Tak povedlo se.
Zde log z FRST
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by lubos (administrator) on LUBOS-PC on 14-04-2014 22:01:53
Running from C:\Users\lubos\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Essentials\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\system32\DeviceDisplayObjectProvider.exe
(U3 LLC) C:\Users\lubos\AppData\Roaming\U3\453082163811618C\LaunchPad.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSSE] => c:\Program Files\Microsoft Security Essentials\msseces.exe [1448568 2010-09-15] (Microsoft Corporation)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-21-4189299555-548978827-3029997808-1000\...\MountPoints2: {f4eae9b3-c404-11e3-9d7e-002454ea2d01} - F:\LaunchU3.exe -a
Startup: C:\Users\lubos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\gafah1.lnk
ShortcutTarget: gafah1.lnk -> C:\ProgramData\2992199F9A\1hafag.cpp (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
==================== Services (Whitelisted) =================
R2 MsMpSvc; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [17424 2010-03-25] (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\2992199F9A\gafah1.faa [332036 2014-04-06] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [173984 2010-03-25] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-14 22:01 - 2014-04-14 22:02 - 00004711 _____ () C:\Users\lubos\Desktop\FRST.txt
2014-04-14 22:00 - 2014-04-14 20:58 - 00112640 _____ (forum.viry.cz) C:\Users\lubos\Desktop\FRSTLauncher.exe
2014-04-14 22:00 - 2014-04-14 20:57 - 02054144 _____ (Farbar) C:\Users\lubos\Desktop\FRST64.exe
2014-04-14 21:59 - 2014-04-14 22:01 - 00000000 ____D () C:\FRST
2014-04-14 21:59 - 2014-04-14 21:59 - 00000000 ____D () C:\Users\lubos\AppData\Roaming\U3
2014-04-06 06:18 - 2014-04-14 21:46 - 00000000 ____D () C:\ProgramData\2992199F9A
2014-03-23 11:50 - 2014-03-23 11:50 - 00000000 ____D () C:\Users\lubos\Desktop\Nová složka
2014-03-23 11:41 - 2014-03-23 11:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
==================== One Month Modified Files and Folders =======
2014-04-14 22:02 - 2014-04-14 22:01 - 00004711 _____ () C:\Users\lubos\Desktop\FRST.txt
2014-04-14 22:01 - 2014-04-14 21:59 - 00000000 ____D () C:\FRST
2014-04-14 22:01 - 2013-10-07 12:21 - 01418650 _____ () C:\Windows\WindowsUpdate.log
2014-04-14 21:59 - 2014-04-14 21:59 - 00000000 ____D () C:\Users\lubos\AppData\Roaming\U3
2014-04-14 21:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-14 21:46 - 2014-04-06 06:18 - 00000000 ____D () C:\ProgramData\2992199F9A
2014-04-14 21:21 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-14 21:21 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-14 21:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-14 21:14 - 2009-07-14 06:51 - 00041008 _____ () C:\Windows\setupact.log
2014-04-14 20:58 - 2014-04-14 22:00 - 00112640 _____ (forum.viry.cz) C:\Users\lubos\Desktop\FRSTLauncher.exe
2014-04-14 20:57 - 2014-04-14 22:00 - 02054144 _____ (Farbar) C:\Users\lubos\Desktop\FRST64.exe
2014-04-06 06:18 - 2013-10-07 12:29 - 00000000 ___RD () C:\Users\lubos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-05 10:33 - 2011-04-12 10:34 - 00622660 _____ () C:\Windows\system32\perfh005.dat
2014-04-05 10:33 - 2011-04-12 10:34 - 00118810 _____ () C:\Windows\system32\perfc005.dat
2014-04-05 10:33 - 2009-07-14 07:13 - 01445734 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-23 11:50 - 2014-03-23 11:50 - 00000000 ____D () C:\Users\lubos\Desktop\Nová složka
2014-03-23 11:41 - 2014-03-23 11:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-03-23 00:36 - 2009-07-14 07:08 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-19 07:06 - 2013-10-07 15:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 07:05 - 2013-10-07 15:06 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\lubos\AppData\Local\Temp\ExPromo.exe
C:\Users\lubos\AppData\Local\Temp\mUN5.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-04 08:02
==================== End Of Log ============================