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NoMore Ads
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NoMore Ads
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Isaver
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Isaver
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Happy2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Happy2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Fun2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Fun2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ExstraSavings
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ExstraSavings
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7725107c84cfa2a2
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7725107c84cfa2a2
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{7b8eae64-7470-31eb-7b8e-eae64747b991}
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{7b8eae64-7470-31eb-7b8e-eae64747b991}
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikac
2015-07-02 11:26 - 2015-07-05 02:41 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\theWord
2015-07-02 11:26 - 2015-07-05 02:41 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\theWord
2015-07-02 11:26 - 2015-07-04 21:29 - 00000000 ____D C:\Documents and Settings\postgres
2015-07-02 11:26 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Local Settings\Data aplikací
2015-07-02 11:26 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\Henrich
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\ScanSoft
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\The Word
2015-06-30 21:01 - 2015-06-30 21:01 - 00000097 _____ C:\prefs.js
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ___SD C:\Documents and Settings\postgres(2)
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\postgres(2)\Šablony
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\postgres(2)\Data aplikací
2015-06-30 20:52 - 2015-04-25 21:24 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Data aplikací\Google
2015-06-30 20:52 - 2015-04-25 21:24 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Data aplikací
2015-06-30 20:52 - 2014-02-24 21:36 - 00000000 ____D C:\Documents and Settings\postgres(2)\Data aplikací\Macromedia
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ___HD C:\Documents and Settings\postgres(2)\Okolní síť
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Oblíbené položky
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Temp
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Dokumenty
2015-06-30 20:50 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2015-06-30 14:34 - 2015-06-30 14:34 - 00000000 ____D C:\Documents and Settings\Henrich(2)
2015-06-30 14:03 - 2015-07-05 02:26 - 00000157 ____N C:\WINDOWS\wiadebug.log
2015-06-30 14:03 - 2015-07-05 02:26 - 00000050 ____N C:\WINDOWS\wiaservc.log
2015-06-30 14:03 - 2015-06-30 14:03 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2015-06-30 14:02 - 2015-07-04 22:42 - 00032566 ____N C:\WINDOWS\SchedLgU.Txt
2015-06-30 13:58 - 2015-07-02 11:53 - 00000000 ____D C:\EEK
2015-06-30 13:57 - 2015-06-30 14:12 - 00000000 ____D C:\AdwCleaner
2015-06-25 09:52 - 2015-06-25 09:52 - 00000022 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nový objekt - Textový dokument (2).txt
2015-06-23 22:41 - 2015-07-05 02:26 - 00000284 _____ C:\WINDOWS\Tasks\ASC8_PerformanceMonitor.job
2015-06-22 21:57 - 2015-06-22 21:57 - 00000000 ____D C:\Documents and Settings\LocalService.NT AUTHORITY.000\Data aplikací\IObit
2015-06-21 21:45 - 2015-06-21 21:45 - 00074308 ____H C:\WINDOWS\system32\mlfcache.dat
2015-06-17 15:43 - 2015-06-30 21:37 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\foto
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-05 03:00 - 2014-11-25 17:03 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Temp
2015-07-05 03:00 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha
2015-07-05 02:54 - 2013-04-03 14:21 - 00001050 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1085031214-839522115-1003UA.job
2015-07-05 02:42 - 2014-03-23 15:44 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\DAEMON Tools Pro
2015-07-05 02:42 - 2013-06-20 20:16 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-05 02:41 - 2014-03-17 23:15 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-07-05 02:41 - 2014-03-17 23:15 - 00065536 _____ C:\WINDOWS\system32\config\EventForwarding-Operational.Evt
2015-07-05 02:41 - 2013-03-18 15:25 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2015-07-05 02:41 - 2013-03-18 11:36 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2015-07-05 02:41 - 2013-03-18 11:06 - 00000000 __SHD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\UserData
2015-07-05 02:41 - 2013-03-18 10:50 - 00000000 ___HD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací
2015-07-05 02:41 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348
2015-07-05 02:30 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Plocha
2015-07-05 02:29 - 2015-02-18 11:59 - 00000178 ___SH C:\Documents and Settings\postgres\ntuser.ini
2015-07-05 02:28 - 2014-06-23 20:45 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-05 02:27 - 2013-03-18 10:43 - 01622432 ____N C:\WINDOWS\WindowsUpdate.log
2015-07-05 02:26 - 2014-11-25 16:40 - 00000282 _____ C:\WINDOWS\Tasks\Game_Booster_AutoUpdate.job
2015-07-05 02:26 - 2014-06-23 20:45 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-05 02:26 - 2014-05-14 11:00 - 00000288 _____ C:\WINDOWS\Tasks\HitsBlender Update Service.job
2015-07-05 02:26 - 2014-03-18 15:48 - 00000226 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2015-07-05 02:26 - 2013-12-13 11:42 - 00046072 _____ C:\WINDOWS\system32\nvAppTimestamps
2015-07-05 02:26 - 2013-03-18 10:49 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-04 22:41 - 2013-03-18 10:50 - 00000178 ___SH C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\ntuser.ini
2015-07-04 22:37 - 2013-03-21 18:49 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\OCO
2015-07-04 22:20 - 2014-04-02 18:12 - 00000000 ____D C:\Program Files\IObit
2015-07-04 21:29 - 2013-03-18 10:49 - 00000000 __SHD C:\Documents and Settings\LocalService.NT AUTHORITY.000
2015-07-04 21:29 - 2013-03-18 10:48 - 00000000 __SHD C:\Documents and Settings\NetworkService.NT AUTHORITY.000
2015-07-04 21:28 - 2013-03-18 08:57 - 00000000 ____D C:\WINDOWS\Registration
2015-07-03 22:49 - 2013-12-10 22:36 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ProductData
2015-07-03 22:49 - 2013-12-10 22:36 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ProductData
2015-07-03 22:47 - 2001-10-25 17:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-02 20:31 - 2015-05-14 22:18 - 00001825 _____ C:\Documents and Settings\All Users.WINDOWS\Plocha\Google Chrome.lnk
2015-07-02 12:42 - 2013-06-20 20:16 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-02 12:42 - 2013-06-20 20:16 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-07-02 11:54 - 2014-11-24 18:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Google Drive
2015-07-02 11:54 - 2014-11-24 18:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Google Drive
2015-07-02 11:53 - 2014-04-06 19:58 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\IObit
2015-07-02 11:53 - 2014-03-09 22:55 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Wondershare Video Converter Ultimate
2015-07-02 11:53 - 2014-03-09 22:55 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Wondershare Video Converter Ultimate
2015-07-02 11:53 - 2013-03-18 11:35 - 00000000 ___RD C:\Documents and Settings\All Users.WINDOWS\Dokumenty
2015-07-02 11:53 - 2013-03-18 11:34 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS
2015-07-02 11:51 - 2013-09-11 16:17 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2015-07-02 11:51 - 2013-09-11 16:17 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2015-07-02 11:25 - 2013-03-18 11:34 - 00000000 __RHD C:\Documents and Settings\All Users.WINDOWS\Data aplikací
2015-07-02 09:33 - 2013-03-19 21:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2015-07-02 09:33 - 2013-03-19 21:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2015-07-01 21:24 - 2013-03-18 10:50 - 00000000 ___RD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Dokumenty
2015-06-30 20:50 - 2013-12-17 10:08 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2015-06-30 20:50 - 2013-12-17 10:08 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2015-06-30 14:33 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy
2015-06-30 14:33 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy
2015-06-30 14:33 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací
2015-06-30 13:12 - 2015-01-05 19:17 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\MPC-HC
2015-06-30 12:56 - 2013-12-13 13:16 - 41447424 _____ C:\WINDOWS\system32\config\software.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00643072 _____ C:\WINDOWS\system32\config\default.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00081920 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00028672 _____ C:\WINDOWS\system32\config\SAM.iobit
2015-06-29 07:54 - 2013-04-03 14:21 - 00000998 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1085031214-839522115-1003Core.job
2015-06-23 22:41 - 2013-03-18 10:50 - 00000000 ___HD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Šablony
2015-06-19 12:20 - 2013-12-17 13:45 - 00002565 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Microsoft Office Word 2007.lnk
2015-06-17 13:11 - 2015-05-20 19:23 - 00011199 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SmarThruOptions.xml
2015-06-08 15:00 - 2014-03-18 15:48 - 00000220 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
==================== Files in the root of some directories =======
2014-03-26 22:07 - 2014-03-26 22:07 - 0000604 ____H () C:\Program Files\STLL Notifier
2015-01-11 22:10 - 2009-08-27 18:50 - 0000701 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\init.dll
2014-12-23 12:26 - 2014-12-23 14:47 - 0000115 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\LogFile.txt
2015-05-20 19:23 - 2015-06-17 13:11 - 0011199 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SmarThruOptions.xml
2015-01-11 22:10 - 2009-09-15 10:14 - 0000701 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\sound.dll
2015-01-11 22:10 - 2009-09-11 17:33 - 0000006 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SYSTEM32.dll
2015-01-11 22:11 - 2015-01-11 22:11 - 0000048 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\tigersetting.dll
2015-01-06 23:09 - 2015-01-07 23:11 - 0005632 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-31 22:00 - 2014-03-31 22:02 - 0000024 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\pdfshaper.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
Do prílohy som pridal Addition.rar
LOG z FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2015
Ran by Henrich (administrator) on DOMA-9C5ACA6348 on 05-07-2015 03:00:18
Running from C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha
Loaded Profiles: Henrich (Available Profiles: Henrich & postgres)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\WINDOWS\twain_32\Samsung\SCX4600\Scan2Pc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\ASTSRV.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20145368 2013-12-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1980416 2013-12-18] (Wondershare)
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [Samsung PanelMgr] => C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe [688128 2011-07-13] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [4600 Scan2PC] => C:\WINDOWS\Twain_32\Samsung\SCX4600\Scan2pc.exe [1990144 2011-06-24] ()
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-12-17] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5088456 2014-10-01] (ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478752 2012-12-18] (Adobe Systems Inc.)
HKLM\...\Run: [IObit Malware Fighter] => C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [5767488 2015-01-16] (IObit)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2425632 2014-11-07] (IObit)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3129560 2014-02-24] (Disc Soft Ltd)
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\MountPoints2: {535f715d-8f9d-11e2-8764-806d6172696f} - E:\Run.exe
HKU\S-1-5-21-299502267-1085031214-839522115-1003\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [1034240 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
BootExecute: bootdeletebootdelete
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seeklatin.com/
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... A_5JV9D1KS
HKU\S-1-5-21-299502267-1085031214-839522115-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.sk/
SearchScopes: HKLM -> {7BDD16DA-7640-4368-AA75-C04518F5F635} URL = ${SEARCH_URL}{searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {09EFB0A3-79FA-49BA-A497-EC6794EA6AFC} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {19294AB0-B218-408F-8F1C-D1B0A14C947F} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {39F81375-11FA-4ABC-B863-B6334A4902F3} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {3B1B7753-8C53-44BF-A98D-74584C74CDC9} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {445C3016-616E-4A0B-B1C2-7377CF97EC50} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {5CEB7A10-FB9B-4944-88EA-1E6E8707EA19} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {63FA79C9-B640-4FCB-B521-B649B2407500} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {7E8FA1FB-109E-4CB0-8B5C-C05123927A76} URL = http://search.seznam.cz/?q={searchTerms ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {A37D5BAA-FCA3-4168-913B-FA4464D4E2E4} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {B34C8B52-8174-4F9D-8AED-61ECB15FB22A} URL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {C7E886B6-EA2F-4397-8D2E-CFEC691E4C6F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13014
SearchScopes: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> {CF3B62E1-F1E5-4F44-A093-2B695FAD5863} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-11-23] (IObit)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-22] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-22] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-11-23] (IObit)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-299502267-1085031214-839522115-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 2625641765
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 10.201.1.2 10.201.1.254
Tcpip\..\Interfaces\{22C53D6C-ACEA-4068-8049-A6CF21C3AD9D}: [DhcpNameServer] 10.201.1.2 10.201.1.254
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-03-30] (Google)
FF Plugin: @java.com/DTPlugin,version=10.72.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.72.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2013-02-16] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Extension: General Crawler - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com [2013-05-04]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-24]
FF HKLM\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF Extension: Wondershare Video Converter Ultimate - C:\Program Files\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2014-05-08]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2015-04-14]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-02-01]
CHR Extension: (Translator for all languages) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\amdeidgbmcliegnpcbbkhlflkbdpomhk [2015-04-28]
CHR Extension: (Google Drive) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-12]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-28]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2015-04-14]
CHR Extension: (AdBlock) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-02-01]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ihmgiclibbndffejedjimfjmfoabpcke [2015-05-14]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-24]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-01]
CHR Extension: (No Name) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\noaijdpnepcgjemiklgfkcfbkokogabh [2015-04-28]
CHR Extension: (Gmail) - C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-28]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23]
CHR HKLM\...\Chrome\Extension: [fknfdieimobmimhdkfkheeejenmdjhoe] - No Path Or update_url value
CHR HKU\S-1-5-21-299502267-1085031214-839522115-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [815392 2014-11-04] (IObit)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2014-02-24] (Macrovision Europe Ltd.) [File not signed]
R2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [344864 2015-01-13] (IObit)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-12-22] (Oracle Corporation)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2724128 2015-01-16] (IObit)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S2 nvda; C:\Program Files\NVDA\nvda_service.exe [40040 2014-11-27] (NV Access Limited)
S2 postgresql-8.4; c:\postgreSQL\bin\pg_ctl.exe [81920 2013-04-02] (PostgreSQL Global Development Group) [File not signed]
S3 Samsung UPD Service2; C:\WINDOWS\system32\SUPDSvc2.exe [129536 2012-04-06] (Samsung Electronics)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2014-03-17] (Creative)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2013-12-13] (Advanced Micro Devices)
R3 anvsnddrv; C:\WINDOWS\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [38400 2009-02-16] (Samsung Electronics Co., Ltd.) [File not signed]
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-03] (Disc Soft Ltd)
R3 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [191928 2014-10-10] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-10-10] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [176448 2014-10-10] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [39464 2014-10-10] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [63160 2014-10-10] (ESET)
R1 Eve; C:\WINDOWS\System32\DRIVERS\eve.sys [33624 2013-03-28] ()
R3 FileMonitor; C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [247968 2014-11-10] (IObit)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2014-12-22] (REALiX(tm))
S3 MAGicKB; C:\WINDOWS\System32\DRIVERS\MAGicKB.sys [24608 2011-05-11] (Freedom Scientific, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2014-03-17] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2010-07-16] (CACE Technologies, Inc.)
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [70912 2013-12-13] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [168040 2013-12-13] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2013-12-13] (NVIDIA Corporation)
S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [16472 2010-08-16] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [11104 2010-08-16] ()
R3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys [31776 2014-11-10] (IObit.com)
S3 snpstd2; C:\WINDOWS\System32\DRIVERS\snpstd2.sys [334080 2004-07-28] ()
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2014-03-23] (Duplex Secure Ltd.)
S3 ssudserd; C:\WINDOWS\System32\DRIVERS\ssudserd.sys [184192 2014-06-16] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
R1 tStLib; C:\WINDOWS\System32\drivers\tStLib.sys [55224 2014-03-18] (StdLib)
R3 UrlFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys [17360 2014-11-10] (IObit.com)
R3 WsAudio_Device; C:\WINDOWS\System32\drivers\VirtualAudio.sys [27496 2013-03-25] (Wondershare)
U3 an4e6sh3; C:\WINDOWS\system32\Drivers\an4e6sh3.sys [0 ] (NVIDIA Corporation) <==== ATTENTION (zero byte File/Folder)
S3 a2acc; No ImagePath
S1 A2DDA; \??\C:\EEK\bin\a2ddax86.sys [X]
S1 a2injectiondriver; No ImagePath
S1 a2util; No ImagePath
S3 cleanhlp; \??\C:\EEK\bin\cleanhlp32.sys [X]
S3 cpuz137; \??\C:\DOCUME~1\HENRIC~2.DOM\LOCALS~1\Temp\cpuz137\cpuz137_x32.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S2 SSPORT; No ImagePath
S2 StarOpen; No ImagePath
S3 TotRec8; No ImagePath
S3 WinRing0_1_2_0; No ImagePath
S2 zumbus; system32\DRIVERS\zumbus.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-05 03:00 - 2015-07-05 03:00 - 00024926 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRST.txt
2015-07-05 02:58 - 2015-07-05 03:00 - 00000000 ____D C:\FRST
2015-07-05 02:57 - 2015-07-05 02:57 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRSTLauncher (4).exe
2015-07-05 02:56 - 2015-07-05 02:56 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 91789.crdownload
2015-07-05 02:55 - 2015-07-05 02:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 544349.crdownload
2015-07-05 02:55 - 2015-07-05 02:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 54180.crdownload
2015-07-05 02:54 - 2015-07-05 02:54 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nepotvrdené 304155.crdownload
2015-07-05 02:52 - 2015-07-05 02:52 - 01636352 _____ (Farbar) C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\FRST.exe
2015-07-05 02:51 - 2015-07-05 02:51 - 00000048 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nový objekt - Textový dokument.txt
2015-07-04 16:08 - 2015-07-04 16:09 - 00421376 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Z_Londýna-šokující.pps
2015-07-04 10:53 - 2015-07-04 11:34 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\fotky
2015-07-02 11:54 - 2015-07-02 11:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Advanced SystemCare 8
2015-07-02 11:54 - 2015-07-02 11:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Advanced SystemCare 8
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 __RHD C:\Documents and Settings\postgres\Data aplikací
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy\Příslušenství
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy\Po spuštění
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start\Programy
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___RD C:\Documents and Settings\postgres\Nabídka Start
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Šablony
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Okolní tiskárny
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Okolní síť
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\ws-enabler
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\uuNisAAles
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\uNNissaales
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\unisaleess
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\Uniasales
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\PriceMionus
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\PriCeMinnus
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\Play
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\HitsBlender
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\GrabRez
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\DownLite
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\BikeXperience
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Program Files\bestadblocker
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Plocha
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Oblíbené položky
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Local Settings\Temp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Dokumenty
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\postgres\Data aplikací\Macromedia
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\EZDownloader
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\GlarySoft
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Dokumenty\NativeFus_Log
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Davar3
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\websavee
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Trusted Publisher
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Trusted Publisher
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SNT
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SNT
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SetApp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SetApp
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SaveLots
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SaveLots
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\save oN
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\priCecihop
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ParetoLogic
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ParetoLogic
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NoMore Ads
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NoMore Ads
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Isaver
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Isaver
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Happy2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Happy2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GoSave
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Fun2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Fun2Save
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ExstraSavings
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ExstraSavings
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7725107c84cfa2a2
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7725107c84cfa2a2
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{7b8eae64-7470-31eb-7b8e-eae64747b991}
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{7b8eae64-7470-31eb-7b8e-eae64747b991}
2015-07-02 11:53 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikac
2015-07-02 11:26 - 2015-07-05 02:41 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\theWord
2015-07-02 11:26 - 2015-07-05 02:41 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\theWord
2015-07-02 11:26 - 2015-07-04 21:29 - 00000000 ____D C:\Documents and Settings\postgres
2015-07-02 11:26 - 2015-07-02 11:53 - 00000000 ___HD C:\Documents and Settings\postgres\Local Settings\Data aplikací
2015-07-02 11:26 - 2015-07-02 11:53 - 00000000 ____D C:\Documents and Settings\Henrich
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\ScanSoft
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\The Word
2015-07-02 11:26 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\The Word
2015-06-30 21:01 - 2015-06-30 21:01 - 00000097 _____ C:\prefs.js
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ___SD C:\Documents and Settings\postgres(2)
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\postgres(2)\Šablony
2015-06-30 20:52 - 2015-07-02 11:26 - 00000000 ____D C:\Documents and Settings\postgres(2)\Data aplikací
2015-06-30 20:52 - 2015-04-25 21:24 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Data aplikací\Google
2015-06-30 20:52 - 2015-04-25 21:24 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Data aplikací
2015-06-30 20:52 - 2014-02-24 21:36 - 00000000 ____D C:\Documents and Settings\postgres(2)\Data aplikací\Macromedia
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ___HD C:\Documents and Settings\postgres(2)\Okolní síť
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Oblíbené položky
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Local Settings\Temp
2015-06-30 20:52 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\postgres(2)\Dokumenty
2015-06-30 20:50 - 2015-07-02 11:26 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2015-06-30 14:34 - 2015-06-30 14:34 - 00000000 ____D C:\Documents and Settings\Henrich(2)
2015-06-30 14:03 - 2015-07-05 02:26 - 00000157 ____N C:\WINDOWS\wiadebug.log
2015-06-30 14:03 - 2015-07-05 02:26 - 00000050 ____N C:\WINDOWS\wiaservc.log
2015-06-30 14:03 - 2015-06-30 14:03 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2015-06-30 14:02 - 2015-07-04 22:42 - 00032566 ____N C:\WINDOWS\SchedLgU.Txt
2015-06-30 13:58 - 2015-07-02 11:53 - 00000000 ____D C:\EEK
2015-06-30 13:57 - 2015-06-30 14:12 - 00000000 ____D C:\AdwCleaner
2015-06-25 09:52 - 2015-06-25 09:52 - 00000022 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Nový objekt - Textový dokument (2).txt
2015-06-23 22:41 - 2015-07-05 02:26 - 00000284 _____ C:\WINDOWS\Tasks\ASC8_PerformanceMonitor.job
2015-06-22 21:57 - 2015-06-22 21:57 - 00000000 ____D C:\Documents and Settings\LocalService.NT AUTHORITY.000\Data aplikací\IObit
2015-06-21 21:45 - 2015-06-21 21:45 - 00074308 ____H C:\WINDOWS\system32\mlfcache.dat
2015-06-17 15:43 - 2015-06-30 21:37 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\foto
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-05 03:00 - 2014-11-25 17:03 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Temp
2015-07-05 03:00 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha
2015-07-05 02:54 - 2013-04-03 14:21 - 00001050 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1085031214-839522115-1003UA.job
2015-07-05 02:42 - 2014-03-23 15:44 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\DAEMON Tools Pro
2015-07-05 02:42 - 2013-06-20 20:16 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-05 02:41 - 2014-03-17 23:15 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-07-05 02:41 - 2014-03-17 23:15 - 00065536 _____ C:\WINDOWS\system32\config\EventForwarding-Operational.Evt
2015-07-05 02:41 - 2013-03-18 15:25 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2015-07-05 02:41 - 2013-03-18 11:36 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2015-07-05 02:41 - 2013-03-18 11:06 - 00000000 __SHD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\UserData
2015-07-05 02:41 - 2013-03-18 10:50 - 00000000 ___HD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací
2015-07-05 02:41 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348
2015-07-05 02:30 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Plocha
2015-07-05 02:29 - 2015-02-18 11:59 - 00000178 ___SH C:\Documents and Settings\postgres\ntuser.ini
2015-07-05 02:28 - 2014-06-23 20:45 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-05 02:27 - 2013-03-18 10:43 - 01622432 ____N C:\WINDOWS\WindowsUpdate.log
2015-07-05 02:26 - 2014-11-25 16:40 - 00000282 _____ C:\WINDOWS\Tasks\Game_Booster_AutoUpdate.job
2015-07-05 02:26 - 2014-06-23 20:45 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-05 02:26 - 2014-05-14 11:00 - 00000288 _____ C:\WINDOWS\Tasks\HitsBlender Update Service.job
2015-07-05 02:26 - 2014-03-18 15:48 - 00000226 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2015-07-05 02:26 - 2013-12-13 11:42 - 00046072 _____ C:\WINDOWS\system32\nvAppTimestamps
2015-07-05 02:26 - 2013-03-18 10:49 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-04 22:41 - 2013-03-18 10:50 - 00000178 ___SH C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\ntuser.ini
2015-07-04 22:37 - 2013-03-21 18:49 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\OCO
2015-07-04 22:20 - 2014-04-02 18:12 - 00000000 ____D C:\Program Files\IObit
2015-07-04 21:29 - 2013-03-18 10:49 - 00000000 __SHD C:\Documents and Settings\LocalService.NT AUTHORITY.000
2015-07-04 21:29 - 2013-03-18 10:48 - 00000000 __SHD C:\Documents and Settings\NetworkService.NT AUTHORITY.000
2015-07-04 21:28 - 2013-03-18 08:57 - 00000000 ____D C:\WINDOWS\Registration
2015-07-03 22:49 - 2013-12-10 22:36 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ProductData
2015-07-03 22:49 - 2013-12-10 22:36 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ProductData
2015-07-03 22:47 - 2001-10-25 17:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-02 20:31 - 2015-05-14 22:18 - 00001825 _____ C:\Documents and Settings\All Users.WINDOWS\Plocha\Google Chrome.lnk
2015-07-02 12:42 - 2013-06-20 20:16 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-02 12:42 - 2013-06-20 20:16 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-07-02 11:54 - 2014-11-24 18:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Google Drive
2015-07-02 11:54 - 2014-11-24 18:53 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Google Drive
2015-07-02 11:53 - 2014-04-06 19:58 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\IObit
2015-07-02 11:53 - 2014-03-09 22:55 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Wondershare Video Converter Ultimate
2015-07-02 11:53 - 2014-03-09 22:55 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Wondershare Video Converter Ultimate
2015-07-02 11:53 - 2013-03-18 11:35 - 00000000 ___RD C:\Documents and Settings\All Users.WINDOWS\Dokumenty
2015-07-02 11:53 - 2013-03-18 11:34 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS
2015-07-02 11:51 - 2013-09-11 16:17 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2015-07-02 11:51 - 2013-09-11 16:17 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2015-07-02 11:25 - 2013-03-18 11:34 - 00000000 __RHD C:\Documents and Settings\All Users.WINDOWS\Data aplikací
2015-07-02 09:33 - 2013-03-19 21:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2015-07-02 09:33 - 2013-03-19 21:54 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2015-07-01 21:24 - 2013-03-18 10:50 - 00000000 ___RD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Dokumenty
2015-06-30 20:50 - 2013-12-17 10:08 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2015-06-30 20:50 - 2013-12-17 10:08 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2015-06-30 14:33 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy
2015-06-30 14:33 - 2013-03-18 11:35 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy
2015-06-30 14:33 - 2013-03-18 10:50 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací
2015-06-30 13:12 - 2015-01-05 19:17 - 00000000 ____D C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\MPC-HC
2015-06-30 12:56 - 2013-12-13 13:16 - 41447424 _____ C:\WINDOWS\system32\config\software.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00643072 _____ C:\WINDOWS\system32\config\default.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00081920 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2015-06-30 12:56 - 2013-12-13 13:16 - 00028672 _____ C:\WINDOWS\system32\config\SAM.iobit
2015-06-29 07:54 - 2013-04-03 14:21 - 00000998 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1085031214-839522115-1003Core.job
2015-06-23 22:41 - 2013-03-18 10:50 - 00000000 ___HD C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Šablony
2015-06-19 12:20 - 2013-12-17 13:45 - 00002565 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Plocha\Microsoft Office Word 2007.lnk
2015-06-17 13:11 - 2015-05-20 19:23 - 00011199 _____ C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SmarThruOptions.xml
2015-06-08 15:00 - 2014-03-18 15:48 - 00000220 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
==================== Files in the root of some directories =======
2014-03-26 22:07 - 2014-03-26 22:07 - 0000604 ____H () C:\Program Files\STLL Notifier
2015-01-11 22:10 - 2009-08-27 18:50 - 0000701 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\init.dll
2014-12-23 12:26 - 2014-12-23 14:47 - 0000115 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\LogFile.txt
2015-05-20 19:23 - 2015-06-17 13:11 - 0011199 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SmarThruOptions.xml
2015-01-11 22:10 - 2009-09-15 10:14 - 0000701 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\sound.dll
2015-01-11 22:10 - 2009-09-11 17:33 - 0000006 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\SYSTEM32.dll
2015-01-11 22:11 - 2015-01-11 22:11 - 0000048 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Data aplikací\tigersetting.dll
2015-01-06 23:09 - 2015-01-07 23:11 - 0005632 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-31 22:00 - 2014-03-31 22:02 - 0000024 _____ () C:\Documents and Settings\Henrich.DOMA-9C5ACA6348\Local Settings\Data aplikací\pdfshaper.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
Do prílohy som pridal Addition.rar