Porsím vyoska o revizi
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Porsím vyoska o revizi
Ahoj. Prosím o kontrolu dost zabržděného počítače.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Táta (administrator) on TÁTA-PC on 27-05-2014 07:31:36
Running from E:\Users\Táta\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) E:\Windows\System32\atiesrxx.exe
(AMD) E:\Windows\System32\atieclxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastUI.exe
(forum.viry.cz) E:\Users\Táta\Desktop\FRST-OlderVersion\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [avast] => E:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: E:\Users\Táta\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - E:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - E:\Users\Táta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=12454
CHR StartupUrls: "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - E:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U32) - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Unity Player) - E:\Users\T\u00E1ta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Plugin: (Shockwave Flash) - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.320.5) - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Extension: (Seznam Lištička - Email) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-02-19]
CHR Extension: (Seznam Lištička - Slovník) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-02-19]
CHR Extension: (Chrome In-App Payments service) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Seznam Lištička - Rychlá volba) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-02-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 MBAMScheduler; E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; E:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; E:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; E:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; E:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; E:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; E:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; E:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; E:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 MBAMProtector; E:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; E:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
R0 sptd; E:\Windows\System32\Drivers\sptd.sys [564824 2013-10-20] (Duplex Secure Ltd.)
U3 agk9gb7h; E:\Windows\System32\Drivers\agk9gb7h.sys [0 ] (Advanced Micro Devices)
S3 EverestDriver; \??\E:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-27 07:31 - 2014-05-27 07:31 - 00010495 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-05-27 07:31 - 2014-05-27 07:31 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-05-15 05:03 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-15 05:03 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-15 05:03 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-15 05:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
2014-05-15 04:58 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) E:\Windows\system32\shell32.dll
2014-05-15 04:58 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) E:\Windows\SysWOW64\shell32.dll
2014-05-15 04:57 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-15 04:57 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-15 04:57 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 04:57 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 04:57 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) E:\Windows\system32\lsasrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) E:\Windows\system32\sspicli.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) E:\Windows\system32\lsass.exe
2014-05-15 04:57 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) E:\Windows\system32\sspisrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) E:\Windows\system32\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) E:\Windows\SysWOW64\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) E:\Windows\SysWOW64\sspicli.dll
2014-05-15 04:57 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) E:\Windows\system32\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) E:\Windows\system32\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) E:\Windows\system32\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) E:\Windows\system32\KernelBase.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) E:\Windows\system32\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) E:\Windows\system32\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) E:\Windows\system32\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) E:\Windows\system32\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) E:\Windows\system32\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) E:\Windows\system32\winlogon.exe
2014-05-15 04:57 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) E:\Windows\system32\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) E:\Windows\system32\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) E:\Windows\system32\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) E:\Windows\system32\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) E:\Windows\system32\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) E:\Windows\system32\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 04:57 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) E:\Windows\SysWOW64\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) E:\Windows\SysWOW64\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) E:\Windows\SysWOW64\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) E:\Windows\SysWOW64\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) E:\Windows\SysWOW64\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) E:\Windows\SysWOW64\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) E:\Windows\SysWOW64\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) E:\Windows\SysWOW64\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) E:\Windows\SysWOW64\KernelBase.dll
2014-05-10 09:30 - 2014-05-10 09:31 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-08 08:03 - 2014-05-15 16:35 - 00000000 ___SD () E:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-05-27 07:31 - 2014-05-27 07:31 - 00010495 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-05-27 07:31 - 2014-05-27 07:31 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-05-27 07:31 - 2014-01-02 11:13 - 00000000 ____D () E:\FRST
2014-05-27 07:31 - 2014-01-02 11:11 - 02066944 _____ (Farbar) E:\Users\Táta\Desktop\FRST64.exe
2014-05-27 07:31 - 2012-08-23 09:30 - 01839056 _____ () E:\Windows\WindowsUpdate.log
2014-05-27 07:28 - 2012-07-03 20:00 - 00004182 _____ () E:\Windows\System32\Tasks\avast! Emergency Update
2014-05-27 07:26 - 2014-02-21 18:30 - 00000948 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-27 07:26 - 2009-07-14 07:08 - 00000006 ____H () E:\Windows\Tasks\SA.DAT
2014-05-27 07:25 - 2012-08-23 11:50 - 00079130 _____ () E:\Windows\setupact.log
2014-05-26 18:41 - 2014-01-01 17:00 - 00000000 ____D () E:\AdwCleaner
2014-05-26 18:33 - 2014-02-21 19:22 - 00000914 _____ () E:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-26 18:33 - 2009-07-14 07:08 - 00032518 _____ () E:\Windows\Tasks\SCHEDLGU.TXT
2014-05-26 18:21 - 2014-02-21 18:30 - 00000952 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-25 07:27 - 2011-01-01 21:14 - 00000000 ____D () E:\Users\Táta\Desktop\Tata
2014-05-25 06:32 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-25 06:32 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-23 14:13 - 2012-12-22 10:55 - 00002194 _____ () E:\Users\Public\Desktop\Google Chrome.lnk
2014-05-20 07:05 - 2009-07-14 17:18 - 00669132 _____ () E:\Windows\system32\perfh005.dat
2014-05-20 07:05 - 2009-07-14 17:18 - 00141760 _____ () E:\Windows\system32\perfc005.dat
2014-05-20 07:05 - 2009-07-14 07:13 - 01584626 _____ () E:\Windows\system32\PerfStringBackup.INI
2014-05-16 19:48 - 2012-05-07 09:39 - 00692400 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-16 19:48 - 2012-05-07 09:39 - 00070832 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-16 19:48 - 2012-05-07 09:39 - 00003852 _____ () E:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-16 17:33 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\rescache
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 16:35 - 2014-05-08 08:03 - 00000000 ___SD () E:\Windows\system32\CompatTel
2014-05-15 16:35 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\PolicyDefinitions
2014-05-11 19:52 - 2012-05-07 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 09:31 - 2014-05-10 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-09 08:14 - 2014-05-15 04:57 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 04:57 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-08 08:07 - 2012-12-22 10:53 - 00003948 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 08:07 - 2012-12-22 10:53 - 00003696 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 06:40 - 2014-05-15 05:03 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 05:03 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 05:03 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 05:03 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
E:\Users\Táta\AppData\Local\Temp\Quarantine.exe
E:\Users\Táta\AppData\Local\Temp\~38CB.exe
E:\Users\Táta\AppData\Local\Temp\~6133.exe
==================== Bamital & volsnap Check =================
E:\Windows\System32\winlogon.exe => MD5 is legit
E:\Windows\System32\wininit.exe => MD5 is legit
E:\Windows\SysWOW64\wininit.exe => MD5 is legit
E:\Windows\explorer.exe => MD5 is legit
E:\Windows\SysWOW64\explorer.exe => MD5 is legit
E:\Windows\System32\svchost.exe => MD5 is legit
E:\Windows\SysWOW64\svchost.exe => MD5 is legit
E:\Windows\System32\services.exe => MD5 is legit
E:\Windows\System32\User32.dll => MD5 is legit
E:\Windows\SysWOW64\User32.dll => MD5 is legit
E:\Windows\System32\userinit.exe => MD5 is legit
E:\Windows\SysWOW64\userinit.exe => MD5 is legit
E:\Windows\System32\rpcss.dll => MD5 is legit
E:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "E:\Users\T�ta\Desktop" je 9845 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS
E:\Windows\AutoKMS.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"E:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"E:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Táta (administrator) on TÁTA-PC on 27-05-2014 07:31:36
Running from E:\Users\Táta\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) E:\Windows\System32\atiesrxx.exe
(AMD) E:\Windows\System32\atieclxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastUI.exe
(forum.viry.cz) E:\Users\Táta\Desktop\FRST-OlderVersion\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [avast] => E:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: E:\Users\Táta\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - E:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - E:\Users\Táta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=12454
CHR StartupUrls: "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - E:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - E:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U32) - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Unity Player) - E:\Users\T\u00E1ta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Plugin: (Shockwave Flash) - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.320.5) - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Extension: (Seznam Lištička - Email) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-02-19]
CHR Extension: (Seznam Lištička - Slovník) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-02-19]
CHR Extension: (Chrome In-App Payments service) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Seznam Lištička - Rychlá volba) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-02-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 MBAMScheduler; E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; E:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; E:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; E:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; E:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; E:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; E:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; E:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; E:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 MBAMProtector; E:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; E:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
R0 sptd; E:\Windows\System32\Drivers\sptd.sys [564824 2013-10-20] (Duplex Secure Ltd.)
U3 agk9gb7h; E:\Windows\System32\Drivers\agk9gb7h.sys [0 ] (Advanced Micro Devices)
S3 EverestDriver; \??\E:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-27 07:31 - 2014-05-27 07:31 - 00010495 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-05-27 07:31 - 2014-05-27 07:31 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-05-15 05:03 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-15 05:03 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-15 05:03 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-15 05:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
2014-05-15 04:58 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) E:\Windows\system32\shell32.dll
2014-05-15 04:58 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) E:\Windows\SysWOW64\shell32.dll
2014-05-15 04:57 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-15 04:57 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-15 04:57 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 04:57 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 04:57 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) E:\Windows\system32\lsasrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) E:\Windows\system32\sspicli.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) E:\Windows\system32\lsass.exe
2014-05-15 04:57 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) E:\Windows\system32\sspisrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) E:\Windows\system32\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) E:\Windows\SysWOW64\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) E:\Windows\SysWOW64\sspicli.dll
2014-05-15 04:57 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) E:\Windows\system32\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) E:\Windows\system32\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) E:\Windows\system32\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) E:\Windows\system32\KernelBase.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) E:\Windows\system32\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) E:\Windows\system32\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) E:\Windows\system32\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) E:\Windows\system32\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) E:\Windows\system32\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) E:\Windows\system32\winlogon.exe
2014-05-15 04:57 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) E:\Windows\system32\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) E:\Windows\system32\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) E:\Windows\system32\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) E:\Windows\system32\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) E:\Windows\system32\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) E:\Windows\system32\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 04:57 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) E:\Windows\SysWOW64\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) E:\Windows\SysWOW64\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) E:\Windows\SysWOW64\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) E:\Windows\SysWOW64\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) E:\Windows\SysWOW64\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) E:\Windows\SysWOW64\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) E:\Windows\SysWOW64\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) E:\Windows\SysWOW64\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) E:\Windows\SysWOW64\KernelBase.dll
2014-05-10 09:30 - 2014-05-10 09:31 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-08 08:03 - 2014-05-15 16:35 - 00000000 ___SD () E:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-05-27 07:31 - 2014-05-27 07:31 - 00010495 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-05-27 07:31 - 2014-05-27 07:31 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-05-27 07:31 - 2014-01-02 11:13 - 00000000 ____D () E:\FRST
2014-05-27 07:31 - 2014-01-02 11:11 - 02066944 _____ (Farbar) E:\Users\Táta\Desktop\FRST64.exe
2014-05-27 07:31 - 2012-08-23 09:30 - 01839056 _____ () E:\Windows\WindowsUpdate.log
2014-05-27 07:28 - 2012-07-03 20:00 - 00004182 _____ () E:\Windows\System32\Tasks\avast! Emergency Update
2014-05-27 07:26 - 2014-02-21 18:30 - 00000948 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-27 07:26 - 2009-07-14 07:08 - 00000006 ____H () E:\Windows\Tasks\SA.DAT
2014-05-27 07:25 - 2012-08-23 11:50 - 00079130 _____ () E:\Windows\setupact.log
2014-05-26 18:41 - 2014-01-01 17:00 - 00000000 ____D () E:\AdwCleaner
2014-05-26 18:33 - 2014-02-21 19:22 - 00000914 _____ () E:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-26 18:33 - 2009-07-14 07:08 - 00032518 _____ () E:\Windows\Tasks\SCHEDLGU.TXT
2014-05-26 18:21 - 2014-02-21 18:30 - 00000952 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-25 07:27 - 2011-01-01 21:14 - 00000000 ____D () E:\Users\Táta\Desktop\Tata
2014-05-25 06:32 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-25 06:32 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-23 14:13 - 2012-12-22 10:55 - 00002194 _____ () E:\Users\Public\Desktop\Google Chrome.lnk
2014-05-20 07:05 - 2009-07-14 17:18 - 00669132 _____ () E:\Windows\system32\perfh005.dat
2014-05-20 07:05 - 2009-07-14 17:18 - 00141760 _____ () E:\Windows\system32\perfc005.dat
2014-05-20 07:05 - 2009-07-14 07:13 - 01584626 _____ () E:\Windows\system32\PerfStringBackup.INI
2014-05-16 19:48 - 2012-05-07 09:39 - 00692400 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-16 19:48 - 2012-05-07 09:39 - 00070832 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-16 19:48 - 2012-05-07 09:39 - 00003852 _____ () E:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-16 17:33 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\rescache
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 16:35 - 2014-05-08 08:03 - 00000000 ___SD () E:\Windows\system32\CompatTel
2014-05-15 16:35 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\PolicyDefinitions
2014-05-11 19:52 - 2012-05-07 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 09:31 - 2014-05-10 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-09 08:14 - 2014-05-15 04:57 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 04:57 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-08 08:07 - 2012-12-22 10:53 - 00003948 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 08:07 - 2012-12-22 10:53 - 00003696 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 06:40 - 2014-05-15 05:03 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 05:03 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 05:03 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 05:03 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
E:\Users\Táta\AppData\Local\Temp\Quarantine.exe
E:\Users\Táta\AppData\Local\Temp\~38CB.exe
E:\Users\Táta\AppData\Local\Temp\~6133.exe
==================== Bamital & volsnap Check =================
E:\Windows\System32\winlogon.exe => MD5 is legit
E:\Windows\System32\wininit.exe => MD5 is legit
E:\Windows\SysWOW64\wininit.exe => MD5 is legit
E:\Windows\explorer.exe => MD5 is legit
E:\Windows\SysWOW64\explorer.exe => MD5 is legit
E:\Windows\System32\svchost.exe => MD5 is legit
E:\Windows\SysWOW64\svchost.exe => MD5 is legit
E:\Windows\System32\services.exe => MD5 is legit
E:\Windows\System32\User32.dll => MD5 is legit
E:\Windows\SysWOW64\User32.dll => MD5 is legit
E:\Windows\System32\userinit.exe => MD5 is legit
E:\Windows\SysWOW64\userinit.exe => MD5 is legit
E:\Windows\System32\rpcss.dll => MD5 is legit
E:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "E:\Users\T�ta\Desktop" je 9845 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS
E:\Windows\AutoKMS.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"E:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"E:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: Porsím vyoska o revizi
Zdravicko
Navody mam ve vykani a kvuli tobe je prepisovat nebudu
Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Porsím vyoska o revizi
To je jasný, že nic přepisovat nemusíš 
Tady je zmiňovaný log z programu Zoek
Zoek.exe v5.0.0.0 Updated 22-05-2014
Tool run by T ta on Łt 27.05.2014 at 9:12:44,60.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: E:\Users\TTA~1\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
27.5.2014 9:13:48 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
Added to E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default\prefs.js:
Added to E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_27.05.2014_0928_.backup
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_27.05.2014_0928_.backup
==== Deleting Files \ Folders ======================
E:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="E:\Program Files\AVAST Software\Avast\WebRep\FF" [14.09.2013 08:15]
==== Firefox Extensions ======================
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
- avast Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
AppDir: E:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Chrome Look ======================
Seznam Li\u0161ti\u010Dka - Email - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
==== Reset Google Chrome ======================
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS deleted successfully
==== Empty IE Cache ======================
E:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
E:\Users\TTA~1\AppData\Local\Mozilla\Firefox\Profiles\9b22ti9i.default\Cache emptied successfully
==== Empty Chrome Cache ======================
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== E:\zoek_backup content ======================
E:\zoek_backup (files=4 folders=0 46943 bytes)
==== Empty Temp Folders ======================
E:\Users\Default\AppData\Local\Temp emptied successfully
E:\Users\Default User\AppData\Local\Temp emptied successfully
E:\Users\TTA~1\AppData\Local\Temp will be emptied at reboot
E:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
E:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
E:\Windows\Temp successfully emptied
E:\Users\TTA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
E:\$RECYCLE.BIN successfully emptied
==== EOF on Łt 27.05.2014 at 9:34:57,12 ======================
Tady je zmiňovaný log z programu Zoek
Zoek.exe v5.0.0.0 Updated 22-05-2014
Tool run by T ta on Łt 27.05.2014 at 9:12:44,60.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: E:\Users\TTA~1\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
27.5.2014 9:13:48 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
Added to E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default\prefs.js:
Added to E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_27.05.2014_0928_.backup
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_27.05.2014_0928_.backup
==== Deleting Files \ Folders ======================
E:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="E:\Program Files\AVAST Software\Avast\WebRep\FF" [14.09.2013 08:15]
==== Firefox Extensions ======================
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
- avast Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF
ProfilePath: E:\Users\TTA~1\AppData\Roaming\Thunderbird\Profiles\3jca0mu5.default
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
AppDir: E:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Chrome Look ======================
Seznam Li\u0161ti\u010Dka - Email - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba - TTA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
==== Reset Google Chrome ======================
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS deleted successfully
==== Empty IE Cache ======================
E:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
E:\Users\TTA~1\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
E:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
E:\Users\TTA~1\AppData\Local\Mozilla\Firefox\Profiles\9b22ti9i.default\Cache emptied successfully
==== Empty Chrome Cache ======================
E:\Users\TTA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== E:\zoek_backup content ======================
E:\zoek_backup (files=4 folders=0 46943 bytes)
==== Empty Temp Folders ======================
E:\Users\Default\AppData\Local\Temp emptied successfully
E:\Users\Default User\AppData\Local\Temp emptied successfully
E:\Users\TTA~1\AppData\Local\Temp will be emptied at reboot
E:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
E:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
E:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
E:\Windows\Temp successfully emptied
E:\Users\TTA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
E:\$RECYCLE.BIN successfully emptied
==== EOF on Łt 27.05.2014 at 9:34:57,12 ======================
Naposledy upravil(a) Stene dne 27 Kvě 2014 08:38, celkem upraveno 1 x.
Re: Porsím vyoska o revizi
Tímto bych se chtěl nenápadně připomenout.. 
Re: Porsím vyoska o revizi
- Ulozte nejlepe na Plochu a rozbalte
- Spustte kliknutim na mbar
- Nyni postupne kliknete na Next a Update
- Po dokonceni update (aktualizace) databaze kliknete opet na Next
- Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
- Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
- Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
- Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
- PC bude restartovan
- Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
Re: Porsím vyoska o revizi
Tušil jsem, že jsem udělal zmatek tím editováním..
mbar mi nic nenašel a log mi to nevyhodilo
mbar mi nic nenašel a log mi to nevyhodilo
Re: Porsím vyoska o revizi
Poprosim o novy log z FRST
Re: Porsím vyoska o revizi
Tady je nový log z FRST 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Táta (administrator) on TÁTA-PC on 04-06-2014 16:27:44
Running from E:\Users\Táta\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) E:\Windows\System32\atiesrxx.exe
(AMD) E:\Windows\System32\atieclxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastUI.exe
(forum.viry.cz) E:\Users\Táta\Desktop\FRST-OlderVersion\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [avast] => E:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\...\MountPoints2: {fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba} - H:\LGAutoRun.exe
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: E:\Users\Táta\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: seznam.cz
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - E:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - E:\Users\Táta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Seznam Lištička - Email) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-02-19]
CHR Extension: (Seznam Lištička - Slovník) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-02-19]
CHR Extension: (Chrome In-App Payments service) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Seznam Lištička - Rychlá volba) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-02-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; E:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; E:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; E:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; E:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; E:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; E:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; E:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; E:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 MTsensor; E:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
R0 sptd; E:\Windows\System32\Drivers\sptd.sys [564824 2013-10-20] (Duplex Secure Ltd.)
U3 aokb5osh; E:\Windows\System32\Drivers\aokb5osh.sys [0 ] (Microsoft Corporation)
S3 EverestDriver; \??\E:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-04 16:27 - 2014-06-04 16:28 - 00009036 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-06-04 16:27 - 2014-06-04 16:27 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-06-03 15:43 - 2014-06-03 16:05 - 00000000 ____D () E:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-03 15:43 - 2014-06-03 15:43 - 00119000 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 15:42 - 2014-06-03 16:05 - 00000000 ____D () E:\Users\Táta\Desktop\mbar
2014-06-03 15:42 - 2014-06-03 15:42 - 00091352 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-03 15:41 - 2014-06-03 15:42 - 12589848 _____ (Malwarebytes Corp.) E:\Users\Táta\Downloads\mbar-1.07.0.1009.exe
2014-06-03 15:22 - 2014-06-03 15:29 - 00000000 ____D () E:\Users\Táta\Desktop\video
2014-06-01 12:22 - 2014-06-01 12:22 - 00003584 _____ () E:\Users\Táta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-01 12:10 - 2014-06-01 12:41 - 00000000 ____D () E:\Users\Táta\AppData\Local\WMTools Downloaded Files
2014-06-01 12:09 - 2014-06-01 12:09 - 00002507 _____ () E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
2014-06-01 12:09 - 2014-06-01 12:09 - 00000000 ____D () E:\Program Files (x86)\Movie Maker 2.6
2014-06-01 12:00 - 2014-06-01 12:00 - 07363072 _____ () E:\Users\Táta\Downloads\MM26_CS.msi
2014-05-27 09:33 - 2014-06-04 16:28 - 00000000 ____D () E:\Users\Táta\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default User\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:12 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 09:13 - 2014-05-27 09:34 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:12 - 2014-05-27 09:28 - 00000000 ____D () E:\zoek_backup
2014-05-27 07:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) E:\Windows\SysWOW64\sqlite3.dll
2014-05-15 05:03 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-15 05:03 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-15 05:03 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-15 05:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
2014-05-15 04:58 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) E:\Windows\system32\shell32.dll
2014-05-15 04:58 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) E:\Windows\SysWOW64\shell32.dll
2014-05-15 04:57 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-15 04:57 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-15 04:57 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 04:57 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 04:57 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) E:\Windows\system32\lsasrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) E:\Windows\system32\sspicli.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) E:\Windows\system32\lsass.exe
2014-05-15 04:57 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) E:\Windows\system32\sspisrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) E:\Windows\system32\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) E:\Windows\SysWOW64\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) E:\Windows\SysWOW64\sspicli.dll
2014-05-15 04:57 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) E:\Windows\system32\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) E:\Windows\system32\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) E:\Windows\system32\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) E:\Windows\system32\KernelBase.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) E:\Windows\system32\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) E:\Windows\system32\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) E:\Windows\system32\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) E:\Windows\system32\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) E:\Windows\system32\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) E:\Windows\system32\winlogon.exe
2014-05-15 04:57 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) E:\Windows\system32\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) E:\Windows\system32\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) E:\Windows\system32\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) E:\Windows\system32\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) E:\Windows\system32\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) E:\Windows\system32\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 04:57 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) E:\Windows\SysWOW64\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) E:\Windows\SysWOW64\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) E:\Windows\SysWOW64\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) E:\Windows\SysWOW64\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) E:\Windows\SysWOW64\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) E:\Windows\SysWOW64\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) E:\Windows\SysWOW64\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) E:\Windows\SysWOW64\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) E:\Windows\SysWOW64\KernelBase.dll
2014-05-10 09:30 - 2014-05-10 09:31 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-08 08:03 - 2014-05-15 16:35 - 00000000 ___SD () E:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-06-04 16:28 - 2014-06-04 16:27 - 00009036 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-06-04 16:28 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Táta\AppData\Local\Temp
2014-06-04 16:27 - 2014-06-04 16:27 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-06-04 16:27 - 2014-01-02 11:13 - 00000000 ____D () E:\FRST
2014-06-04 16:27 - 2014-01-02 11:11 - 02068992 _____ (Farbar) E:\Users\Táta\Desktop\FRST64.exe
2014-06-04 16:22 - 2014-02-21 19:22 - 00000914 _____ () E:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-04 16:18 - 2012-08-23 09:30 - 01133296 _____ () E:\Windows\WindowsUpdate.log
2014-06-04 16:17 - 2014-02-21 18:30 - 00000952 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 14:59 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-04 14:59 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-04 14:52 - 2014-02-21 18:30 - 00000948 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-04 14:51 - 2012-08-23 11:50 - 00083462 _____ () E:\Windows\setupact.log
2014-06-04 14:51 - 2009-07-14 07:08 - 00000006 ____H () E:\Windows\Tasks\SA.DAT
2014-06-03 16:05 - 2014-06-03 15:43 - 00000000 ____D () E:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-03 16:05 - 2014-06-03 15:42 - 00000000 ____D () E:\Users\Táta\Desktop\mbar
2014-06-03 15:43 - 2014-06-03 15:43 - 00119000 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 15:42 - 2014-06-03 15:42 - 00091352 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-03 15:42 - 2014-06-03 15:41 - 12589848 _____ (Malwarebytes Corp.) E:\Users\Táta\Downloads\mbar-1.07.0.1009.exe
2014-06-03 15:29 - 2014-06-03 15:22 - 00000000 ____D () E:\Users\Táta\Desktop\video
2014-06-03 15:17 - 2012-07-03 20:00 - 00004182 _____ () E:\Windows\System32\Tasks\avast! Emergency Update
2014-06-01 21:07 - 2009-07-14 07:09 - 00000000 ____D () E:\Windows\System32\Tasks\WPD
2014-06-01 12:41 - 2014-06-01 12:10 - 00000000 ____D () E:\Users\Táta\AppData\Local\WMTools Downloaded Files
2014-06-01 12:35 - 2013-10-28 16:04 - 00000000 ____D () E:\Users\Táta\AppData\Roaming\vlc
2014-06-01 12:22 - 2014-06-01 12:22 - 00003584 _____ () E:\Users\Táta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-01 12:09 - 2014-06-01 12:09 - 00002507 _____ () E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
2014-06-01 12:09 - 2014-06-01 12:09 - 00000000 ____D () E:\Program Files (x86)\Movie Maker 2.6
2014-06-01 12:00 - 2014-06-01 12:00 - 07363072 _____ () E:\Users\Táta\Downloads\MM26_CS.msi
2014-05-31 14:41 - 2009-07-14 17:18 - 00669132 _____ () E:\Windows\system32\perfh005.dat
2014-05-31 14:41 - 2009-07-14 17:18 - 00141760 _____ () E:\Windows\system32\perfc005.dat
2014-05-31 14:41 - 2009-07-14 07:13 - 01584626 _____ () E:\Windows\system32\PerfStringBackup.INI
2014-05-27 09:34 - 2014-05-27 09:13 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default User\AppData\Local\Temp
2014-05-27 09:33 - 2012-09-30 13:24 - 00038890 _____ () E:\Windows\PFRO.log
2014-05-27 09:28 - 2014-05-27 09:12 - 00000000 ____D () E:\zoek_backup
2014-05-27 09:12 - 2014-05-27 09:33 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 07:45 - 2014-01-01 17:00 - 00000000 ____D () E:\AdwCleaner
2014-05-26 18:33 - 2009-07-14 07:08 - 00032518 _____ () E:\Windows\Tasks\SCHEDLGU.TXT
2014-05-25 07:27 - 2011-01-01 21:14 - 00000000 ____D () E:\Users\Táta\Desktop\Tata
2014-05-16 19:48 - 2012-05-07 09:39 - 00692400 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-16 19:48 - 2012-05-07 09:39 - 00070832 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-16 19:48 - 2012-05-07 09:39 - 00003852 _____ () E:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-16 17:33 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\rescache
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 16:35 - 2014-05-08 08:03 - 00000000 ___SD () E:\Windows\system32\CompatTel
2014-05-15 16:35 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\PolicyDefinitions
2014-05-11 19:52 - 2012-05-07 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 09:31 - 2014-05-10 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-09 08:14 - 2014-05-15 04:57 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 04:57 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-08 08:07 - 2012-12-22 10:53 - 00003948 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 08:07 - 2012-12-22 10:53 - 00003696 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 06:40 - 2014-05-15 05:03 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 05:03 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 05:03 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 05:03 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
E:\Users\Táta\AppData\Local\Temp\vlc-2.1.3-win32.exe
==================== Bamital & volsnap Check =================
E:\Windows\System32\winlogon.exe => MD5 is legit
E:\Windows\System32\wininit.exe => MD5 is legit
E:\Windows\SysWOW64\wininit.exe => MD5 is legit
E:\Windows\explorer.exe => MD5 is legit
E:\Windows\SysWOW64\explorer.exe => MD5 is legit
E:\Windows\System32\svchost.exe => MD5 is legit
E:\Windows\SysWOW64\svchost.exe => MD5 is legit
E:\Windows\System32\services.exe => MD5 is legit
E:\Windows\System32\User32.dll => MD5 is legit
E:\Windows\SysWOW64\User32.dll => MD5 is legit
E:\Windows\System32\userinit.exe => MD5 is legit
E:\Windows\SysWOW64\userinit.exe => MD5 is legit
E:\Windows\System32\rpcss.dll => MD5 is legit
E:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "E:\Users\T�ta\Desktop" je 2311 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"E:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"E:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Táta (administrator) on TÁTA-PC on 04-06-2014 16:27:44
Running from E:\Users\Táta\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) E:\Windows\System32\atiesrxx.exe
(AMD) E:\Windows\System32\atieclxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastUI.exe
(forum.viry.cz) E:\Users\Táta\Desktop\FRST-OlderVersion\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [avast] => E:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\...\MountPoints2: {fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba} - H:\LGAutoRun.exe
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: E:\Users\Táta\AppData\Roaming\Mozilla\Firefox\Profiles\9b22ti9i.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: seznam.cz
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - E:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 - E:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - E:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - E:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - E:\Users\Táta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: E:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-03]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Seznam Lištička - Email) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-02-19]
CHR Extension: (Seznam Lištička - Slovník) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-02-19]
CHR Extension: (Chrome In-App Payments service) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Seznam Lištička - Rychlá volba) - E:\Users\Táta\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-02-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; E:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; E:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; E:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; E:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; E:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; E:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; E:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; E:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 MTsensor; E:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
R0 sptd; E:\Windows\System32\Drivers\sptd.sys [564824 2013-10-20] (Duplex Secure Ltd.)
U3 aokb5osh; E:\Windows\System32\Drivers\aokb5osh.sys [0 ] (Microsoft Corporation)
S3 EverestDriver; \??\E:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-04 16:27 - 2014-06-04 16:28 - 00009036 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-06-04 16:27 - 2014-06-04 16:27 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-06-03 15:43 - 2014-06-03 16:05 - 00000000 ____D () E:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-03 15:43 - 2014-06-03 15:43 - 00119000 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 15:42 - 2014-06-03 16:05 - 00000000 ____D () E:\Users\Táta\Desktop\mbar
2014-06-03 15:42 - 2014-06-03 15:42 - 00091352 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-03 15:41 - 2014-06-03 15:42 - 12589848 _____ (Malwarebytes Corp.) E:\Users\Táta\Downloads\mbar-1.07.0.1009.exe
2014-06-03 15:22 - 2014-06-03 15:29 - 00000000 ____D () E:\Users\Táta\Desktop\video
2014-06-01 12:22 - 2014-06-01 12:22 - 00003584 _____ () E:\Users\Táta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-01 12:10 - 2014-06-01 12:41 - 00000000 ____D () E:\Users\Táta\AppData\Local\WMTools Downloaded Files
2014-06-01 12:09 - 2014-06-01 12:09 - 00002507 _____ () E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
2014-06-01 12:09 - 2014-06-01 12:09 - 00000000 ____D () E:\Program Files (x86)\Movie Maker 2.6
2014-06-01 12:00 - 2014-06-01 12:00 - 07363072 _____ () E:\Users\Táta\Downloads\MM26_CS.msi
2014-05-27 09:33 - 2014-06-04 16:28 - 00000000 ____D () E:\Users\Táta\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default User\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:12 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 09:13 - 2014-05-27 09:34 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:12 - 2014-05-27 09:28 - 00000000 ____D () E:\zoek_backup
2014-05-27 07:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) E:\Windows\SysWOW64\sqlite3.dll
2014-05-15 05:03 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-15 05:03 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-15 05:03 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-15 05:03 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-15 05:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
2014-05-15 04:58 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) E:\Windows\system32\shell32.dll
2014-05-15 04:58 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) E:\Windows\SysWOW64\shell32.dll
2014-05-15 04:57 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-15 04:57 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-15 04:57 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 04:57 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) E:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 04:57 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) E:\Windows\system32\lsasrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) E:\Windows\system32\sspicli.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) E:\Windows\system32\lsass.exe
2014-05-15 04:57 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) E:\Windows\system32\sspisrv.dll
2014-05-15 04:57 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) E:\Windows\system32\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) E:\Windows\SysWOW64\secur32.dll
2014-05-15 04:57 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) E:\Windows\SysWOW64\sspicli.dll
2014-05-15 04:57 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) E:\Windows\system32\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) E:\Windows\system32\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) E:\Windows\system32\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) E:\Windows\system32\KernelBase.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) E:\Windows\system32\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) E:\Windows\system32\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) E:\Windows\system32\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) E:\Windows\system32\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) E:\Windows\system32\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) E:\Windows\system32\winlogon.exe
2014-05-15 04:57 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) E:\Windows\system32\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) E:\Windows\system32\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) E:\Windows\system32\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) E:\Windows\system32\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) E:\Windows\system32\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) E:\Windows\system32\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 04:57 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) E:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 04:57 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\kerberos.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) E:\Windows\SysWOW64\objsel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) E:\Windows\SysWOW64\msv1_0.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) E:\Windows\SysWOW64\schannel.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wdigest.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) E:\Windows\SysWOW64\TSpkg.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) E:\Windows\SysWOW64\cngprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) E:\Windows\SysWOW64\adprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) E:\Windows\SysWOW64\capiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\dimsroam.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) E:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 04:57 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) E:\Windows\SysWOW64\credssp.dll
2014-05-15 04:57 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) E:\Windows\SysWOW64\KernelBase.dll
2014-05-10 09:30 - 2014-05-10 09:31 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-08 08:03 - 2014-05-15 16:35 - 00000000 ___SD () E:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-06-04 16:28 - 2014-06-04 16:27 - 00009036 _____ () E:\Users\Táta\Desktop\FRST.txt
2014-06-04 16:28 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Táta\AppData\Local\Temp
2014-06-04 16:27 - 2014-06-04 16:27 - 00000000 ____D () E:\Users\Táta\Desktop\FRST-OlderVersion
2014-06-04 16:27 - 2014-01-02 11:13 - 00000000 ____D () E:\FRST
2014-06-04 16:27 - 2014-01-02 11:11 - 02068992 _____ (Farbar) E:\Users\Táta\Desktop\FRST64.exe
2014-06-04 16:22 - 2014-02-21 19:22 - 00000914 _____ () E:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-04 16:18 - 2012-08-23 09:30 - 01133296 _____ () E:\Windows\WindowsUpdate.log
2014-06-04 16:17 - 2014-02-21 18:30 - 00000952 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 14:59 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-04 14:59 - 2009-07-14 06:45 - 00014224 ____H () E:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-04 14:52 - 2014-02-21 18:30 - 00000948 _____ () E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-04 14:51 - 2012-08-23 11:50 - 00083462 _____ () E:\Windows\setupact.log
2014-06-04 14:51 - 2009-07-14 07:08 - 00000006 ____H () E:\Windows\Tasks\SA.DAT
2014-06-03 16:05 - 2014-06-03 15:43 - 00000000 ____D () E:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-03 16:05 - 2014-06-03 15:42 - 00000000 ____D () E:\Users\Táta\Desktop\mbar
2014-06-03 15:43 - 2014-06-03 15:43 - 00119000 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 15:42 - 2014-06-03 15:42 - 00091352 _____ (Malwarebytes Corporation) E:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-03 15:42 - 2014-06-03 15:41 - 12589848 _____ (Malwarebytes Corp.) E:\Users\Táta\Downloads\mbar-1.07.0.1009.exe
2014-06-03 15:29 - 2014-06-03 15:22 - 00000000 ____D () E:\Users\Táta\Desktop\video
2014-06-03 15:17 - 2012-07-03 20:00 - 00004182 _____ () E:\Windows\System32\Tasks\avast! Emergency Update
2014-06-01 21:07 - 2009-07-14 07:09 - 00000000 ____D () E:\Windows\System32\Tasks\WPD
2014-06-01 12:41 - 2014-06-01 12:10 - 00000000 ____D () E:\Users\Táta\AppData\Local\WMTools Downloaded Files
2014-06-01 12:35 - 2013-10-28 16:04 - 00000000 ____D () E:\Users\Táta\AppData\Roaming\vlc
2014-06-01 12:22 - 2014-06-01 12:22 - 00003584 _____ () E:\Users\Táta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-01 12:09 - 2014-06-01 12:09 - 00002507 _____ () E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
2014-06-01 12:09 - 2014-06-01 12:09 - 00000000 ____D () E:\Program Files (x86)\Movie Maker 2.6
2014-06-01 12:00 - 2014-06-01 12:00 - 07363072 _____ () E:\Users\Táta\Downloads\MM26_CS.msi
2014-05-31 14:41 - 2009-07-14 17:18 - 00669132 _____ () E:\Windows\system32\perfh005.dat
2014-05-31 14:41 - 2009-07-14 17:18 - 00141760 _____ () E:\Windows\system32\perfc005.dat
2014-05-31 14:41 - 2009-07-14 07:13 - 01584626 _____ () E:\Windows\system32\PerfStringBackup.INI
2014-05-27 09:34 - 2014-05-27 09:13 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default\AppData\Local\Temp
2014-05-27 09:33 - 2014-05-27 09:33 - 00000000 ____D () E:\Users\Default User\AppData\Local\Temp
2014-05-27 09:33 - 2012-09-30 13:24 - 00038890 _____ () E:\Windows\PFRO.log
2014-05-27 09:28 - 2014-05-27 09:12 - 00000000 ____D () E:\zoek_backup
2014-05-27 09:12 - 2014-05-27 09:33 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 07:45 - 2014-01-01 17:00 - 00000000 ____D () E:\AdwCleaner
2014-05-26 18:33 - 2009-07-14 07:08 - 00032518 _____ () E:\Windows\Tasks\SCHEDLGU.TXT
2014-05-25 07:27 - 2011-01-01 21:14 - 00000000 ____D () E:\Users\Táta\Desktop\Tata
2014-05-16 19:48 - 2012-05-07 09:39 - 00692400 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-16 19:48 - 2012-05-07 09:39 - 00070832 _____ (Adobe Systems Incorporated) E:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-16 19:48 - 2012-05-07 09:39 - 00003852 _____ () E:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-16 17:33 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\rescache
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 16:39 - 2010-12-28 20:33 - 00000000 ___RD () E:\Users\Táta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 16:35 - 2014-05-08 08:03 - 00000000 ___SD () E:\Windows\system32\CompatTel
2014-05-15 16:35 - 2009-07-14 05:20 - 00000000 ____D () E:\Windows\PolicyDefinitions
2014-05-11 19:52 - 2012-05-07 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 09:31 - 2014-05-10 09:30 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-05-09 08:14 - 2014-05-15 04:57 - 00477184 _____ (Microsoft Corporation) E:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 04:57 - 00424448 _____ (Microsoft Corporation) E:\Windows\system32\aeinv.dll
2014-05-08 08:07 - 2012-12-22 10:53 - 00003948 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 08:07 - 2012-12-22 10:53 - 00003696 _____ () E:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 06:40 - 2014-05-15 05:03 - 23544320 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 05:03 - 17382912 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 05:03 - 02724864 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 05:03 - 00084992 _____ (Microsoft Corporation) E:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 05:03 - 00069632 _____ (Microsoft Corporation) E:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
E:\Users\Táta\AppData\Local\Temp\vlc-2.1.3-win32.exe
==================== Bamital & volsnap Check =================
E:\Windows\System32\winlogon.exe => MD5 is legit
E:\Windows\System32\wininit.exe => MD5 is legit
E:\Windows\SysWOW64\wininit.exe => MD5 is legit
E:\Windows\explorer.exe => MD5 is legit
E:\Windows\SysWOW64\explorer.exe => MD5 is legit
E:\Windows\System32\svchost.exe => MD5 is legit
E:\Windows\SysWOW64\svchost.exe => MD5 is legit
E:\Windows\System32\services.exe => MD5 is legit
E:\Windows\System32\User32.dll => MD5 is legit
E:\Windows\SysWOW64\User32.dll => MD5 is legit
E:\Windows\System32\userinit.exe => MD5 is legit
E:\Windows\SysWOW64\userinit.exe => MD5 is legit
E:\Windows\System32\rpcss.dll => MD5 is legit
E:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "E:\Users\T�ta\Desktop" je 2311 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"E:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"E:\Users\T�ta\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"E:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: Porsím vyoska o revizi
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation) HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\...\MountPoints2: {fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba} - H:\LGAutoRun.exe S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X] S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X] S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X] S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X] S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X] S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X] 2014-05-27 09:33 - 2014-05-27 09:12 - 00024064 _____ () E:\Windows\zoek-delete.exe 2014-05-27 09:13 - 2014-05-27 09:34 - 00009450 _____ () E:\zoek-results.log 2014-05-27 09:12 - 2014-05-27 09:28 - 00000000 ____D () E:\zoek_backup Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f Hosts: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: Porsím vyoska o revizi
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-06-2014
Ran by Táta at 2014-06-06 15:25:10 Run:2
Running from E:\Users\Táta\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\...\MountPoints2: {fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba} - H:\LGAutoRun.exe
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
2014-05-27 09:33 - 2014-05-27 09:12 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 09:13 - 2014-05-27 09:34 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:12 - 2014-05-27 09:28 - 00000000 ____D () E:\zoek_backup
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
Hosts:
End
*****************
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SPReview => value deleted successfully.
'HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba}' => Key deleted successfully.
'HKCR\CLSID\{fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba}'=> Key not found.
Synth3dVsc => Service deleted successfully.
tsusbhub => Service deleted successfully.
VGPU => Service deleted successfully.
X6va005 => Service deleted successfully.
X6va007 => Service deleted successfully.
X6va008 => Service deleted successfully.
X6va009 => Service deleted successfully.
X6va010 => Service deleted successfully.
X6va011 => Service deleted successfully.
E:\Windows\zoek-delete.exe => Moved successfully.
E:\zoek-results.log => Moved successfully.
E:\zoek_backup => Moved successfully.
E:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
E:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
==== End of Fixlog ====
Ran by Táta at 2014-06-06 15:25:10 Run:2
Running from E:\Users\Táta\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\.DEFAULT\...\RunOnce: [SPReview] - E:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\...\MountPoints2: {fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba} - H:\LGAutoRun.exe
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va005; \??\E:\Users\TTA~1\AppData\Local\Temp\005F343.tmp [X]
S3 X6va007; \??\E:\Users\TTA~1\AppData\Local\Temp\0076A18.tmp [X]
S3 X6va008; \??\E:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 X6va009; \??\E:\Windows\SysWOW64\Drivers\X6va009 [X]
S3 X6va010; \??\E:\Windows\SysWOW64\Drivers\X6va010 [X]
S3 X6va011; \??\E:\Windows\SysWOW64\Drivers\X6va011 [X]
2014-05-27 09:33 - 2014-05-27 09:12 - 00024064 _____ () E:\Windows\zoek-delete.exe
2014-05-27 09:13 - 2014-05-27 09:34 - 00009450 _____ () E:\zoek-results.log
2014-05-27 09:12 - 2014-05-27 09:28 - 00000000 ____D () E:\zoek_backup
Task: E:\Windows\Tasks\Adobe Flash Player Updater.job => E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files (x86)\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
Hosts:
End
*****************
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SPReview => value deleted successfully.
'HKU\S-1-5-21-3057140317-4145169195-2744818469-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba}' => Key deleted successfully.
'HKCR\CLSID\{fe0ae57b-e8b8-11e3-9a77-90e6ba9df2ba}'=> Key not found.
Synth3dVsc => Service deleted successfully.
tsusbhub => Service deleted successfully.
VGPU => Service deleted successfully.
X6va005 => Service deleted successfully.
X6va007 => Service deleted successfully.
X6va008 => Service deleted successfully.
X6va009 => Service deleted successfully.
X6va010 => Service deleted successfully.
X6va011 => Service deleted successfully.
E:\Windows\zoek-delete.exe => Moved successfully.
E:\zoek-results.log => Moved successfully.
E:\zoek_backup => Moved successfully.
E:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
E:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
E:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
E:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
==== End of Fixlog ====
Re: Porsím vyoska o revizi
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Porsím vyoska o revizi
Omlouvám se za neaktivitu, ale k tomuto počítači se dostanu jednou za čas..
Už to funguje perfektně..
Děkuju!!!!
Už to funguje perfektně..
Děkuju!!!!
Re: Porsím vyoska o revizi
Neni tedy zac a tema uzaviram...




Přispějete na provoz fóra?