
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola PC po odstranění mallware
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Kontrola PC po odstranění mallware
Dobrý den,
po startu systému se nyní objevuje hláška RUNDLL: "Chyba při načítání souboru TWEAKUI.CPL. Uvedený modul nebyl nalezen". Po potvrzení hláška zmizí.
Kontrolou Avastu(kompletní důkladný test) jsem nalezl několik malware a přesunul do truhly.
Prosím o pomoc s doléčením.
Níže posílám log ADWCleaneru(SCAN a následně CLEAN) a RSIT:
# AdwCleaner v4.102 - Report created 29/11/2014 at 09:59:50
# Updated 23/11/2014 by Xplode
# Database : 2014-11-23.7 [Local]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : oper - KANCELAR1
# Running from : C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
*************************
AdwCleaner[R0].txt - [726 octets] - [29/11/2014 09:54:45]
AdwCleaner[S0].txt - [648 octets] - [29/11/2014 09:59:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [707 octets] ##########
Logfile of random's system information tool 1.10 (written by random/random)
Run by oper at 2014-11-29 10:13:58
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 206 GB (86%) free of 238 GB
Total RAM: 990 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:08, on 29.11.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\oper\Plocha\RSIT.exe
C:\Program Files\trend micro\oper.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.seznam.cz
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = skola.int
O17 - HKLM\Software\..\Telephony: DomainName = skola.int
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: NameServer = 192.168.77.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = skola.int
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6841 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\Záloha na počítač kancelar.job - C:\WINDOWS\system32\ntbackup.exe backup "@C:\Documents and Settings\nemcova\Local Settings\Data aplikací\Microsoft\Windows NT\NTBackup\data\Záloha na počítač kancelar.bks" /a /d "Sada vytvořena 23.10.2008 v 8:31" /v:no /r:no /rs:no /hc:off /m daily /j "Záloha na počítač kancelar" /l:s /f "\\Kancelar\install\Záloha-Iveta\Zaloha.bkf"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-11-29 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2014-11-24 586968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-11-29 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"NWEReboot"= []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2007-04-12 98304]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2014-11-24 5226600]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-06-01 94208]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-11-21 5282584]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDesktopCleanupWizard"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Install\NeRo_Miranda\miranda32.exe"="C:\Install\NeRo_Miranda\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe"="C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe"="C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe:*:Enabled:HP Networked Printer Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3acm"=l3codeca.acm
"msacm.msaudio1"=msaud32.acm
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
======List of files/folders created in the last 1 month======
2014-11-29 10:13:58 ----D---- C:\rsit
2014-11-29 10:13:58 ----D---- C:\Program Files\trend micro
2014-11-29 09:54:42 ----D---- C:\AdwCleaner
2014-11-29 09:37:03 ----A---- C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\java.exe
2014-11-28 09:01:04 ----D---- C:\Program Files\CCleaner
2014-11-27 08:49:59 ----D---- C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49:13 ----D---- C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:04:28 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04:26 ----A---- C:\WINDOWS\avastSS.scr
2014-10-30 16:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:06:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:05:09 ----D---- C:\Program Files\NVIDIA Corporation
2014-10-30 16:03:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:03:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 16:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 15:44:20 ----D---- C:\WINDOWS\system32\MRT
2014-10-30 15:31:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19:10 ----N---- C:\WINDOWS\system32\xp_eos.exe
2014-10-30 03:04:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:04:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-10-30 03:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
======List of files/folders modified in the last 1 month======
2014-11-29 10:14:06 ----D---- C:\WINDOWS\Prefetch
2014-11-29 10:13:58 ----D---- C:\Program Files
2014-11-29 10:06:10 ----SHD---- C:\WINDOWS\Installer
2014-11-29 10:06:10 ----SD---- C:\WINDOWS\Tasks
2014-11-29 10:06:10 ----D---- C:\WINDOWS\Temp
2014-11-29 10:02:30 ----D---- C:\WINDOWS
2014-11-29 10:01:28 ----D---- C:\Program Files\Google
2014-11-29 10:00:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-11-29 10:00:15 ----D---- C:\WINDOWS\system32\CatRoot2
2014-11-29 09:46:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:37:13 ----HD---- C:\Config.Msi
2014-11-29 09:37:12 ----D---- C:\Program Files\Common Files\Java
2014-11-29 09:37:04 ----D---- C:\WINDOWS\system32
2014-11-29 09:33:01 ----SHD---- C:\RECYCLER
2014-11-29 09:27:38 ----D---- C:\WINDOWS\security
2014-11-28 12:21:12 ----SHD---- C:\WINDOWS\CSC
2014-11-28 09:17:03 ----D---- C:\WINDOWS\Debug
2014-11-28 09:17:02 ----D---- C:\WINDOWS\Minidump
2014-11-28 08:52:14 ----HD---- C:\WINDOWS\inf
2014-11-28 07:15:55 ----D---- C:\gordic
2014-11-27 14:21:35 ----D---- C:\POKARC
2014-11-27 14:15:38 ----D---- C:\KDFARC
2014-11-27 09:31:28 ----D---- C:\Program Files\Internet Explorer
2014-11-27 09:31:21 ----A---- C:\WINDOWS\system.ini
2014-11-27 09:29:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-11-27 09:04:37 ----SD---- C:\Documents and Settings\oper\Data aplikací\Microsoft
2014-11-26 14:09:16 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-25 06:50:55 ----D---- C:\WINDOWS\system32\drivers
2014-11-18 08:32:32 ----D---- C:\Program Files\Messenger
2014-11-12 15:21:17 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-31 14:56:19 ----D---- C:\UCRARC
2014-10-31 07:30:02 ----RSD---- C:\WINDOWS\assembly
2014-10-31 07:30:02 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-30 16:05:02 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03:33 ----D---- C:\WINDOWS\ie8updates
2014-10-30 15:56:34 ----D---- C:\WINDOWS\WinSxS
2014-10-30 15:56:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-11-24 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-11-24 206248]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-01-27 99584]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-03-11 20640]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-11-24 55240]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-11-24 787800]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-11-24 423784]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-11-24 57928]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-11-24 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-11-24 70384]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 HidBatt;Ovladač baterie zdroje UPS standardu HID; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2008-04-13 20352]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2003-08-04 6912]
S3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2003-08-04 11392]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2014-11-24 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-11-29 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-01-24 131139]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26 267440]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
po startu systému se nyní objevuje hláška RUNDLL: "Chyba při načítání souboru TWEAKUI.CPL. Uvedený modul nebyl nalezen". Po potvrzení hláška zmizí.
Kontrolou Avastu(kompletní důkladný test) jsem nalezl několik malware a přesunul do truhly.
Prosím o pomoc s doléčením.
Níže posílám log ADWCleaneru(SCAN a následně CLEAN) a RSIT:
# AdwCleaner v4.102 - Report created 29/11/2014 at 09:59:50
# Updated 23/11/2014 by Xplode
# Database : 2014-11-23.7 [Local]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : oper - KANCELAR1
# Running from : C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
*************************
AdwCleaner[R0].txt - [726 octets] - [29/11/2014 09:54:45]
AdwCleaner[S0].txt - [648 octets] - [29/11/2014 09:59:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [707 octets] ##########
Logfile of random's system information tool 1.10 (written by random/random)
Run by oper at 2014-11-29 10:13:58
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 206 GB (86%) free of 238 GB
Total RAM: 990 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:08, on 29.11.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\oper\Plocha\RSIT.exe
C:\Program Files\trend micro\oper.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.seznam.cz
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = skola.int
O17 - HKLM\Software\..\Telephony: DomainName = skola.int
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: NameServer = 192.168.77.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = skola.int
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6841 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\Záloha na počítač kancelar.job - C:\WINDOWS\system32\ntbackup.exe backup "@C:\Documents and Settings\nemcova\Local Settings\Data aplikací\Microsoft\Windows NT\NTBackup\data\Záloha na počítač kancelar.bks" /a /d "Sada vytvořena 23.10.2008 v 8:31" /v:no /r:no /rs:no /hc:off /m daily /j "Záloha na počítač kancelar" /l:s /f "\\Kancelar\install\Záloha-Iveta\Zaloha.bkf"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-11-29 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2014-11-24 586968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-11-29 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"NWEReboot"= []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2007-04-12 98304]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2014-11-24 5226600]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-06-01 94208]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-11-21 5282584]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDesktopCleanupWizard"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Install\NeRo_Miranda\miranda32.exe"="C:\Install\NeRo_Miranda\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe"="C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe"="C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe:*:Enabled:HP Networked Printer Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3acm"=l3codeca.acm
"msacm.msaudio1"=msaud32.acm
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
======List of files/folders created in the last 1 month======
2014-11-29 10:13:58 ----D---- C:\rsit
2014-11-29 10:13:58 ----D---- C:\Program Files\trend micro
2014-11-29 09:54:42 ----D---- C:\AdwCleaner
2014-11-29 09:37:03 ----A---- C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\java.exe
2014-11-28 09:01:04 ----D---- C:\Program Files\CCleaner
2014-11-27 08:49:59 ----D---- C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49:13 ----D---- C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:04:28 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04:26 ----A---- C:\WINDOWS\avastSS.scr
2014-10-30 16:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:06:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:05:09 ----D---- C:\Program Files\NVIDIA Corporation
2014-10-30 16:03:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:03:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 16:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 15:44:20 ----D---- C:\WINDOWS\system32\MRT
2014-10-30 15:31:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19:10 ----N---- C:\WINDOWS\system32\xp_eos.exe
2014-10-30 03:04:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:04:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-10-30 03:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
======List of files/folders modified in the last 1 month======
2014-11-29 10:14:06 ----D---- C:\WINDOWS\Prefetch
2014-11-29 10:13:58 ----D---- C:\Program Files
2014-11-29 10:06:10 ----SHD---- C:\WINDOWS\Installer
2014-11-29 10:06:10 ----SD---- C:\WINDOWS\Tasks
2014-11-29 10:06:10 ----D---- C:\WINDOWS\Temp
2014-11-29 10:02:30 ----D---- C:\WINDOWS
2014-11-29 10:01:28 ----D---- C:\Program Files\Google
2014-11-29 10:00:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-11-29 10:00:15 ----D---- C:\WINDOWS\system32\CatRoot2
2014-11-29 09:46:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:37:13 ----HD---- C:\Config.Msi
2014-11-29 09:37:12 ----D---- C:\Program Files\Common Files\Java
2014-11-29 09:37:04 ----D---- C:\WINDOWS\system32
2014-11-29 09:33:01 ----SHD---- C:\RECYCLER
2014-11-29 09:27:38 ----D---- C:\WINDOWS\security
2014-11-28 12:21:12 ----SHD---- C:\WINDOWS\CSC
2014-11-28 09:17:03 ----D---- C:\WINDOWS\Debug
2014-11-28 09:17:02 ----D---- C:\WINDOWS\Minidump
2014-11-28 08:52:14 ----HD---- C:\WINDOWS\inf
2014-11-28 07:15:55 ----D---- C:\gordic
2014-11-27 14:21:35 ----D---- C:\POKARC
2014-11-27 14:15:38 ----D---- C:\KDFARC
2014-11-27 09:31:28 ----D---- C:\Program Files\Internet Explorer
2014-11-27 09:31:21 ----A---- C:\WINDOWS\system.ini
2014-11-27 09:29:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-11-27 09:04:37 ----SD---- C:\Documents and Settings\oper\Data aplikací\Microsoft
2014-11-26 14:09:16 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-25 06:50:55 ----D---- C:\WINDOWS\system32\drivers
2014-11-18 08:32:32 ----D---- C:\Program Files\Messenger
2014-11-12 15:21:17 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-31 14:56:19 ----D---- C:\UCRARC
2014-10-31 07:30:02 ----RSD---- C:\WINDOWS\assembly
2014-10-31 07:30:02 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-30 16:05:02 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03:33 ----D---- C:\WINDOWS\ie8updates
2014-10-30 15:56:34 ----D---- C:\WINDOWS\WinSxS
2014-10-30 15:56:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-11-24 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-11-24 206248]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-01-27 99584]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-03-11 20640]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-11-24 55240]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-11-24 787800]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-11-24 423784]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-11-24 57928]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-11-24 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-11-24 70384]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 HidBatt;Ovladač baterie zdroje UPS standardu HID; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2008-04-13 20352]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2003-08-04 6912]
S3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2003-08-04 11392]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2014-11-24 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-11-29 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-01-24 131139]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26 267440]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Kontrola PC po odstranění mallware
Zdravim
Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu


- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; resethosts; emptyclsid; IEdefaults; FFdefaults; CHRdefaults; emptyIEcache; emptyFFcache; emptyCHRcache; emptyalltemp; emptyflash; emptyjava; emptyrecycle.bin;
- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Kontrola PC po odstranění mallware
Po restartu ta hláška ohledně nenalezeného objektu je tam stále. Co kdybych odebral z registru položku:
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Co vůbec Tweakui.cpl dělá?
Níže poíslám log Zoek:
Zoek.exe v5.0.0.0 Updated 28-11-2014
Tool run by oper on so 29.11.2014 at 12:49:03,65.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\oper\Plocha\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.11.2014 12:50:44 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Suspicious Entries Found ======================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Program Files\ComPlus Applications deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ezsid.dat deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [24.11.2014 12:04]
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[24.11.2014 12:04]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... RA_csCZ448"
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\bistep\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\gio\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\hlava\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\kancelar\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\skolnik\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=2 folders=1 210 bytes)
==== Empty Temp Folders ======================
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\oper\LOCALS~1\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on so 29.11.2014 at 13:06:49,84 ======================
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Co vůbec Tweakui.cpl dělá?
Níže poíslám log Zoek:
Zoek.exe v5.0.0.0 Updated 28-11-2014
Tool run by oper on so 29.11.2014 at 12:49:03,65.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\oper\Plocha\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.11.2014 12:50:44 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Suspicious Entries Found ======================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Program Files\ComPlus Applications deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ezsid.dat deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [24.11.2014 12:04]
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[24.11.2014 12:04]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... RA_csCZ448"
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\bistep\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\gio\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\hlava\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\kancelar\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\skolnik\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=2 folders=1 210 bytes)
==== Empty Temp Folders ======================
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\oper\LOCALS~1\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on so 29.11.2014 at 13:06:49,84 ======================
Re: Kontrola PC po odstranění mallware


Re: Kontrola PC po odstranění mallware
OK.
Níže je log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01
Ran by oper (administrator) on KANCELAR1 on 29-11-2014 13:48:26
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\WINDOWS\system32\logon.scr
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAShCut.exe [61952 2004-10-27] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [925696 2005-05-20] (Analog Devices, Inc.)
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
SearchScopes: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdat ... /opuc4.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.77.11 192.168.77.12
Tcpip\..\Interfaces\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: [NameServer] 192.168.77.15
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-27]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-06-21]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
S2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [142336 2010-04-12] (HP) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-11-29] (Oracle Corporation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AEAudioService; C:\WINDOWS\System32\drivers\AEAudio.sys [127872 2005-03-04] (Andrea Electronics Corporation)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [42496 2005-03-09] (Advanced Micro Devices)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-24] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-24] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-24] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-24] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [423784 2014-11-24] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-24] ()
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows (R) Server 2003 DDK provider)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [99584 2006-01-27] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [34176 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13056 2006-02-17] (NVIDIA Corporation)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-03-11] (Sonic Solutions) [File not signed]
R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [393088 2005-08-11] (Sensaura)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:47 - 2014-11-29 13:48 - 00000000 ____D () C:\FRST
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:38 - 2014-11-29 13:47 - 01109504 _____ (Farbar) C:\Documents and Settings\oper\Plocha\FRST.exe
2014-11-29 13:02 - 2014-11-29 13:48 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Temp
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
2014-11-29 09:46 - 2014-11-29 09:46 - 00020328 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-11-29 09:41 - 2014-11-29 09:41 - 00000000 __SHD () C:\Documents and Settings\oper\IECompatCache
2014-11-29 09:39 - 2014-11-29 09:39 - 00000000 __SHD () C:\Documents and Settings\oper\PrivacIE
2014-11-29 09:37 - 2014-11-29 09:37 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Temp
2014-11-29 09:37 - 2014-11-29 09:36 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-28 09:01 - 2014-11-28 09:01 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2014-11-27 09:09 - 2014-11-27 09:09 - 00012818 ____N () C:\Documents and Settings\oper\Dokumenty\Gordic Reporter - POKS0004.mdi
2014-11-27 09:02 - 2014-11-27 09:02 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WKdf.lnk
2014-11-27 08:59 - 2014-11-27 08:59 - 00012822 ____N () C:\Documents and Settings\oper\Plocha\Gordic Reporter - POKS0001.mdi
2014-11-27 08:54 - 2014-11-27 08:54 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Sun
2014-11-27 08:49 - 2014-11-27 09:10 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49 - 2014-11-27 08:49 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WPOK.lnk
2014-11-27 08:49 - 2014-11-27 08:49 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:05 - 2014-11-24 12:05 - 00001742 _____ () C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2014-11-24 12:04 - 2014-11-24 12:04 - 00291352 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04 - 2014-11-24 12:04 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-30 16:07 - 2014-10-30 16:07 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:05 - 2014-10-30 16:06 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb0.bin
2014-10-30 16:05 - 2014-10-30 16:06 - 00000001 _____ () C:\WINDOWS\system32\nvdrssel.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb1.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 _____ () C:\WINDOWS\system32\nvdrswr.lk
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 15:44 - 2014-11-12 15:27 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26 - 2014-10-30 15:26 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____N (Microsoft Corporation) C:\WINDOWS\system32\xp_eos.exe
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xp_eos.exe
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-29 13:48 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper\Plocha
2014-11-29 13:40 - 2007-04-06 08:11 - 00000000 ___HD () C:\Documents and Settings\oper\Local Settings\Data aplikací
2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-29 13:06 - 2006-03-02 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-29 13:05 - 2007-03-30 15:00 - 01790245 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-29 13:04 - 2007-04-06 08:09 - 00000112 _____ () C:\WINDOWS\system32\config\netlogon.ftl
2014-11-29 13:04 - 2007-03-30 15:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-29 13:02 - 2007-04-06 08:11 - 00000272 ___SH () C:\Documents and Settings\oper\ntuser.ini
2014-11-29 13:02 - 2007-03-30 15:04 - 00032512 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-29 12:57 - 2007-03-30 16:35 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-11-29 12:00 - 2008-10-23 07:31 - 00000826 _____ () C:\WINDOWS\Tasks\Záloha na počítač kancelar.job
2014-11-29 10:06 - 2011-09-05 08:23 - 00000000 ____D () C:\Program Files\Google
2014-11-29 10:05 - 2009-03-04 07:27 - 00000966 __RSH () C:\Documents and Settings\oper\ntuser.pol
2014-11-29 10:05 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper
2014-11-29 09:46 - 2012-06-19 08:50 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Google
2014-11-29 09:46 - 2011-09-05 08:23 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:46 - 2007-04-06 08:11 - 00000000 __RHD () C:\Documents and Settings\oper\Data aplikací
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-11-29 09:37 - 2012-08-08 10:07 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-11-29 09:37 - 2009-08-31 08:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-11-29 09:36 - 2009-08-31 08:19 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-11-29 09:27 - 2007-03-30 16:23 - 00000000 ____D () C:\WINDOWS\security
2014-11-28 12:24 - 2009-03-04 07:21 - 00000272 ___SH () C:\Documents and Settings\pergerova\ntuser.ini
2014-11-28 12:23 - 2009-03-04 07:44 - 00000000 ____D () C:\Documents and Settings\pergerova\Data aplikací\Skype
2014-11-28 12:22 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Local Settings\Temp
2014-11-28 12:21 - 2007-04-06 08:11 - 00000000 __SHD () C:\WINDOWS\CSC
2014-11-28 09:17 - 2009-08-26 15:31 - 00000000 ____D () C:\WINDOWS\Minidump
2014-11-28 09:16 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova
2014-11-28 08:09 - 2010-12-09 14:24 - 00039424 _____ () C:\Documents and Settings\pergerova\Dokumenty\Čerpání přímé 2010.xls
2014-11-28 08:09 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Dokumenty
2014-11-28 07:25 - 2012-10-15 12:52 - 00028160 _____ () C:\Documents and Settings\pergerova\Dokumenty\Kontrola čerpání rozpočtu z provozní dotace - starší verze excelu.xls
2014-11-28 07:15 - 2007-04-11 11:23 - 00000000 ____D () C:\gordic
2014-11-28 07:02 - 2012-02-06 12:47 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled příjmů a výdajů ŠJ za měsíc 2012.xls
2014-11-27 14:21 - 2009-12-17 14:38 - 00000000 ____D () C:\POKARC
2014-11-27 14:15 - 2009-12-17 14:41 - 00000000 ____D () C:\KDFARC
2014-11-27 10:45 - 2012-02-06 12:56 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Uzaverka SJ - formular 2012.xls
2014-11-27 09:35 - 2009-03-04 07:21 - 00000000 __RHD () C:\Documents and Settings\pergerova\Data aplikací
2014-11-27 09:33 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Plocha
2014-11-27 09:32 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Nabídka Start\Programy
2014-11-27 09:31 - 2006-03-02 13:00 - 00001300 _____ () C:\WINDOWS\system.ini
2014-11-27 09:09 - 2007-04-06 08:11 - 00000000 ___RD () C:\Documents and Settings\oper\Dokumenty
2014-11-26 14:09 - 2013-05-15 06:22 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-26 14:09 - 2013-05-15 06:22 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-24 12:05 - 2011-06-21 10:07 - 00787800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-11-24 12:05 - 2010-08-26 10:19 - 00423784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2014-11-24 12:04 - 2014-08-04 06:46 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00206248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00070384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00057928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00055240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-11-20 10:39 - 2009-03-04 08:08 - 00715264 _____ () C:\Documents and Settings\pergerova\Dokumenty\FKSP příspěvky.xls
2014-11-20 07:06 - 2009-03-04 07:21 - 00000000 ___HD () C:\Documents and Settings\pergerova\Local Settings\Data aplikací
2014-11-18 08:32 - 2007-03-30 14:57 - 00000000 ____D () C:\Program Files\Messenger
2014-11-12 15:21 - 2007-04-06 08:53 - 100445232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-05 12:56 - 2012-02-06 12:43 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Převod nákladů na DČ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00019968 _____ () C:\Documents and Settings\pergerova\Dokumenty\Výpočet DPH za ŠJ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00016384 _____ () C:\Documents and Settings\pergerova\Dokumenty\Tržby Šj 2012.xls
2014-11-03 10:41 - 2009-03-04 08:08 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled o hosp. ŠJ.xls
2014-10-31 14:56 - 2008-04-10 11:45 - 00000000 ____D () C:\UCRARC
2014-10-31 07:30 - 2011-09-23 07:48 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-10-31 06:57 - 2007-03-30 16:34 - 00122928 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-30 16:05 - 2007-04-02 06:24 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03 - 2012-06-19 08:59 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-10-30 16:02 - 2007-04-06 08:53 - 00875892 _____ () C:\WINDOWS\system32\TZLog.log
2014-10-30 15:56 - 2007-03-30 16:36 - 01186406 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-30 12:14 - 2007-04-06 08:12 - 00002588 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-10-30 07:02 - 2007-04-02 06:28 - 00043531 _____ () C:\WINDOWS\system32\nvapps.xml
Some content of TEMP:
====================
C:\Documents and Settings\gio\Local Settings\Temp\nerodeltmp.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplpat_c.dll
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u33-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u35-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\PKIComponent-KBExt-setup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Níže je log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01
Ran by oper (administrator) on KANCELAR1 on 29-11-2014 13:48:26
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\WINDOWS\system32\logon.scr
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAShCut.exe [61952 2004-10-27] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [925696 2005-05-20] (Analog Devices, Inc.)
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
SearchScopes: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdat ... /opuc4.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.77.11 192.168.77.12
Tcpip\..\Interfaces\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: [NameServer] 192.168.77.15
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-27]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-06-21]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
S2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [142336 2010-04-12] (HP) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-11-29] (Oracle Corporation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AEAudioService; C:\WINDOWS\System32\drivers\AEAudio.sys [127872 2005-03-04] (Andrea Electronics Corporation)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [42496 2005-03-09] (Advanced Micro Devices)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-24] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-24] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-24] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-24] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [423784 2014-11-24] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-24] ()
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows (R) Server 2003 DDK provider)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [99584 2006-01-27] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [34176 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13056 2006-02-17] (NVIDIA Corporation)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-03-11] (Sonic Solutions) [File not signed]
R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [393088 2005-08-11] (Sensaura)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:47 - 2014-11-29 13:48 - 00000000 ____D () C:\FRST
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:38 - 2014-11-29 13:47 - 01109504 _____ (Farbar) C:\Documents and Settings\oper\Plocha\FRST.exe
2014-11-29 13:02 - 2014-11-29 13:48 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Temp
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
2014-11-29 09:46 - 2014-11-29 09:46 - 00020328 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-11-29 09:41 - 2014-11-29 09:41 - 00000000 __SHD () C:\Documents and Settings\oper\IECompatCache
2014-11-29 09:39 - 2014-11-29 09:39 - 00000000 __SHD () C:\Documents and Settings\oper\PrivacIE
2014-11-29 09:37 - 2014-11-29 09:37 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Temp
2014-11-29 09:37 - 2014-11-29 09:36 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-28 09:01 - 2014-11-28 09:01 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2014-11-27 09:09 - 2014-11-27 09:09 - 00012818 ____N () C:\Documents and Settings\oper\Dokumenty\Gordic Reporter - POKS0004.mdi
2014-11-27 09:02 - 2014-11-27 09:02 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WKdf.lnk
2014-11-27 08:59 - 2014-11-27 08:59 - 00012822 ____N () C:\Documents and Settings\oper\Plocha\Gordic Reporter - POKS0001.mdi
2014-11-27 08:54 - 2014-11-27 08:54 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Sun
2014-11-27 08:49 - 2014-11-27 09:10 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49 - 2014-11-27 08:49 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WPOK.lnk
2014-11-27 08:49 - 2014-11-27 08:49 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:05 - 2014-11-24 12:05 - 00001742 _____ () C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2014-11-24 12:04 - 2014-11-24 12:04 - 00291352 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04 - 2014-11-24 12:04 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-30 16:07 - 2014-10-30 16:07 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:05 - 2014-10-30 16:06 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb0.bin
2014-10-30 16:05 - 2014-10-30 16:06 - 00000001 _____ () C:\WINDOWS\system32\nvdrssel.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb1.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 _____ () C:\WINDOWS\system32\nvdrswr.lk
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 15:44 - 2014-11-12 15:27 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26 - 2014-10-30 15:26 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____N (Microsoft Corporation) C:\WINDOWS\system32\xp_eos.exe
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xp_eos.exe
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-29 13:48 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper\Plocha
2014-11-29 13:40 - 2007-04-06 08:11 - 00000000 ___HD () C:\Documents and Settings\oper\Local Settings\Data aplikací
2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-29 13:06 - 2006-03-02 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-29 13:05 - 2007-03-30 15:00 - 01790245 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-29 13:04 - 2007-04-06 08:09 - 00000112 _____ () C:\WINDOWS\system32\config\netlogon.ftl
2014-11-29 13:04 - 2007-03-30 15:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-29 13:02 - 2007-04-06 08:11 - 00000272 ___SH () C:\Documents and Settings\oper\ntuser.ini
2014-11-29 13:02 - 2007-03-30 15:04 - 00032512 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-29 12:57 - 2007-03-30 16:35 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-11-29 12:00 - 2008-10-23 07:31 - 00000826 _____ () C:\WINDOWS\Tasks\Záloha na počítač kancelar.job
2014-11-29 10:06 - 2011-09-05 08:23 - 00000000 ____D () C:\Program Files\Google
2014-11-29 10:05 - 2009-03-04 07:27 - 00000966 __RSH () C:\Documents and Settings\oper\ntuser.pol
2014-11-29 10:05 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper
2014-11-29 09:46 - 2012-06-19 08:50 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Google
2014-11-29 09:46 - 2011-09-05 08:23 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:46 - 2007-04-06 08:11 - 00000000 __RHD () C:\Documents and Settings\oper\Data aplikací
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-11-29 09:37 - 2012-08-08 10:07 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-11-29 09:37 - 2009-08-31 08:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-11-29 09:36 - 2009-08-31 08:19 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-11-29 09:27 - 2007-03-30 16:23 - 00000000 ____D () C:\WINDOWS\security
2014-11-28 12:24 - 2009-03-04 07:21 - 00000272 ___SH () C:\Documents and Settings\pergerova\ntuser.ini
2014-11-28 12:23 - 2009-03-04 07:44 - 00000000 ____D () C:\Documents and Settings\pergerova\Data aplikací\Skype
2014-11-28 12:22 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Local Settings\Temp
2014-11-28 12:21 - 2007-04-06 08:11 - 00000000 __SHD () C:\WINDOWS\CSC
2014-11-28 09:17 - 2009-08-26 15:31 - 00000000 ____D () C:\WINDOWS\Minidump
2014-11-28 09:16 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova
2014-11-28 08:09 - 2010-12-09 14:24 - 00039424 _____ () C:\Documents and Settings\pergerova\Dokumenty\Čerpání přímé 2010.xls
2014-11-28 08:09 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Dokumenty
2014-11-28 07:25 - 2012-10-15 12:52 - 00028160 _____ () C:\Documents and Settings\pergerova\Dokumenty\Kontrola čerpání rozpočtu z provozní dotace - starší verze excelu.xls
2014-11-28 07:15 - 2007-04-11 11:23 - 00000000 ____D () C:\gordic
2014-11-28 07:02 - 2012-02-06 12:47 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled příjmů a výdajů ŠJ za měsíc 2012.xls
2014-11-27 14:21 - 2009-12-17 14:38 - 00000000 ____D () C:\POKARC
2014-11-27 14:15 - 2009-12-17 14:41 - 00000000 ____D () C:\KDFARC
2014-11-27 10:45 - 2012-02-06 12:56 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Uzaverka SJ - formular 2012.xls
2014-11-27 09:35 - 2009-03-04 07:21 - 00000000 __RHD () C:\Documents and Settings\pergerova\Data aplikací
2014-11-27 09:33 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Plocha
2014-11-27 09:32 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Nabídka Start\Programy
2014-11-27 09:31 - 2006-03-02 13:00 - 00001300 _____ () C:\WINDOWS\system.ini
2014-11-27 09:09 - 2007-04-06 08:11 - 00000000 ___RD () C:\Documents and Settings\oper\Dokumenty
2014-11-26 14:09 - 2013-05-15 06:22 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-26 14:09 - 2013-05-15 06:22 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-24 12:05 - 2011-06-21 10:07 - 00787800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-11-24 12:05 - 2010-08-26 10:19 - 00423784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2014-11-24 12:04 - 2014-08-04 06:46 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00206248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00070384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00057928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00055240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-11-20 10:39 - 2009-03-04 08:08 - 00715264 _____ () C:\Documents and Settings\pergerova\Dokumenty\FKSP příspěvky.xls
2014-11-20 07:06 - 2009-03-04 07:21 - 00000000 ___HD () C:\Documents and Settings\pergerova\Local Settings\Data aplikací
2014-11-18 08:32 - 2007-03-30 14:57 - 00000000 ____D () C:\Program Files\Messenger
2014-11-12 15:21 - 2007-04-06 08:53 - 100445232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-05 12:56 - 2012-02-06 12:43 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Převod nákladů na DČ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00019968 _____ () C:\Documents and Settings\pergerova\Dokumenty\Výpočet DPH za ŠJ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00016384 _____ () C:\Documents and Settings\pergerova\Dokumenty\Tržby Šj 2012.xls
2014-11-03 10:41 - 2009-03-04 08:08 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled o hosp. ŠJ.xls
2014-10-31 14:56 - 2008-04-10 11:45 - 00000000 ____D () C:\UCRARC
2014-10-31 07:30 - 2011-09-23 07:48 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-10-31 06:57 - 2007-03-30 16:34 - 00122928 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-30 16:05 - 2007-04-02 06:24 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03 - 2012-06-19 08:59 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-10-30 16:02 - 2007-04-06 08:53 - 00875892 _____ () C:\WINDOWS\system32\TZLog.log
2014-10-30 15:56 - 2007-03-30 16:36 - 01186406 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-30 12:14 - 2007-04-06 08:12 - 00002588 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-10-30 07:02 - 2007-04-02 06:28 - 00043531 _____ () C:\WINDOWS\system32\nvapps.xml
Some content of TEMP:
====================
C:\Documents and Settings\gio\Local Settings\Temp\nerodeltmp.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplpat_c.dll
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u33-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u35-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\PKIComponent-KBExt-setup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Re: Kontrola PC po odstranění mallware

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\Run: [NWEReboot] => [X] HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.) HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG) HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File DisableService: JavaQuickStarterService 2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt 2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE 2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat 2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe 2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe 2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log 2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup 2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe 2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit 2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro 2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner 2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe 2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe 2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job 2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job Hosts: EmptyTemp: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: Kontrola PC po odstranění mallware
Super, zdá se to být OK.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-11-2014 01
Ran by oper at 2014-11-29 14:36:39 Run:1
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
DisableService: JavaQuickStarterService
2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NWEReboot => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Tweak UI => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk => Moved successfully.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key not found.
JavaQuickStarterService service was disabled
C:\Documents and Settings\oper\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE => Moved successfully.
C:\Documents and Settings\oper\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Documents and Settings\oper\Plocha\zoek.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Documents and Settings\oper\Plocha\RSIT.exe => Moved successfully.
C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.5 GB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-11-2014 01
Ran by oper at 2014-11-29 14:36:39 Run:1
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
DisableService: JavaQuickStarterService
2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NWEReboot => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Tweak UI => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk => Moved successfully.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key not found.
JavaQuickStarterService service was disabled
C:\Documents and Settings\oper\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE => Moved successfully.
C:\Documents and Settings\oper\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Documents and Settings\oper\Plocha\zoek.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Documents and Settings\oper\Plocha\RSIT.exe => Moved successfully.
C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.5 GB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Kontrola PC po odstranění mallware
Tak jeste uklidime
DelFix https://toolslib.net/downloads/finish/2/
Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Stahnete a spustte
- Ponechte zatrzitkou pouze u volby Remote disinfection tools
- Kliknete na Run

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


Re: Kontrola PC po odstranění mallware
Nedaří se mně stáhnout z výše uvedeného odkazu DelFix.
Nedá se stáhnout odjinud? Případně uklidit jinak?
Nedá se stáhnout odjinud? Případně uklidit jinak?
Re: Kontrola PC po odstranění mallware
Podařilo se mně ho stáhnout od jinud.
Takže mám uklizeno a vyčištěno CCleanerem.
Děkuji moc za pomoc a přeji pěkný den.
Takže mám uklizeno a vyčištěno CCleanerem.
Děkuji moc za pomoc a přeji pěkný den.