
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Pomalý notebook - Podezření na vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Pomalý notebook - Podezření na vir
Dejte log dle tohoto http://forum.viry.cz/viewtopic.php?f=13&t=133100
Re: Pomalý notebook - Podezření na vir
Pořád se to dost seká. Co byste poradil jako další krok? Díky
Majkl55
Re: Pomalý notebook - Podezření na vir
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Ondra (administrator) on ONDRA-PC on 17-02-2014 22:12:50
Running from C:\Users\Ondra\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\smartlogon.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
() C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program files\P4G\BatteryLife.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Windows\AsScrPro.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe
(SMART Technologies) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
(Apple Inc.) C:\Program Files\QuickTime\qttask.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardTools.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Aware.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Marker.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_44_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [104936 2008-07-19] (CyberLink)
HKLM\...\Run: [P2Go_Menu] - C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [210216 2008-06-14] (CyberLink Corp.)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [98304 2008-08-18] (ASUS)
HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [8105984 2008-09-03] (ASUS)
HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-12-29] (ASUS)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6711840 2009-02-11] (Realtek Semiconductor)
HKLM\...\Run: [ADSMTray] - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [266240 2008-04-01] (ASUSTek Computer Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [ACMON] - C:\Program Files\ASUS\Splendid\ACMON.exe [851968 2008-10-01] (ATK)
HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3054136 2009-06-10] (ASUS)
HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2009-06-10] ()
HKLM\...\Run: [MobileConnect] - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2086912 2008-10-09] (Vodafone)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13789728 2009-07-02] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [3076144 2011-08-09] (ESET)
HKLM\...\Run: [SMART SNMP Agent] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe [1037608 2008-07-31] (SMART Technologies ULC)
HKLM\...\Run: [SMART Board Service] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe [2123048 2008-08-08] (SMART Technologies)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
BHO: CIEDownload Object - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsup ... gctlcm.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{400211BB-8E7D-476A-B18B-BADBBB9EDD13}: [NameServer]10.255.255.10,10.255.255.20
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-01-01]
========================== Services (Whitelisted) =================
R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [100920 2008-08-14] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [974944 2011-08-09] (ESET)
S2 gupdate1ca06351bc16190; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-07-16] (Google Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-10-09] (Vodafone)
S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
==================== Drivers (Whitelisted) ====================
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-06-10] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-10-07] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [147480 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [33656 2011-08-04] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2011-08-04] (ESET)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1083880 2009-04-11] (Společnost Microsoft)
R3 SMARTMouseFilterx86; C:\Windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2008-07-30] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\Windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2008-07-30] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\Windows\System32\DRIVERS\SMARTVTabletPCx86.sys [16808 2008-07-30] (SMART Technologies ULC)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1753984 2009-03-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-07-08] ()
R3 SRS_PremiumSound_Service; C:\Windows\System32\drivers\srs_PremiumSound_i386.sys [230952 2009-01-14] ()
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-17 22:12 - 2014-02-17 22:13 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:12 - 00000000 ____D () C:\FRST
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-09 13:10 - 2014-02-17 21:59 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-08 19:49 - 2014-02-09 13:39 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-08 19:49 - 2014-02-09 13:37 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:49 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:21 - 2014-02-16 17:37 - 00000000 ____D () C:\AdwCleaner
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-02 16:24 - 2014-02-02 16:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-01-19 18:32 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:30 - 2014-01-19 18:36 - 00000000 ____D () C:\ProgramData\InstallMate
==================== One Month Modified Files and Folders =======
2014-02-17 22:13 - 2014-02-17 22:12 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:12 - 2014-02-17 22:08 - 00000000 ____D () C:\FRST
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:11 - 2014-02-17 22:09 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 22:06 - 2006-11-02 10:33 - 01393902 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 22:01 - 2009-06-25 20:54 - 00031871 _____ () C:\ProgramData\nvModes.001
2014-02-17 22:01 - 2009-06-10 04:39 - 00000000 ___HD () C:\ASUS.DAT
2014-02-17 22:00 - 2014-02-15 18:07 - 00008594 _____ () C:\zoek-results.log
2014-02-17 21:59 - 2014-02-09 13:10 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-17 21:59 - 2013-02-19 10:13 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-17 21:59 - 2013-01-04 01:11 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-02-17 21:59 - 2009-06-25 20:53 - 00031871 _____ () C:\ProgramData\nvModes.dat
2014-02-17 21:59 - 2006-11-02 13:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:58 - 2006-11-02 13:01 - 00032566 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-17 21:57 - 2009-06-10 04:09 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-02-17 21:57 - 2009-06-10 03:37 - 01980783 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 21:52 - 2009-07-31 14:13 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Skype
2014-02-17 21:45 - 2013-02-19 10:13 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-17 21:17 - 2013-03-31 19:13 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-17 21:16 - 2014-02-17 21:56 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-16 17:37 - 2014-02-08 17:21 - 00000000 ____D () C:\AdwCleaner
2014-02-16 14:44 - 2013-01-03 21:21 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-02-16 12:24 - 2014-02-17 21:33 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 03:18 - 2014-02-16 12:07 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-16 00:01 - 2014-02-09 22:09 - 00000000 ____D () C:\zoek_backup
2014-02-15 18:01 - 2014-02-15 18:00 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:13 - 2014-02-09 22:52 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-02-09 15:23 - 2012-09-30 14:01 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter
2014-02-09 13:39 - 2014-02-08 19:49 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-09 13:37 - 2014-02-08 19:49 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 18:40 - 2009-08-15 18:43 - 00000000 ____D () C:\Windows\Minidump
2014-02-08 18:40 - 2009-07-04 20:55 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\uTorrent
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:36 - 2012-12-09 12:48 - 00000000 ____D () C:\Program Files\trend micro
2014-02-08 17:20 - 2014-02-08 17:09 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 21:17 - 2012-04-03 18:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-06 21:17 - 2011-09-14 19:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-06 21:06 - 2009-07-16 16:49 - 00001978 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-06 20:58 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-02-06 20:58 - 2009-09-15 19:17 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-02-06 20:30 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-02-06 20:29 - 2009-06-25 17:16 - 00000000 ____D () C:\Users\Ondra
2014-02-06 20:29 - 2006-11-02 10:22 - 51642368 _____ () C:\Windows\system32\config\software_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 45875200 _____ () C:\Windows\system32\config\system_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 44302336 _____ () C:\Windows\system32\config\components_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\default_previous
2014-02-06 20:28 - 2009-06-10 04:41 - 00000000 ____D () C:\ProgramData\P4G
2014-02-06 20:28 - 2009-06-10 04:18 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-02-06 20:28 - 2009-06-10 03:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-06 20:28 - 2006-11-02 12:37 - 00000000 ____D () C:\Windows\ShellNew
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 __RSD () C:\Windows\Media
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\spool
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\rescache
2014-02-06 20:27 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\registration
2014-02-03 20:50 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-02 16:39 - 2009-06-10 03:49 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-02-02 16:27 - 2014-02-02 16:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 21:08 - 2009-06-25 17:55 - 00009728 _____ () C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-19 18:36 - 2014-01-19 18:30 - 00000000 ____D () C:\ProgramData\InstallMate
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:32 - 2009-06-25 17:34 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Google
Files to move or delete:
====================
C:\Users\Ondra\AppData\Roaming\desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-17 22:05
==================== End Of Log ============================
Ran by Ondra (administrator) on ONDRA-PC on 17-02-2014 22:12:50
Running from C:\Users\Ondra\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\smartlogon.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
() C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program files\P4G\BatteryLife.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Windows\AsScrPro.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe
(SMART Technologies) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
(Apple Inc.) C:\Program Files\QuickTime\qttask.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardTools.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Aware.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Marker.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_44_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [104936 2008-07-19] (CyberLink)
HKLM\...\Run: [P2Go_Menu] - C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [210216 2008-06-14] (CyberLink Corp.)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [98304 2008-08-18] (ASUS)
HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [8105984 2008-09-03] (ASUS)
HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-12-29] (ASUS)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6711840 2009-02-11] (Realtek Semiconductor)
HKLM\...\Run: [ADSMTray] - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [266240 2008-04-01] (ASUSTek Computer Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [ACMON] - C:\Program Files\ASUS\Splendid\ACMON.exe [851968 2008-10-01] (ATK)
HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3054136 2009-06-10] (ASUS)
HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2009-06-10] ()
HKLM\...\Run: [MobileConnect] - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2086912 2008-10-09] (Vodafone)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13789728 2009-07-02] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [3076144 2011-08-09] (ESET)
HKLM\...\Run: [SMART SNMP Agent] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe [1037608 2008-07-31] (SMART Technologies ULC)
HKLM\...\Run: [SMART Board Service] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe [2123048 2008-08-08] (SMART Technologies)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
BHO: CIEDownload Object - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsup ... gctlcm.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{400211BB-8E7D-476A-B18B-BADBBB9EDD13}: [NameServer]10.255.255.10,10.255.255.20
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-01-01]
========================== Services (Whitelisted) =================
R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [100920 2008-08-14] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [974944 2011-08-09] (ESET)
S2 gupdate1ca06351bc16190; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-07-16] (Google Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-10-09] (Vodafone)
S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
==================== Drivers (Whitelisted) ====================
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-06-10] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-10-07] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [147480 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [33656 2011-08-04] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2011-08-04] (ESET)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1083880 2009-04-11] (Společnost Microsoft)
R3 SMARTMouseFilterx86; C:\Windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2008-07-30] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\Windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2008-07-30] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\Windows\System32\DRIVERS\SMARTVTabletPCx86.sys [16808 2008-07-30] (SMART Technologies ULC)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1753984 2009-03-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-07-08] ()
R3 SRS_PremiumSound_Service; C:\Windows\System32\drivers\srs_PremiumSound_i386.sys [230952 2009-01-14] ()
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-17 22:12 - 2014-02-17 22:13 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:12 - 00000000 ____D () C:\FRST
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-09 13:10 - 2014-02-17 21:59 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-08 19:49 - 2014-02-09 13:39 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-08 19:49 - 2014-02-09 13:37 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:49 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:21 - 2014-02-16 17:37 - 00000000 ____D () C:\AdwCleaner
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-02 16:24 - 2014-02-02 16:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-01-19 18:32 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:30 - 2014-01-19 18:36 - 00000000 ____D () C:\ProgramData\InstallMate
==================== One Month Modified Files and Folders =======
2014-02-17 22:13 - 2014-02-17 22:12 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:12 - 2014-02-17 22:08 - 00000000 ____D () C:\FRST
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:11 - 2014-02-17 22:09 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 22:06 - 2006-11-02 10:33 - 01393902 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 22:01 - 2009-06-25 20:54 - 00031871 _____ () C:\ProgramData\nvModes.001
2014-02-17 22:01 - 2009-06-10 04:39 - 00000000 ___HD () C:\ASUS.DAT
2014-02-17 22:00 - 2014-02-15 18:07 - 00008594 _____ () C:\zoek-results.log
2014-02-17 21:59 - 2014-02-09 13:10 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-17 21:59 - 2013-02-19 10:13 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-17 21:59 - 2013-01-04 01:11 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-02-17 21:59 - 2009-06-25 20:53 - 00031871 _____ () C:\ProgramData\nvModes.dat
2014-02-17 21:59 - 2006-11-02 13:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:58 - 2006-11-02 13:01 - 00032566 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-17 21:57 - 2009-06-10 04:09 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-02-17 21:57 - 2009-06-10 03:37 - 01980783 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 21:52 - 2009-07-31 14:13 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Skype
2014-02-17 21:45 - 2013-02-19 10:13 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-17 21:17 - 2013-03-31 19:13 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-17 21:16 - 2014-02-17 21:56 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-16 17:37 - 2014-02-08 17:21 - 00000000 ____D () C:\AdwCleaner
2014-02-16 14:44 - 2013-01-03 21:21 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-02-16 12:24 - 2014-02-17 21:33 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 03:18 - 2014-02-16 12:07 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-16 00:01 - 2014-02-09 22:09 - 00000000 ____D () C:\zoek_backup
2014-02-15 18:01 - 2014-02-15 18:00 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:13 - 2014-02-09 22:52 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-02-09 15:23 - 2012-09-30 14:01 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter
2014-02-09 13:39 - 2014-02-08 19:49 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-09 13:37 - 2014-02-08 19:49 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 18:40 - 2009-08-15 18:43 - 00000000 ____D () C:\Windows\Minidump
2014-02-08 18:40 - 2009-07-04 20:55 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\uTorrent
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:36 - 2012-12-09 12:48 - 00000000 ____D () C:\Program Files\trend micro
2014-02-08 17:20 - 2014-02-08 17:09 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 21:17 - 2012-04-03 18:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-06 21:17 - 2011-09-14 19:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-06 21:06 - 2009-07-16 16:49 - 00001978 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-06 20:58 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-02-06 20:58 - 2009-09-15 19:17 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-02-06 20:30 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-02-06 20:29 - 2009-06-25 17:16 - 00000000 ____D () C:\Users\Ondra
2014-02-06 20:29 - 2006-11-02 10:22 - 51642368 _____ () C:\Windows\system32\config\software_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 45875200 _____ () C:\Windows\system32\config\system_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 44302336 _____ () C:\Windows\system32\config\components_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\default_previous
2014-02-06 20:28 - 2009-06-10 04:41 - 00000000 ____D () C:\ProgramData\P4G
2014-02-06 20:28 - 2009-06-10 04:18 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-02-06 20:28 - 2009-06-10 03:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-06 20:28 - 2006-11-02 12:37 - 00000000 ____D () C:\Windows\ShellNew
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 __RSD () C:\Windows\Media
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\spool
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\rescache
2014-02-06 20:27 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\registration
2014-02-03 20:50 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-02 16:39 - 2009-06-10 03:49 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-02-02 16:27 - 2014-02-02 16:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 21:08 - 2009-06-25 17:55 - 00009728 _____ () C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-19 18:36 - 2014-01-19 18:30 - 00000000 ____D () C:\ProgramData\InstallMate
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:32 - 2009-06-25 17:34 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Google
Files to move or delete:
====================
C:\Users\Ondra\AppData\Roaming\desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-17 22:05
==================== End Of Log ============================
Majkl55
Re: Pomalý notebook - Podezření na vir

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [] - [X] HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd) HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.) HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.) HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found GroupPolicy: Group Policy on Chrome detected <======= ATTENTION SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms} SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333 SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333 S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] 2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat 2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE 2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe 2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat 2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log 2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log 2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log 2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe 2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log 2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup 2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe 2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl C:\Users\Ondra\AppData\Roaming\desktop.ini c:\progra~1\GSSvc.dll C:\Users\Ondra\AppData\Roaming\Search Protection Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: Pomalý notebook - Podezření na vir
tady to je...
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-02-2014 01
Ran by Ondra at 2014-02-23 14:52:02 Run:1
Running from C:\Users\Ondra\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
C:\Users\Ondra\AppData\Roaming\desktop.ini
c:\progra~1\GSSvc.dll
C:\Users\Ondra\AppData\Roaming\Search Protection
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ehTray.exe => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SRS Premium Sound => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtection => Value deleted successfully.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3134179490-1787442154-2696964708-1000 => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKCR\CLSID\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKCR\CLSID\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKCR\CLSID\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKCR\CLSID\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKCR\CLSID\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
"c:\\progra~1\\gse7cc~1.ena" => Value Data removed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
916e5338 => Service deleted successfully.
a3qff9o1 => Service not found.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
"C:\Users\Ondra\AppData\Local\LM.bat" => File/Directory not found.
"C:\Users\Ondra\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\Ondra\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\Ondra\Desktop\LM.bat => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results2014-02-16-122447.log => Moved successfully.
C:\zoek-results2014-02-16-031835.log => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Ondra\Desktop\zoek.exe => Moved successfully.
C:\zoek-results2014-02-09-221302.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe => Moved successfully.
C:\Users\Ondra\Desktop\adwcleaner.exe => Moved successfully.
C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl => Moved successfully.
C:\Users\Ondra\AppData\Roaming\desktop.ini => Moved successfully.
"c:\progra~1\GSSvc.dll" => File/Directory not found.
"C:\Users\Ondra\AppData\Roaming\Search Protection" => File/Directory not found.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
The system needs a manual reboot.
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-02-2014 01
Ran by Ondra at 2014-02-23 14:52:02 Run:1
Running from C:\Users\Ondra\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
C:\Users\Ondra\AppData\Roaming\desktop.ini
c:\progra~1\GSSvc.dll
C:\Users\Ondra\AppData\Roaming\Search Protection
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ehTray.exe => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SRS Premium Sound => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtection => Value deleted successfully.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3134179490-1787442154-2696964708-1000 => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKCR\CLSID\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKCR\CLSID\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKCR\CLSID\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKCR\CLSID\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKCR\CLSID\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
"c:\\progra~1\\gse7cc~1.ena" => Value Data removed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
916e5338 => Service deleted successfully.
a3qff9o1 => Service not found.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
"C:\Users\Ondra\AppData\Local\LM.bat" => File/Directory not found.
"C:\Users\Ondra\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\Ondra\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\Ondra\Desktop\LM.bat => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results2014-02-16-122447.log => Moved successfully.
C:\zoek-results2014-02-16-031835.log => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Ondra\Desktop\zoek.exe => Moved successfully.
C:\zoek-results2014-02-09-221302.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe => Moved successfully.
C:\Users\Ondra\Desktop\adwcleaner.exe => Moved successfully.
C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl => Moved successfully.
C:\Users\Ondra\AppData\Roaming\desktop.ini => Moved successfully.
"c:\progra~1\GSSvc.dll" => File/Directory not found.
"C:\Users\Ondra\AppData\Roaming\Search Protection" => File/Directory not found.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
The system needs a manual reboot.
==== End of Fixlog ====
Majkl55
Re: Pomalý notebook - Podezření na vir
Notebook se nerestartoval. Fixlist.txt jsem vytvoril. Co mate na mysli: "presunte vytvoreny fixlist vedle FRST"? Oba mam na plose vedle sebe. Mam fixlist presunout do adresare FRST?
Majkl55
Re: Pomalý notebook - Podezření na vir
Provedl jste to dobre
Jak se chova PC??

Jak se chova PC??
Re: Pomalý notebook - Podezření na vir
PC je lepší než minulý týden, ale stále pomalé. Hlavně Explorer jde dost pomalu.
Majkl55
Re: Pomalý notebook - Podezření na vir

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

- Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
- Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
- prepnete se do zalozky Nastroje
- Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
- Toto provedte se vsemi disky
- Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
- Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
- Kliknete na Analyzovat
- Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
- Postup provedte se vsemi disky
- Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
- Vyhodou programku je, ze se neinstaluje
- Staci tedy jen stahnout dle verze vaseho OS a rozbalit
- Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
- Probehne analyza disku a nasledne i defragmentace
