
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Špatné starty PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Špatné starty PC
Dobrý den, mám problém s mým PC. Když ho zapnu, sám od sebe během startu spadne a začne se načítat znovu. Nestane se to úplně pokaždé, ale často, někdy jednou, někdy víckrát. Občas se to stane i ve chvíli, kdy už nějakou dobu na něm normálně pracuji. Nemám tušení, v čem by mohl být problém. Zkoušela jsem i obnovu systému, ale nic se nezměnilo a v tomto bodě mé schopnosti končí. Přikládám log FRST a prosím o radu. Díky. Alex
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Saša (administrator) on PCIMPACT on 17-02-2014 11:25:18
Running from C:\Documents and Settings\Saša\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Oracle Corporation) C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Realtek Semiconductor Corp.) C:\WINDOWS\ALCMTR.EXE
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [High Definition Audio Property Page Shortcut] - C:\WINDOWS\system32\HDAShCut.exe [61952 2005-01-07] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [14156800 2005-04-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [65536 2005-04-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
HKU\S-1-5-21-1844237615-507921405-682003330-1003\...\MountPoints2: {948188b0-158e-11de-94bf-00132098d4a5} - F:\kyme.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
Startup: C:\Documents and Settings\Eva\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\Saša\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Documents and Settings\Saša\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\Viktor\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Documents and Settings\Viktor\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
URLSearchHook: HKCU - QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Saša\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
SearchScopes: HKLM - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKLM - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKCU - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKCU - {064B753F-7952-49E7-94DA-99A222F4E2F9} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {1585E497-9BD3-469A-8D75-03EF4665BE28} URL = http://search.yahoo.com/search?p={searc ... f-8&fr=ie8
SearchScopes: HKCU - {292FB986-0936-4BC6-86E8-4ED1526A5E2E} URL = http://search.centrum.cz/index.php?char ... x&kibitz=0
SearchScopes: HKCU - {9E22ECDB-ECD0-48B2-88E0-C06F6C5F65B2} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Saša\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default
FF DefaultSearchEngine: QIP Search
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.qip.ru/search?from=FF&query=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\searchplugins\qipsearch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - WEB - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\2020Player_WEB@2020Technologies.com [2012-07-13]
FF Extension: Lavasoft Search Plugin - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2012-05-18]
FF Extension: Ad-Aware Security Toolbar - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2012-05-18]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-01-27]
========================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664 2012-05-04] (Oracle Corporation)
==================== Drivers (Whitelisted) ====================
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49664 2006-04-12] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2006-04-12] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2006-04-12] (HP)
S3 k750bus; C:\WINDOWS\System32\DRIVERS\k750bus.sys [55216 2006-03-13] (MCCI)
S3 k750mdfl; C:\WINDOWS\System32\DRIVERS\k750mdfl.sys [6576 2006-03-13] (MCCI)
S3 k750mdm; C:\WINDOWS\System32\DRIVERS\k750mdm.sys [89872 2006-03-13] (MCCI)
S3 k750mgmt; C:\WINDOWS\System32\DRIVERS\k750mgmt.sys [81728 2006-03-13] (MCCI)
S3 k750obex; C:\WINDOWS\System32\DRIVERS\k750obex.sys [79488 2006-03-13] (MCCI)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 se59bus; C:\WINDOWS\System32\DRIVERS\se59bus.sys [61536 2006-09-05] (MCCI)
S3 se59mdfl; C:\WINDOWS\System32\DRIVERS\se59mdfl.sys [9360 2006-09-05] (MCCI)
S3 se59mdm; C:\WINDOWS\System32\DRIVERS\se59mdm.sys [97088 2006-09-05] (MCCI)
S3 se59mgmt; C:\WINDOWS\System32\DRIVERS\se59mgmt.sys [88624 2006-09-05] (MCCI)
S3 se59nd5; C:\WINDOWS\System32\DRIVERS\se59nd5.sys [18704 2006-09-05] (MCCI)
S3 se59obex; C:\WINDOWS\System32\DRIVERS\se59obex.sys [86432 2006-09-05] (MCCI)
S3 se59unic; C:\WINDOWS\System32\DRIVERS\se59unic.sys [90800 2006-09-05] (MCCI)
R3 SMBios; C:\WINDOWS\System32\DRIVERS\SMBios.sys [36484 2004-06-07] (Intel Corporation)
S1 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [31744 2008-04-14] (Microsoft Corporation)
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-08-08 17:00 - 2014-02-13 22:01 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-17 11:25 - 2014-02-17 11:25 - 00014865 _____ () C:\Documents and Settings\Saša\Plocha\FRST.txt
2014-02-17 11:25 - 2014-02-17 11:25 - 00000000 ____D () C:\FRST
2014-02-17 11:24 - 2014-02-17 11:24 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
2014-02-17 11:23 - 2014-02-17 11:24 - 01141248 _____ (Farbar) C:\Documents and Settings\Saša\Plocha\FRST.exe
2014-02-13 22:06 - 2014-02-13 22:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 21:58 - 2014-02-13 21:59 - 00011909 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-13 21:57 - 2014-02-13 21:58 - 00004757 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-13 20:48 - 2014-02-13 22:06 - 00013611 _____ () C:\WINDOWS\KB2916036.log
2014-02-05 20:08 - 2014-02-05 21:08 - 05556104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-02-02 14:14 - 2014-02-02 14:14 - 00000000 ____D () C:\Documents and Settings\Eva\Dokumenty\Moje naskenované obrázky
2014-01-27 19:18 - 2014-01-27 19:18 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Poznámkové bloky aplikace OneNote
2014-01-27 19:04 - 2014-01-27 19:04 - 00000518 _____ () C:\Documents and Settings\Viktor\Plocha\Zástupce - Moje naskenované obrázky.lnk
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Program Files\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
==================== One Month Modified Files and Folders =======
2014-08-08 17:56 - 2010-02-14 21:13 - 00000462 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC38165D-4FD0-4615-823E-5C6A629753E0}.job
2014-02-17 11:25 - 2014-02-17 11:25 - 00014865 _____ () C:\Documents and Settings\Saša\Plocha\FRST.txt
2014-02-17 11:25 - 2014-02-17 11:25 - 00000000 ____D () C:\FRST
2014-02-17 11:25 - 2009-02-24 13:45 - 00000000 ____D () C:\Documents and Settings\Saša\Plocha
2014-02-17 11:24 - 2014-02-17 11:24 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
2014-02-17 11:24 - 2014-02-17 11:23 - 01141248 _____ (Farbar) C:\Documents and Settings\Saša\Plocha\FRST.exe
2014-02-17 11:24 - 2009-02-24 13:45 - 00000000 ___HD () C:\Documents and Settings\Saša\Local Settings\Data aplikací
2014-02-17 11:23 - 2009-06-06 11:27 - 00000464 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4EDD956-0ABA-4CFF-A9C0-66E6B6E916E4}.job
2014-02-17 11:08 - 2012-05-10 18:39 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-17 10:53 - 2009-02-23 15:42 - 00032638 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-17 10:49 - 2009-02-23 16:25 - 00000211 _____ () C:\WINDOWS\wiadebug.log
2014-02-17 10:47 - 2013-07-03 08:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 10:42 - 2009-02-23 15:36 - 01620556 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-17 10:40 - 2009-03-11 20:38 - 00000000 ____D () C:\Documents and Settings\Saša\Dokumenty\Moje naskenované obrázky
2014-02-17 10:35 - 2009-02-24 13:50 - 00073408 _____ () C:\Documents and Settings\Saša\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-02-17 10:33 - 2009-02-23 17:20 - 00000000 ____D () C:\WINDOWS\system32\Lang
2014-02-17 10:33 - 2009-02-23 16:25 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-17 10:33 - 2004-08-18 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-17 10:32 - 2009-02-23 15:42 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-15 22:29 - 2009-02-24 21:32 - 00000178 ___SH () C:\Documents and Settings\Viktor\ntuser.ini
2014-02-15 11:22 - 2013-10-19 14:43 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-02-15 10:46 - 2011-04-14 20:30 - 00004876 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-02-13 22:06 - 2014-02-13 22:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 22:06 - 2014-02-13 20:48 - 00013611 _____ () C:\WINDOWS\KB2916036.log
2014-02-13 22:06 - 2009-02-24 08:11 - 00336655 _____ () C:\WINDOWS\updspapi.log
2014-02-13 22:06 - 2009-02-23 16:22 - 02113865 _____ () C:\WINDOWS\FaxSetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 01027715 _____ () C:\WINDOWS\ocgen.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00973129 _____ () C:\WINDOWS\tsoc.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00715419 _____ () C:\WINDOWS\comsetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00669304 _____ () C:\WINDOWS\msmqinst.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00432265 _____ () C:\WINDOWS\ntdtcsetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00371882 _____ () C:\WINDOWS\netfxocm.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00308906 _____ () C:\WINDOWS\iis6.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00147886 _____ () C:\WINDOWS\MedCtrOC.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00132024 _____ () C:\WINDOWS\ocmsn.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00107151 _____ () C:\WINDOWS\tabletoc.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00106251 _____ () C:\WINDOWS\msgsocm.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-02-13 22:04 - 2009-02-23 16:22 - 00988216 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-13 22:01 - 2014-08-08 17:00 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-13 21:59 - 2014-02-13 21:58 - 00011909 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-13 21:59 - 2009-02-24 13:13 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-13 21:59 - 2009-02-23 16:22 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-02-13 21:58 - 2014-02-13 21:57 - 00004757 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-11 20:09 - 2009-02-24 21:18 - 00000178 ___SH () C:\Documents and Settings\Eva\ntuser.ini
2014-02-11 20:04 - 2009-02-24 21:18 - 00000000 ____D () C:\Documents and Settings\Eva\Plocha
2014-02-09 17:23 - 2009-02-24 21:32 - 00000000 ____D () C:\Documents and Settings\Viktor\Plocha
2014-02-09 16:40 - 2011-02-26 15:26 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Stažené soubory
2014-02-06 21:07 - 2009-02-23 16:21 - 00994335 _____ () C:\WINDOWS\setupapi.log
2014-02-06 21:07 - 2009-02-23 16:21 - 00197729 _____ () C:\WINDOWS\setupact.log
2014-02-06 04:38 - 2009-02-24 13:09 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-06 04:38 - 2004-08-18 13:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 00:08 - 2012-06-14 16:12 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-06 00:08 - 2010-08-09 19:46 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-06 00:08 - 2009-06-11 06:53 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-06 00:08 - 2009-06-11 06:53 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-06 00:08 - 2009-02-24 13:09 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-06 00:08 - 2009-02-24 13:09 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-06 00:08 - 2007-08-13 18:45 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-06 00:08 - 2007-08-13 18:44 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-06 00:08 - 2007-08-13 18:44 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-06 00:08 - 2007-08-13 18:44 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-06 00:08 - 2007-08-13 18:42 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-06 00:08 - 2007-08-13 18:39 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-06 00:08 - 2007-08-13 18:34 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 01469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 00:08 - 2004-08-18 13:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 23:24 - 2007-08-13 18:39 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-05 23:24 - 2004-08-18 13:00 - 00385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-02-05 23:24 - 2004-08-18 13:00 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 21:08 - 2014-02-05 20:08 - 05556104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-02-05 21:08 - 2012-05-10 18:39 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-05 21:08 - 2011-06-03 19:20 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-04 18:55 - 2009-09-15 21:27 - 00002563 _____ () C:\Documents and Settings\Eva\Plocha\Microsoft Office Word 2007.lnk
2014-02-02 21:54 - 2009-11-03 19:01 - 00000000 ____D () C:\Documents and Settings\Eva\Data aplikací\Image Zone Express
2014-02-02 14:14 - 2014-02-02 14:14 - 00000000 ____D () C:\Documents and Settings\Eva\Dokumenty\Moje naskenované obrázky
2014-02-02 14:14 - 2009-02-24 21:18 - 00000000 ___RD () C:\Documents and Settings\Eva\Dokumenty
2014-01-27 19:18 - 2014-01-27 19:18 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Poznámkové bloky aplikace OneNote
2014-01-27 19:18 - 2009-02-24 21:32 - 00000000 ___RD () C:\Documents and Settings\Viktor\Dokumenty
2014-01-27 19:04 - 2014-01-27 19:04 - 00000518 _____ () C:\Documents and Settings\Viktor\Plocha\Zástupce - Moje naskenované obrázky.lnk
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Program Files\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-01-27 18:38 - 2009-02-23 16:22 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-01-27 18:38 - 2009-02-23 16:21 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-01-27 18:23 - 2009-03-03 20:56 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-01-27 18:08 - 2014-01-16 01:38 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-01-27 18:08 - 2014-01-16 01:37 - 00010104 _____ () C:\WINDOWS\KB2914368.log
2014-01-27 17:40 - 2009-02-24 21:32 - 00000000 ____D () C:\Documents and Settings\Viktor
2014-01-27 17:40 - 2009-02-24 21:18 - 00000000 ____D () C:\Documents and Settings\Eva
2014-01-27 17:40 - 2009-02-24 13:45 - 00000000 ____D () C:\Documents and Settings\Saša
2014-01-27 17:40 - 2009-02-23 15:44 - 00000000 ____D () C:\Documents and Settings\Všichni
2014-01-27 17:40 - 2009-02-23 15:42 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-01-27 17:40 - 2009-02-23 15:41 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-01-27 17:40 - 2009-02-23 15:34 - 00000000 ____D () C:\WINDOWS\Registration
2014-01-27 17:27 - 2013-12-12 09:31 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
Some content of TEMP:
====================
C:\Documents and Settings\Eva\Local Settings\Temp\adca3ba5-1956-4ddd-b713-655c519757e8.dll
C:\Documents and Settings\Eva\Local Settings\Temp\AskSLib.dll
C:\Documents and Settings\Eva\Local Settings\Temp\b0d2fabd-1b8a-4ed1-8654-00ac2864de2f.dll
C:\Documents and Settings\Eva\Local Settings\Temp\InstHelper.exe
C:\Documents and Settings\Eva\Local Settings\Temp\jre-7u9-windows-i586-iftw.exe
C:\Documents and Settings\Eva\Local Settings\Temp\mpengine.dll
C:\Documents and Settings\Eva\Local Settings\Temp\PDFXVwer.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe-1.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe-2.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe.exe
C:\Documents and Settings\Saša\Local Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Saša\Local Settings\Temp\hpzscr01.exe
C:\Documents and Settings\Saša\Local Settings\Temp\ose00000.exe
C:\Documents and Settings\Saša\Local Settings\Temp\setup.exe
C:\Documents and Settings\Saša\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\Viktor\Local Settings\Temp\38d6c5ac-d5b0-44bf-b38c-90fcb3a9bdec.dll
C:\Documents and Settings\Viktor\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\Viktor\Local Settings\Temp\setup_wm.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-18 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2004-08-18 13:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-18 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC38165D-4FD0-4615-823E-5C6A629753E0}.job => C:\WINDOWS\system32\msfeedssync.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4EDD956-0ABA-4CFF-A9C0-66E6B6E916E4}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 7.0 (Disabled - Up to date) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personální firewall (Disabled) {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Saa\Plocha" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Documents and Settings\\Eva\\Local Settings\\Temp\\TeamViewer\\Version7\\TeamViewer.exe"="C:\\Documents and Settings\\Eva\\Local Settings\\Temp\\TeamViewer\\Version7\\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Saša (administrator) on PCIMPACT on 17-02-2014 11:25:18
Running from C:\Documents and Settings\Saša\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Oracle Corporation) C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Realtek Semiconductor Corp.) C:\WINDOWS\ALCMTR.EXE
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [High Definition Audio Property Page Shortcut] - C:\WINDOWS\system32\HDAShCut.exe [61952 2005-01-07] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [14156800 2005-04-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [65536 2005-04-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
HKU\S-1-5-21-1844237615-507921405-682003330-1003\...\MountPoints2: {948188b0-158e-11de-94bf-00132098d4a5} - F:\kyme.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
Startup: C:\Documents and Settings\Eva\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\Saša\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Documents and Settings\Saša\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\Viktor\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Documents and Settings\Viktor\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
URLSearchHook: HKCU - QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Saša\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
SearchScopes: HKLM - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKLM - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKCU - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
SearchScopes: HKCU - {064B753F-7952-49E7-94DA-99A222F4E2F9} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {1585E497-9BD3-469A-8D75-03EF4665BE28} URL = http://search.yahoo.com/search?p={searc ... f-8&fr=ie8
SearchScopes: HKCU - {292FB986-0936-4BC6-86E8-4ED1526A5E2E} URL = http://search.centrum.cz/index.php?char ... x&kibitz=0
SearchScopes: HKCU - {9E22ECDB-ECD0-48B2-88E0-C06F6C5F65B2} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/?query={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Saša\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default
FF DefaultSearchEngine: QIP Search
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.qip.ru/search?from=FF&query=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\searchplugins\qipsearch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - WEB - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\2020Player_WEB@2020Technologies.com [2012-07-13]
FF Extension: Lavasoft Search Plugin - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2012-05-18]
FF Extension: Ad-Aware Security Toolbar - C:\Documents and Settings\Saša\Data aplikací\Mozilla\Firefox\Profiles\csanqwlo.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2012-05-18]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-01-27]
========================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664 2012-05-04] (Oracle Corporation)
==================== Drivers (Whitelisted) ====================
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49664 2006-04-12] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2006-04-12] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2006-04-12] (HP)
S3 k750bus; C:\WINDOWS\System32\DRIVERS\k750bus.sys [55216 2006-03-13] (MCCI)
S3 k750mdfl; C:\WINDOWS\System32\DRIVERS\k750mdfl.sys [6576 2006-03-13] (MCCI)
S3 k750mdm; C:\WINDOWS\System32\DRIVERS\k750mdm.sys [89872 2006-03-13] (MCCI)
S3 k750mgmt; C:\WINDOWS\System32\DRIVERS\k750mgmt.sys [81728 2006-03-13] (MCCI)
S3 k750obex; C:\WINDOWS\System32\DRIVERS\k750obex.sys [79488 2006-03-13] (MCCI)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 se59bus; C:\WINDOWS\System32\DRIVERS\se59bus.sys [61536 2006-09-05] (MCCI)
S3 se59mdfl; C:\WINDOWS\System32\DRIVERS\se59mdfl.sys [9360 2006-09-05] (MCCI)
S3 se59mdm; C:\WINDOWS\System32\DRIVERS\se59mdm.sys [97088 2006-09-05] (MCCI)
S3 se59mgmt; C:\WINDOWS\System32\DRIVERS\se59mgmt.sys [88624 2006-09-05] (MCCI)
S3 se59nd5; C:\WINDOWS\System32\DRIVERS\se59nd5.sys [18704 2006-09-05] (MCCI)
S3 se59obex; C:\WINDOWS\System32\DRIVERS\se59obex.sys [86432 2006-09-05] (MCCI)
S3 se59unic; C:\WINDOWS\System32\DRIVERS\se59unic.sys [90800 2006-09-05] (MCCI)
R3 SMBios; C:\WINDOWS\System32\DRIVERS\SMBios.sys [36484 2004-06-07] (Intel Corporation)
S1 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [31744 2008-04-14] (Microsoft Corporation)
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-08-08 17:00 - 2014-02-13 22:01 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-17 11:25 - 2014-02-17 11:25 - 00014865 _____ () C:\Documents and Settings\Saša\Plocha\FRST.txt
2014-02-17 11:25 - 2014-02-17 11:25 - 00000000 ____D () C:\FRST
2014-02-17 11:24 - 2014-02-17 11:24 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
2014-02-17 11:23 - 2014-02-17 11:24 - 01141248 _____ (Farbar) C:\Documents and Settings\Saša\Plocha\FRST.exe
2014-02-13 22:06 - 2014-02-13 22:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 21:58 - 2014-02-13 21:59 - 00011909 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-13 21:57 - 2014-02-13 21:58 - 00004757 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-13 20:48 - 2014-02-13 22:06 - 00013611 _____ () C:\WINDOWS\KB2916036.log
2014-02-05 20:08 - 2014-02-05 21:08 - 05556104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-02-02 14:14 - 2014-02-02 14:14 - 00000000 ____D () C:\Documents and Settings\Eva\Dokumenty\Moje naskenované obrázky
2014-01-27 19:18 - 2014-01-27 19:18 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Poznámkové bloky aplikace OneNote
2014-01-27 19:04 - 2014-01-27 19:04 - 00000518 _____ () C:\Documents and Settings\Viktor\Plocha\Zástupce - Moje naskenované obrázky.lnk
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Program Files\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
==================== One Month Modified Files and Folders =======
2014-08-08 17:56 - 2010-02-14 21:13 - 00000462 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC38165D-4FD0-4615-823E-5C6A629753E0}.job
2014-02-17 11:25 - 2014-02-17 11:25 - 00014865 _____ () C:\Documents and Settings\Saša\Plocha\FRST.txt
2014-02-17 11:25 - 2014-02-17 11:25 - 00000000 ____D () C:\FRST
2014-02-17 11:25 - 2009-02-24 13:45 - 00000000 ____D () C:\Documents and Settings\Saša\Plocha
2014-02-17 11:24 - 2014-02-17 11:24 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Saša\Plocha\FRSTLauncher.exe
2014-02-17 11:24 - 2014-02-17 11:23 - 01141248 _____ (Farbar) C:\Documents and Settings\Saša\Plocha\FRST.exe
2014-02-17 11:24 - 2009-02-24 13:45 - 00000000 ___HD () C:\Documents and Settings\Saša\Local Settings\Data aplikací
2014-02-17 11:23 - 2009-06-06 11:27 - 00000464 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4EDD956-0ABA-4CFF-A9C0-66E6B6E916E4}.job
2014-02-17 11:08 - 2012-05-10 18:39 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-17 10:53 - 2009-02-23 15:42 - 00032638 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-17 10:49 - 2009-02-23 16:25 - 00000211 _____ () C:\WINDOWS\wiadebug.log
2014-02-17 10:47 - 2013-07-03 08:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 10:42 - 2009-02-23 15:36 - 01620556 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-17 10:40 - 2009-03-11 20:38 - 00000000 ____D () C:\Documents and Settings\Saša\Dokumenty\Moje naskenované obrázky
2014-02-17 10:35 - 2009-02-24 13:50 - 00073408 _____ () C:\Documents and Settings\Saša\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-02-17 10:33 - 2009-02-23 17:20 - 00000000 ____D () C:\WINDOWS\system32\Lang
2014-02-17 10:33 - 2009-02-23 16:25 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-17 10:33 - 2004-08-18 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-17 10:32 - 2009-02-23 15:42 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-15 22:29 - 2009-02-24 21:32 - 00000178 ___SH () C:\Documents and Settings\Viktor\ntuser.ini
2014-02-15 11:22 - 2013-10-19 14:43 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-02-15 10:46 - 2011-04-14 20:30 - 00004876 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-02-13 22:06 - 2014-02-13 22:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 22:06 - 2014-02-13 20:48 - 00013611 _____ () C:\WINDOWS\KB2916036.log
2014-02-13 22:06 - 2009-02-24 08:11 - 00336655 _____ () C:\WINDOWS\updspapi.log
2014-02-13 22:06 - 2009-02-23 16:22 - 02113865 _____ () C:\WINDOWS\FaxSetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 01027715 _____ () C:\WINDOWS\ocgen.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00973129 _____ () C:\WINDOWS\tsoc.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00715419 _____ () C:\WINDOWS\comsetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00669304 _____ () C:\WINDOWS\msmqinst.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00432265 _____ () C:\WINDOWS\ntdtcsetup.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00371882 _____ () C:\WINDOWS\netfxocm.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00308906 _____ () C:\WINDOWS\iis6.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00147886 _____ () C:\WINDOWS\MedCtrOC.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00132024 _____ () C:\WINDOWS\ocmsn.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00107151 _____ () C:\WINDOWS\tabletoc.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00106251 _____ () C:\WINDOWS\msgsocm.log
2014-02-13 22:06 - 2009-02-23 16:22 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-02-13 22:04 - 2009-02-23 16:22 - 00988216 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-13 22:01 - 2014-08-08 17:00 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-13 21:59 - 2014-02-13 21:58 - 00011909 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-13 21:59 - 2009-02-24 13:13 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-13 21:59 - 2009-02-23 16:22 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-02-13 21:58 - 2014-02-13 21:57 - 00004757 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-11 20:09 - 2009-02-24 21:18 - 00000178 ___SH () C:\Documents and Settings\Eva\ntuser.ini
2014-02-11 20:04 - 2009-02-24 21:18 - 00000000 ____D () C:\Documents and Settings\Eva\Plocha
2014-02-09 17:23 - 2009-02-24 21:32 - 00000000 ____D () C:\Documents and Settings\Viktor\Plocha
2014-02-09 16:40 - 2011-02-26 15:26 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Stažené soubory
2014-02-06 21:07 - 2009-02-23 16:21 - 00994335 _____ () C:\WINDOWS\setupapi.log
2014-02-06 21:07 - 2009-02-23 16:21 - 00197729 _____ () C:\WINDOWS\setupact.log
2014-02-06 04:38 - 2009-02-24 13:09 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-06 04:38 - 2004-08-18 13:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 00:08 - 2012-06-14 16:12 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-06 00:08 - 2010-08-09 19:46 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-06 00:08 - 2009-06-11 06:53 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-06 00:08 - 2009-06-11 06:53 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-06 00:08 - 2009-02-24 13:28 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-06 00:08 - 2009-02-24 13:09 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-06 00:08 - 2009-02-24 13:09 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-06 00:08 - 2007-08-13 18:54 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-06 00:08 - 2007-08-13 18:45 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-06 00:08 - 2007-08-13 18:44 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-06 00:08 - 2007-08-13 18:44 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-06 00:08 - 2007-08-13 18:44 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-06 00:08 - 2007-08-13 18:42 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-06 00:08 - 2007-08-13 18:39 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-06 00:08 - 2007-08-13 18:34 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 01469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 00:08 - 2004-08-18 13:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 00:08 - 2004-08-18 13:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 23:24 - 2007-08-13 18:39 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-05 23:24 - 2004-08-18 13:00 - 00385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-02-05 23:24 - 2004-08-18 13:00 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 21:08 - 2014-02-05 20:08 - 05556104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-02-05 21:08 - 2012-05-10 18:39 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-05 21:08 - 2011-06-03 19:20 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-04 18:55 - 2009-09-15 21:27 - 00002563 _____ () C:\Documents and Settings\Eva\Plocha\Microsoft Office Word 2007.lnk
2014-02-02 21:54 - 2009-11-03 19:01 - 00000000 ____D () C:\Documents and Settings\Eva\Data aplikací\Image Zone Express
2014-02-02 14:14 - 2014-02-02 14:14 - 00000000 ____D () C:\Documents and Settings\Eva\Dokumenty\Moje naskenované obrázky
2014-02-02 14:14 - 2009-02-24 21:18 - 00000000 ___RD () C:\Documents and Settings\Eva\Dokumenty
2014-01-27 19:18 - 2014-01-27 19:18 - 00000000 ____D () C:\Documents and Settings\Viktor\Dokumenty\Poznámkové bloky aplikace OneNote
2014-01-27 19:18 - 2009-02-24 21:32 - 00000000 ___RD () C:\Documents and Settings\Viktor\Dokumenty
2014-01-27 19:04 - 2014-01-27 19:04 - 00000518 _____ () C:\Documents and Settings\Viktor\Plocha\Zástupce - Moje naskenované obrázky.lnk
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Program Files\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-01-27 18:38 - 2014-01-27 18:38 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-01-27 18:38 - 2009-02-23 16:22 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-01-27 18:38 - 2009-02-23 16:21 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-01-27 18:23 - 2009-03-03 20:56 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-01-27 18:08 - 2014-01-16 01:38 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-01-27 18:08 - 2014-01-16 01:37 - 00010104 _____ () C:\WINDOWS\KB2914368.log
2014-01-27 17:40 - 2009-02-24 21:32 - 00000000 ____D () C:\Documents and Settings\Viktor
2014-01-27 17:40 - 2009-02-24 21:18 - 00000000 ____D () C:\Documents and Settings\Eva
2014-01-27 17:40 - 2009-02-24 13:45 - 00000000 ____D () C:\Documents and Settings\Saša
2014-01-27 17:40 - 2009-02-23 15:44 - 00000000 ____D () C:\Documents and Settings\Všichni
2014-01-27 17:40 - 2009-02-23 15:42 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-01-27 17:40 - 2009-02-23 15:41 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-01-27 17:40 - 2009-02-23 15:34 - 00000000 ____D () C:\WINDOWS\Registration
2014-01-27 17:27 - 2013-12-12 09:31 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
Some content of TEMP:
====================
C:\Documents and Settings\Eva\Local Settings\Temp\adca3ba5-1956-4ddd-b713-655c519757e8.dll
C:\Documents and Settings\Eva\Local Settings\Temp\AskSLib.dll
C:\Documents and Settings\Eva\Local Settings\Temp\b0d2fabd-1b8a-4ed1-8654-00ac2864de2f.dll
C:\Documents and Settings\Eva\Local Settings\Temp\InstHelper.exe
C:\Documents and Settings\Eva\Local Settings\Temp\jre-7u9-windows-i586-iftw.exe
C:\Documents and Settings\Eva\Local Settings\Temp\mpengine.dll
C:\Documents and Settings\Eva\Local Settings\Temp\PDFXVwer.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe-1.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe-2.exe
C:\Documents and Settings\Saša\Local Settings\Temp\firefoxjre_exe.exe
C:\Documents and Settings\Saša\Local Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Saša\Local Settings\Temp\hpzscr01.exe
C:\Documents and Settings\Saša\Local Settings\Temp\ose00000.exe
C:\Documents and Settings\Saša\Local Settings\Temp\setup.exe
C:\Documents and Settings\Saša\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\Viktor\Local Settings\Temp\38d6c5ac-d5b0-44bf-b38c-90fcb3a9bdec.dll
C:\Documents and Settings\Viktor\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\Viktor\Local Settings\Temp\setup_wm.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-18 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2004-08-18 13:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-18 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC38165D-4FD0-4615-823E-5C6A629753E0}.job => C:\WINDOWS\system32\msfeedssync.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4EDD956-0ABA-4CFF-A9C0-66E6B6E916E4}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 7.0 (Disabled - Up to date) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personální firewall (Disabled) {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Saa\Plocha" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Documents and Settings\\Eva\\Local Settings\\Temp\\TeamViewer\\Version7\\TeamViewer.exe"="C:\\Documents and Settings\\Eva\\Local Settings\\Temp\\TeamViewer\\Version7\\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
- Rudy
- Site Admin
- Příspěvky: 119381
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Špatné starty PC
Zdravím!
Otevřte adresář c:\windows\minidump a pokud v něm najdete nějaké soubory, zabalte je fo raru a přiložte k vašemu příštímu postu.
Otevřte adresář c:\windows\minidump a pokud v něm najdete nějaké soubory, zabalte je fo raru a přiložte k vašemu příštímu postu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- Rudy
- Site Admin
- Příspěvky: 119381
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Špatné starty PC
Windows vám shazují systémové ovladače. Není v PC něco přetaktováno?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Špatné starty PC
Popravdě nevím, jestli tam nemůže být něco z dřívějška, ale v posledních měsících, možná i letech u toho nikdo kromě členů rodiny neseděl. Pokud se něco takového nedá udělat omylem, tak nikdo z nich nic s PC nedělal, rozumí tomu ještě míň, než já.
- Rudy
- Site Admin
- Příspěvky: 119381
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Špatné starty PC
Přetaktovat lze pouze vědomě. Zkuste přeinstalovat ovladače základní desky.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Špatné starty PC
Můžete mi, prosím, říct, jaké přesně? Úplně si nejsem jistá, co všechno pod ten pojem spadá.
Jinak moc díky za rady.
Jinak moc díky za rady.
- Rudy
- Site Admin
- Příspěvky: 119381
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Špatné starty PC
Ovladače zákl. desky jsou ty, které se instalují pro řízení chipsetu desky. Bohužel každý výrobce je jinak nazývá. měly by být dostupné na webu výrobce zákl. desky, nebo je máte na CD, dodaném se zákl. deskou.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Špatné starty PC
Tak se mi povedlo najít CD s ovladači, před týdnem jsem něco zkusila přeinstalovat, ale problém trvá... Nemáte ještě nějaký tip?
- Rudy
- Site Admin
- Příspěvky: 119381
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Špatné starty PC
Zkuste kontrolu RAM: http://forum.viry.cz/viewtopic.php?f=53&t=106788 . Není v PC něco přetaktováno?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.