Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o preventivku

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
happysmile
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 17 pro 2011 15:11

Prosím o preventivku

#1 Příspěvek od happysmile »

Zdarvíčko,
poslední dobou mám nějak zpomalenej ntb, tak prosím o konzultaci :)

Logfile of random's system information tool 1.09 (written by random/random)
Run by Frantisek at 2015-06-10 19:10:39
Microsoft® Windows Vista™ Home Premium
System drive C: has 22 GB (29%) free of 76 GB
Total RAM: 1917 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:10:48, on 10.6.2015
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\Program Files\TO2WCM\McciTrayApp.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Frantisek\Downloads\RSIT.exe
C:\Program Files\trend micro\Frantisek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: CrossriderApp0011825 - {11111111-1111-1111-1111-110111181125} - C:\Program Files\BcoolApp\BcoolApp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [TO2WCM_McciTrayApp] C:\Program Files\TO2WCM\McciTrayApp.exe
O4 - HKLM\..\Run: [Speechtech TTS preload] "C:\Program Files\Speechtech TTS\TTSGui.exe" -preload
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (file missing)
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home (file missing)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
O23 - Service: Služba Google Update (gupdate1ca830444619653) (gupdate1ca830444619653) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 7649 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Scheduled scanning task.job
C:\Windows\tasks\User_Feed_Synchronization-{0C6A973B-5A12-4270-913B-F833E95D6EEF}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Frantisek\AppData\Roaming\Mozilla\Firefox\Profiles\rtj11hcu.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.188 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1209149.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll


C:\Users\Frantisek\AppData\Roaming\Mozilla\Firefox\Profiles\rtj11hcu.default\searchplugins\
ask-web-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110111181125}]
BcoolApp - C:\Program Files\BcoolApp\BcoolApp.dll [2012-07-03 484864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-01-29 4911104]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"NDSTray.exe"=NDSTray.exe []
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2007-10-25 413696]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2008-01-17 431456]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2008-01-22 712704]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"TO2WCM_McciTrayApp"=C:\Program Files\TO2WCM\McciTrayApp.exe [2008-01-30 1473536]
"Speechtech TTS preload"=C:\Program Files\Speechtech TTS\TTSGui.exe [2015-02-13 1855144]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desktop SMS]
C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe [2007-06-18 1507328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Manager]
C:\Program Files\F-Secure\Common\FSM32.EXE [2009-08-05 199264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
C:\Program Files\F-Secure\FSGUI\TNBUtil.exe [2009-08-05 2349664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
C:\Program Files\AVG Secure Search\vprot.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.dvacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2015-06-04 17:36:54 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-06-10 19:10:43 ----D---- C:\Program Files\trend micro
2015-06-10 19:10:42 ----D---- C:\Windows\Temp
2015-06-10 19:05:48 ----D---- C:\Program Files\Speechtech TTS
2015-06-10 18:29:55 ----D---- C:\Windows\system32\MRT
2015-06-10 18:29:54 ----D---- C:\Windows\Debug
2015-06-10 18:29:17 ----A---- C:\Windows\system32\mrt.exe
2015-06-10 18:28:40 ----SHD---- C:\System Volume Information
2015-06-09 20:21:58 ----AD---- C:\Windows\System32
2015-06-09 20:21:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-06-08 15:29:22 ----D---- C:\Windows\inf
2015-06-08 14:16:46 ----D---- C:\Windows
2015-06-08 14:16:45 ----D---- C:\Windows\Minidump
2015-06-07 11:27:21 ----D---- C:\Program Files\Mozilla Maintenance Service
2015-06-06 12:31:22 ----RD---- C:\Program Files
2015-05-30 13:03:51 ----D---- C:\Windows\system32\catroot2
2015-05-15 20:14:03 ----SHD---- C:\Windows\Installer
2015-05-15 20:09:33 ----D---- C:\Windows\Tasks
2015-05-14 10:23:38 ----D---- C:\Program Files\Microsoft Silverlight

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 7680]
R0 fsbts;fsbts; C:\Windows\system32\Drivers\fsbts.sys [2012-08-15 44240]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2006-09-27 36560]
R0 tos_sps32;TOSHIBA tos_sps32 Service; C:\Windows\system32\DRIVERS\tos_sps32.sys [2008-01-21 285184]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2007-11-09 23640]
R1 F-Secure HIPS;F-Secure HIPS Driver; \??\C:\Program Files\F-Secure\HIPS\drivers\fshs.sys [2009-08-05 68064]
R1 FSES;F-Secure Email Scanning Driver; C:\Windows\System32\drivers\fses.sys [2010-12-22 36792]
R1 FSFW;F-Secure Firewall Driver; C:\Windows\System32\drivers\fsdfw.sys [2013-04-30 73224]
R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files\F-Secure\Anti-Virus\minifilter\fsvista.sys [2009-08-05 12384]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver; C:\Windows\system32\DRIVERS\rtlprot.sys [2007-04-23 25896]
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-28 1161888]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-27 2929664]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys [2013-07-10 145856]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-01-30 2058528]
R3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-03-29 20096]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-12-28 104448]
R3 RTL8187B;Síťový adaptér Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0; C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-12-26 290304]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 usbvideo;Chicony USB 2.0 Camera; C:\Windows\System32\Drivers\usbvideo.sys [2008-03-11 133888]
R3 UVCFTR;UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [2007-12-17 18432]
S2 DgiVecp;Team MFP Comm Driver; C:\Windows\System32\Drivers\DgiVecp.sys [2003-07-29 40448]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-03-29 21248]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-02-20 60416]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2006-10-05 9216]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-07-27 610304]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe [2009-08-05 215648]
R2 FSMA;FSMA; C:\Program Files\F-Secure\Common\FSMA32.EXE [2009-08-05 186976]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 TNaviSrv;TOSHIBA Navi Support Service; C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2008-01-21 83312]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2007-11-21 129632]
R2 TosCoSrv;TOSHIBA Power Saver; c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2008-01-17 431456]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service; c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-03 126976]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe [2010-05-28 522848]
R3 FSORSPClient;F-Secure ORSP Client; C:\Program Files\F-Secure\ORSP Client\fsorsp.exe [2013-06-07 60352]
S2 gupdate1ca830444619653;Služba Google Update (gupdate1ca830444619653); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-09 268464]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26 107912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-06-04 148080]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o preventivku

#2 Příspěvek od altrok »

Zdravim :bye:


:arrow: Odinstalujte :arrow: Doinstalujte MS Windows aktualizace.

:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

happysmile
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 17 pro 2011 15:11

Re: Prosím o preventivku

#3 Příspěvek od happysmile »

tady to je :)

# AdwCleaner v4.206 - Log vytvořen 12/06/2015 v 17:29:40
# Aktualizováno 01/06/2015 by Xplode
# Databáze : 2015-06-09.1 [Server]
# Operační system : Windows Vista (TM) Home Premium Service Pack 1 (x86)
# Uživatelské jméno : Frantisek - FRANTISEK-PC
# Spuštěno z : C:\Users\Frantisek\Downloads\adwcleaner_4.206.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ICQ6Toolbar
Složka Smazáno : C:\ProgramData\ICQ\ICQToolbar
Složka Smazáno : C:\ProgramData\Trymedia
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileViewPro
Složka Smazáno : C:\Program Files\video download converter
Složka Smazáno : C:\Program Files\FileViewPro
Složka Smazáno : C:\Program Files\download Manager
Složka Smazáno : C:\Program Files\BcoolApp
Složka Smazáno : C:\Program Files\VideoDownloadConverter_4z
Složka Smazáno : C:\Users\Frantisek\AppData\Local\BcoolApp
Složka Smazáno : C:\Users\Frantisek\AppData\Local\VideoDownloadConverter_4z
Složka Smazáno : C:\Users\Frantisek\AppData\LocalLow\BabylonToolbar
Složka Smazáno : C:\Users\Frantisek\Documents\video download converter
Soubor Smazáno : C:\eBay.lnk
Soubor Smazáno : C:\Users\Frantisek\AppData\Roaming\Mozilla\Firefox\Profiles\rtj11hcu.default\searchplugins\ask-web-search.xml
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_wlogin.icq.com_0.localstorage
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_wlogin.icq.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.icq.com_0.localstorage
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.icq.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download.icq.com_0.localstorage
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download.icq.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.icq.com_0.localstorage
Soubor Smazáno : C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.icq.com_0.localstorage-journal

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Klíč Smazáno : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Klíč Smazáno : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escortIEPane
Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Klíč Smazáno : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook
Klíč Smazáno : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.BHO
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.BHO.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.FBApi
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.FBApi.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.Sandbox
Klíč Smazáno : HKLM\SOFTWARE\Classes\CrossriderApp0011825.Sandbox.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110111181125}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220122182225}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{33333333-3333-3333-3333-330133183325}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550155185525}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660166186625}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770177187725}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440144184425}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110111181125}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110111181125}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111181125}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111181125}
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Klíč Smazáno : HKCU\Software\BabylonChromeExtension
Klíč Smazáno : HKCU\Software\BabylonToolbar
Klíč Smazáno : HKCU\Software\Cr_Installer
Klíč Smazáno : HKCU\Software\ICQ\ICQToolbar
Klíč Smazáno : HKCU\Software\InstallCore
Klíč Smazáno : HKCU\Software\InstalledBrowserExtensions
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKCU\Software\AppDataLow\Software\BcoolApp
Klíč Smazáno : HKLM\SOFTWARE\BabylonToolbar
Klíč Smazáno : HKLM\SOFTWARE\ICQ\ICQToolbar
Klíč Smazáno : HKLM\SOFTWARE\Trymedia Systems
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BcoolApp
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E931A51-A183-4E66-8562-D82896E74C67}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BcoolApp
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{0E931A51-A183-4E66-8562-D82896E74C67}

***** [ Prohlížeče ] *****

-\\ Internet Explorer v7.0.6001.18444

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Mozilla Firefox v38.0.5 (x86 cs)

[rtj11hcu.default\prefs.js] - Řádek Smazáno : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[rtj11hcu.default\prefs.js] - Řádek Smazáno : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");

-\\ Google Chrome v43.0.2357.124


*************************

AdwCleaner[R0].txt - [10691 bytů] - [15/02/2014 11:33:10]
AdwCleaner[R1].txt - [11696 bytů] - [12/06/2015 17:28:03]
AdwCleaner[S0].txt - [10844 bytů] - [12/06/2015 17:29:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10903 bytů] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o preventivku

#4 Příspěvek od altrok »

:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

happysmile
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 17 pro 2011 15:11

Re: Prosím o preventivku

#5 Příspěvek od happysmile »

FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Frantisek (administrator) on FRANTISEK-PC on 13-06-2015 19:40:11
Running from C:\Users\Frantisek\Desktop
Loaded Profiles: Frantisek (Available Profiles: Frantisek)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
(Chicony) C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Motive Communications, Inc.) C:\Program Files\TO2SSM\McciTrayApp.exe
(Motive Communications, Inc.) C:\Program Files\TO2WCM\McciTrayApp.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Matsushita Electric Industrial Co., Ltd.) C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSHDLL32.EXE
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(F-Secure Corporation) C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
(F-Secure Corporation) C:\Program Files\F-Secure\FWES\program\fsdfwd.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
(Microsoft Corporation) C:\Windows\System32\wsqmcons.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4911104 2008-01-29] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [NDSTray.exe] => NDSTray.exe
HKLM\...\Run: [Camera Assistant Software] => C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [413696 2007-10-25] (Chicony)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-01-17] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [712704 2008-01-22] (TOSHIBA Corporation)
HKLM\...\Run: [TO2SSM_McciTrayApp] => C:\Program Files\TO2SSM\McciTrayApp.exe [1473536 2008-08-15] (Motive Communications, Inc.)
HKLM\...\Run: [TO2WCM_McciTrayApp] => C:\Program Files\TO2WCM\McciTrayApp.exe [1473536 2008-01-30] (Motive Communications, Inc.)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\...\MountPoints2: {25185980-1e19-11df-9d63-001e336915a6} - D:\installer.exe
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [879616 2008-01-19] (Microsoft Corporation)
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-09-10] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2008-03-11]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk [2009-05-16]
ShortcutTarget: LUMIX Simple Viewer.lnk -> C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2008-03-11]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2008-03-11]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-1095335023-3757000401-259228406-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM -> {ADFC6A92-846C-461E-9BD2-577440CCFEED} URL = http://www.google.cz/search?q={searchTe ... urceid=ie7;
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1095335023-3757000401-259228406-1000 -> {70D46D94-BF1E-45ED-B567-48701376298E} URL = http://127.0.0.1:4664/search&s=jGookWHR ... earchTerms}
SearchScopes: HKU\S-1-5-21-1095335023-3757000401-259228406-1000 -> {ADFC6A92-846C-461E-9BD2-577440CCFEED} URL = http://www.google.cz/search?q={searchTe ... 1I7TSEA_cs
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25] (Sun Microsystems, Inc.)
Toolbar: HKU\S-1-5-21-1095335023-3757000401-259228406-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2009-01-18] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Frantisek\AppData\Roaming\Mozilla\Firefox\Profiles\rtj11hcu.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-09] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1209149.dll [2014-01-29] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1095335023-3757000401-259228406-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Frantisek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-10-27] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-17]

Chrome:
=======
CHR Profile: C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Wallet) - C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (http://s4.soccerstar.cz/) - C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbelebdlfbnomodchllocpdpldiebdpe [2013-02-05]
CHR HKLM\...\Chrome\Extension: [maeiepphbmmcgpcnalhdnobgijjphace] - C:\Users\Frantisek\AppData\Local\BcoolApp\Chrome\BcoolApp.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2007-12-25] (TOSHIBA CORPORATION) [File not signed]
R2 F-Secure Gatekeeper Handler Starter; C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe [215648 2009-08-05] (F-Secure Corporation)
R3 FSDFWD; C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe [522848 2010-05-28] (F-Secure Corporation)
R2 FSMA; C:\Program Files\F-Secure\Common\FSMA32.EXE [186976 2009-08-05] (F-Secure Corporation)
R3 FSORSPClient; C:\Program Files\F-Secure\ORSP Client\fsorsp.exe [60352 2013-06-07] (F-Secure Corporation)
S2 gupdate1ca830444619653; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-26] (Google Inc.)
R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
R2 TOSHIBA SMART Log Service; c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) [File not signed]
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 DgiVecp; C:\Windows\System32\Drivers\DgiVecp.sys [40448 2003-07-29] (DeviceGuys, Inc.) [File not signed]
R3 F-Secure Gatekeeper; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys [145856 2013-07-10] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files\F-Secure\HIPS\drivers\fshs.sys [68064 2009-08-05] (F-Secure Corporation)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [192056 2008-01-19] (Společnost Microsoft)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44240 2012-08-15] ()
R1 FSES; C:\Windows\System32\drivers\fses.sys [36792 2010-12-22] (F-Secure Corporation)
R1 FSFW; C:\Windows\System32\drivers\fsdfw.sys [73224 2013-04-30] (F-Secure Corporation)
R1 fsvista; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsvista.sys [12384 2009-08-05] ()
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1081912 2008-01-19] (Společnost Microsoft)
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36560 2006-09-27] (Sonic Solutions) [File not signed]
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [290304 2007-12-26] (Realtek Semiconductor Corporation )
R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider)
R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-13 19:40 - 2015-06-13 19:41 - 00014850 _____ C:\Users\Frantisek\Desktop\FRST.txt
2015-06-13 19:39 - 2015-06-13 19:40 - 00000000 ____D C:\FRST
2015-06-13 19:37 - 2015-06-13 19:37 - 00112640 _____ (forum.viry.cz) C:\Users\Frantisek\Downloads\Nepotvrzeno 861158.crdownload
2015-06-13 19:36 - 2015-06-13 19:36 - 00112640 _____ (forum.viry.cz) C:\Users\Frantisek\Downloads\Nepotvrzeno 290627.crdownload
2015-06-13 19:35 - 2015-06-13 19:35 - 01148416 _____ (Farbar) C:\Users\Frantisek\Desktop\FRST.exe
2015-06-12 21:03 - 2015-06-12 21:03 - 00000000 ____D C:\Program Files\Microsoft.NET
2015-06-12 21:02 - 2009-11-08 09:55 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-06-12 21:02 - 2009-11-08 09:55 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2015-06-12 21:02 - 2009-11-08 09:55 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2015-06-12 21:02 - 2009-11-08 09:55 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2015-06-12 21:02 - 2009-11-08 09:55 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2015-06-12 20:58 - 2008-04-18 07:30 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-06-12 20:58 - 2008-04-18 07:30 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-06-12 20:58 - 2008-04-18 04:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-06-12 20:58 - 2008-04-18 04:33 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-06-12 20:57 - 2015-06-12 21:19 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-12 20:55 - 2015-06-12 20:56 - 41182528 _____ (Garmin Ltd or its subsidiaries) C:\Users\Frantisek\Downloads\GarminExpress.exe
2015-06-12 20:47 - 2015-06-12 20:47 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_00_00.Wdf
2015-06-12 17:34 - 2015-06-12 17:34 - 00003832 _____ C:\Windows\PFRO.log
2015-06-12 17:21 - 2015-06-12 17:21 - 02231296 _____ C:\Users\Frantisek\Downloads\adwcleaner_4.206 (1).exe
2015-06-12 17:20 - 2015-06-12 17:20 - 02231296 _____ C:\Users\Frantisek\Downloads\adwcleaner_4.206.exe
2015-06-12 09:50 - 2015-06-12 09:50 - 00000954 _____ C:\Users\Frantisek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-12 09:50 - 2015-06-12 09:50 - 00000920 _____ C:\Users\Frantisek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-06-12 09:50 - 2015-06-12 09:50 - 00000000 ____D C:\Users\Frantisek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-12 09:47 - 2015-06-12 09:47 - 00000468 _____ C:\Windows\DtcInstall.log
2015-06-12 09:46 - 2015-06-12 09:46 - 00002022 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-11 23:16 - 2015-06-12 20:48 - 00015407 _____ C:\Windows\setupact.log
2015-06-11 23:16 - 2015-06-11 23:16 - 00000000 _____ C:\Windows\setuperr.log
2015-06-11 22:20 - 2015-06-11 22:20 - 00000000 ____D C:\Users\Frantisek\voip
2015-06-11 22:19 - 2015-06-11 22:30 - 00000000 ____D C:\Users\Frantisek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ
2015-06-11 22:16 - 2015-06-11 22:29 - 00000000 ____D C:\Users\Frantisek\AppData\Roaming\ICQM
2015-06-11 22:15 - 2015-06-11 22:16 - 37968904 _____ (ICQ) C:\Users\Frantisek\Downloads\icq_rfrset.exe
2015-06-11 21:56 - 2015-06-11 21:56 - 00000000 ____D C:\Users\Frantisek\AppData\Local\Skype
2015-06-08 17:31 - 2015-06-08 17:31 - 00016328 _____ C:\Users\Frantisek\Downloads\Prehled_prijimaciho_rizeni_na_web_XLS.xlsx
2015-06-04 17:36 - 2015-06-07 11:27 - 00000000 ____D C:\Program Files\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-13 19:21 - 2013-02-09 10:37 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-13 19:14 - 2012-03-23 15:25 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-13 18:34 - 2008-12-31 11:00 - 01257790 _____ C:\Windows\WindowsUpdate.log
2015-06-13 18:26 - 2006-11-02 12:33 - 01552258 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-13 18:19 - 2012-03-23 15:25 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-13 18:19 - 2009-03-15 13:37 - 00000542 _____ C:\Windows\Tasks\Scheduled scanning task.job
2015-06-13 18:19 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-13 18:19 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-13 18:19 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-13 08:51 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-13 08:25 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2015-06-12 22:09 - 2006-11-02 15:01 - 00032528 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\zh-TW
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\zh-CN
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\uk-UA
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\tr-TR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\th-TH
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sv-SE
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sr-Latn-CS
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sl-SI
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sk-SK
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ru-RU
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ro-RO
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pt-PT
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pt-BR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pl-PL
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\nl-NL
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\nb-NO
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\lv-LV
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\lt-LT
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ko-KR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ja-JP
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\it-IT
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\hu-HU
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\hr-HR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\he-IL
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\fr-FR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\fi-FI
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\et-EE
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\el-GR
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\bg-BG
2015-06-12 22:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ar-SA
2015-06-12 20:54 - 2012-03-12 20:46 - 00000400 ____H C:\Windows\Tasks\User_Feed_Synchronization-{0C6A973B-5A12-4270-913B-F833E95D6EEF}.job
2015-06-12 17:29 - 2014-02-15 11:33 - 00000000 ____D C:\AdwCleaner
2015-06-12 17:29 - 2010-02-24 11:37 - 00000000 ____D C:\ProgramData\ICQ
2015-06-12 09:48 - 2006-11-02 14:55 - 00001743 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-06-12 09:48 - 2006-11-02 14:50 - 00000749 ___RH C:\Windows\WindowsShell.Manifest
2015-06-12 09:48 - 2006-11-02 14:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-12 09:48 - 2006-11-02 13:18 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-12 09:47 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-12 09:47 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-12 09:47 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-12 09:47 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-12 09:47 - 2006-11-02 13:18 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades
2015-06-12 09:46 - 2008-03-11 13:07 - 00000000 ____D C:\Program Files\Google
2015-06-12 09:39 - 2006-11-02 14:47 - 00274976 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 23:26 - 2007-01-08 23:07 - 00000000 ____D C:\Windows\system32\cs
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\DigitalLocker
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Photo Gallery
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Defender
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Collaboration
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Calendar
2015-06-11 23:26 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Movie Maker
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\SLUI
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ias
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\com
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\MSAgent
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\L2Schemas
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\IME
2015-06-11 23:26 - 2006-11-02 13:18 - 00000000 ____D C:\Program Files\Common Files\System
2015-06-11 23:17 - 2008-03-11 12:30 - 00000000 ____D C:\Windows\system32\RTCOM
2015-06-11 22:41 - 2015-02-15 12:35 - 00000000 ____D C:\Program Files\Speechtech TTS
2015-06-11 22:25 - 2006-11-02 12:32 - 00101888 _____ (Infineon Technologies AG) C:\Windows\system32\ifxcardm.dll
2015-06-11 22:24 - 2006-11-02 12:32 - 00082432 _____ (Gemalto, Inc.) C:\Windows\system32\axaltocm.dll
2015-06-11 22:23 - 2009-12-22 14:42 - 00000000 ___RD C:\Program Files\Skype
2015-06-11 22:23 - 2009-12-22 14:41 - 00000000 ____D C:\ProgramData\Skype
2015-06-11 22:22 - 2009-12-22 14:42 - 00000000 ____D C:\Users\Frantisek\AppData\Roaming\Skype
2015-06-11 22:20 - 2008-12-31 11:18 - 00000000 ____D C:\Users\Frantisek
2015-06-10 19:10 - 2012-03-11 20:21 - 00000000 ____D C:\Program Files\trend micro
2015-06-10 18:29 - 2013-07-14 11:22 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 18:29 - 2006-11-02 12:24 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-06-09 20:21 - 2013-02-09 10:37 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-09 20:21 - 2012-03-15 19:41 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-09 18:39 - 2014-07-11 07:53 - 00001976 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-08 16:15 - 2009-01-09 15:26 - 00029696 _____ C:\Users\Frantisek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-08 14:16 - 2009-03-09 13:09 - 00000000 ____D C:\Windows\Minidump
2015-06-07 11:27 - 2013-03-06 13:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-05-14 10:23 - 2010-02-24 13:20 - 00000000 ____D C:\Program Files\Microsoft Silverlight

==================== Files in the root of some directories =======

2009-12-22 14:39 - 2009-11-24 22:05 - 2020136 _____ (Skype Technologies S.A.) C:\Program Files\SkypeSetup.exe
2014-06-24 21:31 - 2014-06-24 21:31 - 0000680 _____ () C:\Users\Frantisek\AppData\Local\d3d9caps.dat
2009-01-09 15:26 - 2015-06-08 16:15 - 0029696 _____ () C:\Users\Frantisek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-23 15:25 - 2014-09-23 15:25 - 0000000 _____ () C:\Users\Frantisek\AppData\Local\{10F27391-9D97-40DD-B395-8D73E658E987}
2009-12-22 14:47 - 2009-12-22 14:47 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Files to move or delete:
====================
C:\Users\Frantisek\mss32.dll


Some files in TEMP:
====================
C:\Users\Frantisek\AppData\Local\Temp\icqsetup.exe
C:\Users\Frantisek\AppData\Local\Temp\Quarantine.exe
C:\Users\Frantisek\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-13 18:25

==================== End of log ============================

additional:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by Frantisek at 2015-06-13 19:41:40
Running from C:\Users\Frantisek\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1095335023-3757000401-259228406-500 - Administrator - Disabled)
Frantisek (S-1-5-21-1095335023-3757000401-259228406-1000 - Administrator - Enabled) => C:\Users\Frantisek
Guest (S-1-5-21-1095335023-3757000401-259228406-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: F-Secure Profi Antivirus 9.01 (Disabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17}
AS: F-Secure Profi Antivirus 9.01 (Disabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: F-Secure Profi Antivirus 9.01 (Disabled) {2D7AC0A6-6241-D774-E168-461178D9686C}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader 8 - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-A80000000000}) (Version: 8.0.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.)
Apple Software Update (HKLM\...\{55FA89BD-21D3-42F7-9249-C94C0094A83C}) (Version: 1.0.0.7 - Apple Computer, Inc.)
ATI Catalyst Install Manager (HKLM\...\{63427619-C918-6F3C-7318-11DDA4975241}) (Version: 3.0.634.0 - ATI Technologies, Inc.)
Camera Assistant Software for Toshiba (HKLM\...\{37C866E4-AA67-4725-9E95-A39968DD7960}) (Version: 1.7.175.0123 - Chicony Electronics Co.,Ltd.)
Catalyst Control Center - Branding (HKLM\...\{D58A1E94-9EEA-4C6E-B9FB-D7C63DC6C941}) (Version: 1.00.0000 - ATI)
ccc-core-static (Version: 2007.0815.2326.40058 - Název společnosti:) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform)
Counter-Strike 1.6 (HKLM\...\{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}) (Version: 1.6 - )
Desktop SMS (HKLM\...\{5980B928-1C95-4B3E-957B-B02D8147FF9E}) (Version: 1.2.0 - IDM)
DVD MovieFactory for TOSHIBA (HKLM\...\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}) (Version: 5.51 - Ulead Systems, Inc.)
EMCO Malware Destroyer 6 (HKLM\...\{FB81C624-5E87-4120-9E47-779662D93937}_is1) (Version: - EMCO Software)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
ffdshow v1.1.3631 [2010-11-15] (HKLM\...\ffdshow_is1) (Version: 1.1.3631.0 - )
FileViewPro (HKLM\...\{29938C06-6962-4C27-A94C-25E4F424A665}_is1) (Version: 1.5 - Solvusoft Corporation)
F-Secure Profi Antivirus (HKLM\...\F-Secure Product 277) (Version: - )
F-Secure PSC Prerequisites (Version: 1.0.5 - F-Secure Corporation) Hidden
Google Desktop (HKLM\...\Google Desktop) (Version: 5.9.1005.12335 - Google)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.124 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
ICQ7.2 (HKLM\...\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}) (Version: 7.2 - ICQ)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: - )
Java(TM) 6 Update 3 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160030}) (Version: 1.6.0.30 - Sun Microsystems, Inc.)
LUMIX Simple Viewer (HKLM\...\{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}) (Version: 0.99.0000 - Panasonic)
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 CSY Language Pack (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 38.0.5 (x86 cs) (HKLM\...\Mozilla Firefox 38.0.5 (x86 cs)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
Návody TOSHIBA (HKLM\...\{0F4F4815-76AD-4B26-8763-72F3344041C2}) (Version: 7.36 - TOSHIBA)
O2 Internet Konfigurator (HKLM\...\O2 Internet Konfigurator) (Version: - )
O2 Průvodce nastavením bezdrátové sítě (HKLM\...\TO2WCM Wireless Connection Client) (Version: - )
OpenOffice.org 3.0 (HKLM\...\{564D0000-547B-4ED8-8070-85286CC8C9BF}) (Version: 3.0.9379 - OpenOffice.org)
PHOTOfunSTUDIO -viewer- (HKLM\...\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}) (Version: 1.00.000 - Panasonic)
Picasa 2 (HKLM\...\Picasa2) (Version: 2.0 - Google, Inc.)
Psaní všemi deseti 1.5 (HKLM\...\Psaní všemi deseti_is1) (Version: - Richard Šusta, David Vejchoda)
QuickTime (HKLM\...\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5559 - Realtek Semiconductor Corp.)
REALTEK RTL8187B Wireless LAN Driver (HKLM\...\{895722FE-25FE-4854-95AC-B0C42F9DBEDA}) (Version: Package:1.00.0026 Driver:6.1116.1226.2007 - )
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: - Realtek Semiconductor Corp.)
Realtek WiFi Protected Setup Library (HKLM\...\{02CA24DD-C8B0-4280-BE53-7862869C2EB1}) (Version: Package:1.00.0026 - REALTEK Semiconductor Corp.)
Skins (Version: 2007.0815.2326.40058 - ATI) Hidden
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.1.8.0 - Synaptics)
TOSHIBA Assist (HKLM\...\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version: 2.01.04 - TOSHIBA)
TOSHIBA ConfigFree (HKLM\...\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}) (Version: 7.1.27 - TOSHIBA Corporation)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.0.1.1.a - TOSHIBA Corporation)
TOSHIBA DVD PLAYER (HKLM\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 1.20.10 - TOSHIBA Corporation)
TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - Toshiba)
TOSHIBA Face Recognition (HKLM\...\InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}) (Version: 1.0.2.32 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM\...\{2883F6F5-0509-43F3-868C-D50330DD9DD3}) (Version: 2.00.06 - )
Toshiba Online Product Information (HKLM\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 1.00.0012 - TOSHIBA)
TOSHIBA Recovery Disc Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.0.0.1b - TOSHIBA)
TOSHIBA Software Modem (HKLM\...\TOSHIBA Software Modem) (Version: 2.1.77 (SM2177ALD04) - Agere Systems)
TOSHIBA Supervisor Password (HKLM\...\{4B1E87C3-00DE-4898-8E39-E390AAEF2391}) (Version: 2.00.03 - )
TOSHIBA Value Added Package (HKLM\...\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.1.14 - TOSHIBA Corporation)
TRDCReminder (HKLM\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0014 - TOSHIBA)
TRDCReminder (Version: 1.00.0014 - TOSHIBA) Hidden
TRORDCLauncher (HKLM\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: 1.0.0.1 - TOSHIBA)
TRORDCLauncher (Version: 1.0.0.1 - TOSHIBA) Hidden
Unity Web Player (HKU\S-1-5-21-1095335023-3757000401-259228406-1000\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version: - )
Xerox Phaser 3117 (HKLM\...\Xerox Phaser 3117) (Version: - )
Ztlumení jednotky CD/DVD (HKLM\...\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}) (Version: 2.02.01 - TOSHIBA)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1095335023-3757000401-259228406-1000_Classes\CLSID\{4052D303-74C5-49EA-BC6B-66099C8D4007}\InprocServer32 -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll (Google)
CustomCLSID: HKU\S-1-5-21-1095335023-3757000401-259228406-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Frantisek\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-1095335023-3757000401-259228406-1000_Classes\CLSID\{9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\localserver32 -> C:\PROGRA~1\Skype\Phone\Skype.exe No File

==================== Restore Points =========================

11-06-2015 21:52:39 Windows Vista Service Pack 1
11-06-2015 22:42:17 ????????? Counter-Strike 1.6
12-06-2015 10:00:31 Windows Update
12-06-2015 20:56:52 Garmin Express
12-06-2015 20:58:27 Windows Update
12-06-2015 21:02:18 Windows Update
12-06-2015 21:10:08 Garmin Express

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 12:23 - 2012-03-12 16:56 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0C3AF200-FADC-49E5-880E-DEE192C8B79A} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2008-01-19] (Společnost Microsoft)
Task: {0EED695E-15A1-429C-9E35-5A45E127AA0E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-09] (Adobe Systems Incorporated)
Task: {18677737-E3DD-4BA1-AB5C-4820FB60FF25} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {47308FFE-EFF1-4D26-B415-9BE476F91680} - System32\Tasks\{CA939BE4-6D2C-4046-9BFF-F270D5F8DC07} => C:\Program Files\Skype\Phone\Skype.exe
Task: {7F384B8E-8E0C-4057-B281-497A1AD59995} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
Task: {91A04BBA-72AC-4B2A-8D47-D5468AE9451C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {A832B3DE-B352-4947-A0D8-7DA9DA9C9DB7} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation)
Task: {BF1B681D-8070-4A2A-BDDB-271D46152ABE} - System32\Tasks\{20E03F72-AF86-4B2F-AE76-DAAA0E35DF13} => pcalua.exe -a F:\Setup.exe -d F:\
Task: {C51AF134-F0F8-410A-B1BA-A8F2EADC4922} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\servicing\vsp1ceip.exe [2008-01-19] (Microsoft Corporation)
Task: {CB983E2C-16D9-481F-9078-9480E5FF8CCC} - System32\Tasks\Scheduled scanning task => C:\Program Files\F-Secure\Anti-Virus\fsav.exe [2009-08-05] (F-Secure Corporation)
Task: {D6C8BD87-ACD3-449B-9AF3-E32FF38E594D} - System32\Tasks\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29] (Apple Computer, Inc.)
Task: {EDD33537-EB14-4DE4-8137-D8A37F5371AF} - System32\Tasks\{B802E4D7-9F29-45F9-ACB6-0EE91E610505} => pcalua.exe -a c:\Users\Frantisek\Downloads\Counter-Strike_1.5.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Scheduled scanning task.job => C:\PROGRA~1\F-Secure\ANTI-V~1\fsav.exeH /HARD /POLICY /SCHED /REPORT C:\PROGRA~1\F-Secure\ANTI-V~1\report.txt
Task: C:\Windows\Tasks\User_Feed_Synchronization-{0C6A973B-5A12-4270-913B-F833E95D6EEF}.job => C:\Windows\system32\msfeedssync.exe

==================== Loaded Modules (Whitelisted) ==============

2007-03-02 11:44 - 2007-03-02 11:44 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
2008-03-11 10:34 - 2007-07-27 23:26 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2007-12-14 22:28 - 2007-12-14 22:28 - 04726784 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2007-12-14 22:40 - 2007-12-14 22:40 - 00090112 _____ () C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll
2008-03-11 12:49 - 2006-10-10 12:44 - 00009728 _____ () C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll
2007-12-25 13:03 - 2007-12-25 13:03 - 00015184 _____ () C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll
2006-10-07 12:57 - 2006-10-07 12:57 - 00053248 _____ () c:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll
2008-12-31 11:01 - 2008-01-22 12:00 - 04624384 _____ () C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
2011-03-12 21:26 - 2010-11-15 21:30 - 08279552 _____ () C:\Program Files\ffdshow\ffdshow.ax
2009-03-15 13:30 - 2010-05-28 20:20 - 00207536 _____ () c:\program files\f-secure\daas2\daas2.dll
2011-06-09 11:43 - 2011-06-09 11:43 - 00030888 _____ () C:\Program Files\F-Secure\Anti-Virus\minifilter\hashlib_x86.dll
2009-03-15 13:29 - 2009-08-05 17:56 - 00036864 _____ () C:\Program Files\F-Secure\Anti-Virus\FSAVHRES.eng
2014-05-12 13:18 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-05-12 13:18 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Frantisek\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:981349EA

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1095335023-3757000401-259228406-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Frantisek\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
DNS Servers: 10.0.0.138

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Desktop SMS => C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
MSCONFIG\startupreg: F-Secure Manager => "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
MSCONFIG\startupreg: F-Secure TNB => "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: vProt => "C:\Program Files\AVG Secure Search\vprot.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [TCP Query User{12E40D40-4D1F-4C9B-A37F-DD2F420AA8AC}C:\program files\valve\hl.exe] => (Allow) C:\program files\valve\hl.exe
FirewallRules: [UDP Query User{DFA753DC-820E-47D8-880E-E430E9F4AA14}C:\program files\valve\hl.exe] => (Allow) C:\program files\valve\hl.exe
FirewallRules: [{A1BC61D0-452B-490F-BBDE-12E9E0EE2CC5}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{A11101CE-F883-49B2-8A29-BEAD5C0F3408}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{0AFAD6DF-494E-4D10-AB2C-24483D7A306D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6F004B13-DAE8-4C4A-9994-20A3A1213C41}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{899DFFE1-1FF2-4323-9E6E-3CDF00C235F5}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{40B27320-99E1-4546-BF14-1B438205B467}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/12/2015 10:09:22 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}

Error: (06/12/2015 09:50:19 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (3204) WindowsMail0: Zálohování bylo ukončeno, protože bylo zastaveno klientem nebo protože se nezdařilo připojení ke klientovi.

Error: (06/11/2015 11:28:25 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: Cílový soubor pro platformu Windows Feedback Platform (soubor DLL obsahující seznam problémů v tomto počítači, které vyžadují další sběr dat pro diagnostiku) nelze analyzovat. Kód chyby je 8014FFF9.

Error: (06/11/2015 11:12:56 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}

Error: (06/11/2015 11:11:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Chybující aplikace plugin-container.exe, verze 38.0.5.5623, časové razítko 0x5563c49a, chybující modul ntdll.dll, verze 6.0.6000.16386, časové razítko 0x4549bdc9, kód výjimky 0xc000000d, posun chyby 0x00088ea9,
ID procesu 0x5cc, čas spuštění aplikace 0xplugin-container.exe0.

Error: (06/11/2015 10:42:17 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {a7b83dd4-2b86-4f25-a280-a8a80f885c2e}

Error: (06/11/2015 10:31:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program _iu14D2N.tmp verze 51.1052.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení problémů.
ID procesu: 1a8c
Čas zahájení: 01d0a4848b6ec1e8
Čas ukončení: 62

Error: (06/11/2015 10:30:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program icqsetup.exe verze 8.3.7317.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení problémů.
ID procesu: 1e6c
Čas zahájení: 01d0a485352f7bc8
Čas ukončení: 16

Error: (06/11/2015 09:52:38 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {a7b83dd4-2b86-4f25-a280-a8a80f885c2e}

Error: (06/11/2015 09:52:37 PM) (Source: VSS) (EventID: 12293) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny zprostředkovatele stínové kopie {b5946137-7b9f-4925-af80-51abd60b20d5} došlo k chybě. Podrobnosti rutiny PostFinalCommitSnapshots({45808b02-a45b-4429-8e2f-53469bb5d606}, 1) [hr = 0x80042308].


Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet


System errors:
=============
Error: (06/13/2015 06:19:43 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (06/13/2015 06:19:34 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (11:48:44, 13.6.2015) bylo neočekávané.

Error: (06/13/2015 08:09:35 AM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (06/12/2015 10:09:21 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/12/2015 06:21:01 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (06/12/2015 06:20:50 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (18:13:26, 12.6.2015) bylo neočekávané.

Error: (06/12/2015 05:35:21 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (06/12/2015 05:29:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Windows Presentation Foundation Font Cache 3.0.0.02

Error: (06/12/2015 05:29:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Media Player Network Sharing1300001Restartovat službu

Error: (06/12/2015 05:29:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: F-Secure Anti-Virus Firewall Daemon1


Microsoft Office:
=========================
Error: (06/12/2015 10:09:22 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}

Error: (06/12/2015 09:50:19 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail3204WindowsMail0:

Error: (06/11/2015 11:28:25 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: 8014FFF9

Error: (06/11/2015 11:12:56 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}

Error: (06/11/2015 11:11:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.5.56235563c49antdll.dll6.0.6000.163864549bdc9c000000d00088ea95cc01d0a48b300dd3c8

Error: (06/11/2015 10:42:17 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005

Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {a7b83dd4-2b86-4f25-a280-a8a80f885c2e}

Error: (06/11/2015 10:31:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: _iu14D2N.tmp51.1052.0.01a8c01d0a4848b6ec1e862

Error: (06/11/2015 10:30:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: icqsetup.exe8.3.7317.01e6c01d0a485352f7bc816

Error: (06/11/2015 09:52:38 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005

Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {a7b83dd4-2b86-4f25-a280-a8a80f885c2e}

Error: (06/11/2015 09:52:37 PM) (Source: VSS) (EventID: 12293) (User: )
Description: {b5946137-7b9f-4925-af80-51abd60b20d5}PostFinalCommitSnapshots({45808b02-a45b-4429-8e2f-53469bb5d606}, 1)0x80042308

Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet


CodeIntegrity Errors:
===================================
Date: 2015-06-13 19:41:01.582
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:41:01.180
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:41:00.779
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:41:00.274
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:59.774
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:59.346
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:58.885
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:58.482
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:45.114
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\F-Secure\HIPS\drivers\fshs.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-06-13 19:40:44.780
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\F-Secure\HIPS\drivers\fshs.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual-Core Processor TK-57
Percentage of memory in use: 55%
Total physical RAM: 1916.89 MB
Available physical RAM: 857.98 MB
Total Pagefile: 4081.05 MB
Available Pagefile: 2882.72 MB
Total Virtual: 2047.88 MB
Available Virtual: 1897.75 MB

==================== Drives ================================

Drive c: (Vista) (Fixed) (Total:74.37 GB) (Free:24.58 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (Data) (Fixed) (Total:73.21 GB) (Free:69.11 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: 2FF790BA)
Partition 1: (Not Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Active) - (Size=74.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=73.2 GB) - (Type=07 NTFS)

==================== End of log ============================

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o preventivku

#6 Příspěvek od altrok »

:arrow: Odinstalujte starou a zranitelnou verzi javy Java(TM) 6 Update 3. Pokud javu potrebujete, pak nainstalujte novou z java.com - pozor na adware pri jeji instalaci http://forum.viry.cz/viewtopic.php?p=1374438#p1374438 . Z hlediska bezpecnosti (exploity) je lepsi ji nemit.

:arrow: Otestujte na virustotal.com C:\Users\Frantisek\mss32.dll - pokud uz byl soubor otestovany, zvolte Reanalyse. Do pristiho prispevku dejte link (odkaz) s vysledky analyzy.

:arrow: Velice doporucuju doinstalovat MS Windows aktualizace (Internet Explorer 9 apod.).


  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    HKU\S-1-5-21-1095335023-3757000401-259228406-1000\...\MountPoints2: {25185980-1e19-11df-9d63-001e336915a6} - D:\installer.exe
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2008-03-11]
    
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    
    CHR HKLM\...\Chrome\Extension: [maeiepphbmmcgpcnalhdnobgijjphace] - C:\Users\Frantisek\AppData\Local\BcoolApp\Chrome\BcoolApp.crx [Not Found]
    
    S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
    S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
    S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
    S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
    S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
    S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
    
    2015-06-13 19:40 - 2015-06-13 19:41 - 00014850 _____ C:\Users\Frantisek\Desktop\FRST.txt
    2015-06-13 19:37 - 2015-06-13 19:37 - 00112640 _____ (forum.viry.cz) C:\Users\Frantisek\Downloads\Nepotvrzeno 861158.crdownload
    2015-06-13 19:36 - 2015-06-13 19:36 - 00112640 _____ (forum.viry.cz) C:\Users\Frantisek\Downloads\Nepotvrzeno 290627.crdownload
    2015-06-12 17:21 - 2015-06-12 17:21 - 02231296 _____ C:\Users\Frantisek\Downloads\adwcleaner_4.206 (1).exe
    2015-06-12 17:20 - 2015-06-12 17:20 - 02231296 _____ C:\Users\Frantisek\Downloads\adwcleaner_4.206.exe
    2015-06-12 17:29 - 2014-02-15 11:33 - 00000000 ____D C:\AdwCleaner
    2014-06-24 21:31 - 2014-06-24 21:31 - 0000680 _____ () C:\Users\Frantisek\AppData\Local\d3d9caps.dat
    
    CustomCLSID: HKU\S-1-5-21-1095335023-3757000401-259228406-1000_Classes\CLSID\{9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\localserver32 -> C:\PROGRA~1\Skype\Phone\Skype.exe No File
    Task: {BF1B681D-8070-4A2A-BDDB-271D46152ABE} - System32\Tasks\{20E03F72-AF86-4B2F-AE76-DAAA0E35DF13} => pcalua.exe -a F:\Setup.exe -d F:\
    Task: {EDD33537-EB14-4DE4-8137-D8A37F5371AF} - System32\Tasks\{B802E4D7-9F29-45F9-ACB6-0EE91E610505} => pcalua.exe -a c:\Users\Frantisek\Downloads\Counter-Strike_1.5.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    AlternateDataStreams: C:\ProgramData\TEMP:981349EA
    EmptyTemp:
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět