Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-02-2016 01
Ran by Administrator (administrator) on PC-REINST (23-02-2016 12:02:29)
Running from C:\Documents and Settings\Administrator\Plocha
Loaded Profiles: Administrator (Available Profiles: Uzivatel & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Trend Micro Inc.) C:\Documents and Settings\Administrator\Dokumenty\Downloads\hijackthis.exe
(forum.viry.cz) C:\Documents and Settings\Administrator\Plocha\FRSTLauncher.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [29831168 2008-05-14] (VIA Technologies, Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [Print2PDF Print Monitor] => C:\Program Files\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE [472728 2012-09-27] (CANON INC.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [WrtMon.exe] => C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe [20480 2006-09-20] ()
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2007-06-27] (ATI Technologies Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{13B882FF-DE99-44FF-8EC2-B1A158D79AA6}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
URLSearchHook: [S-1-5-21-1292428093-1417001333-682003330-500] ATTENTION => Default URLSearchHook is missing
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-04] (Oracle Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll [2015-01-15] ()
FF Plugin: @cuminas.jp/DjVuPlugin -> C:\Program Files\Cuminas\Document Express DjVu Plug-in\npdjvu.dll [2015-02-17] (Cuminas Corporation)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-04] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @software602.cz/602XML Filler -> C:\Program Files\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-10-08] [not signed]
Chrome:
=======
CHR Profile: C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-06]
CHR Extension: (Disk Google) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-06]
CHR Extension: (YouTube) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-06]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-06]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-06]
CHR Extension: (Bitdefender QuickScan) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2016-02-23]
CHR Extension: (Gmail) - C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-06]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [520192 2007-06-29] () [File not signed]
S2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1983936 2015-11-20] (ESET)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [205800 2015-11-20] (ESET)
S1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [146024 2015-11-20] (ESET)
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [127496 2015-11-20] (ESET)
S3 monfilt; C:\WINDOWS\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S2 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [13120 2013-08-25] ()
S3 VIAHdAudAddService; C:\WINDOWS\System32\drivers\viahduaa.sys [238080 2008-05-08] (VIA Technologies, Inc.)
S3 catchme; \??\C:\DOCUME~1\Uzivatel\LOCALS~1\Temp\catchme.sys [X]
S4 IntelIde; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-23 12:02 - 2016-02-23 12:02 - 00009230 _____ C:\Documents and Settings\Administrator\Plocha\FRST.txt
2016-02-23 12:01 - 2016-02-23 12:02 - 00000000 ____D C:\FRST
2016-02-23 12:00 - 2016-02-23 11:59 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Administrator\Plocha\FRSTLauncher.exe
2016-02-23 12:00 - 2016-02-23 11:57 - 01722368 _____ (Farbar) C:\Documents and Settings\Administrator\Plocha\FRST.exe
2016-02-23 11:59 - 2016-02-23 11:59 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Administrator\Dokumenty\FRSTLauncher.exe
2016-02-23 11:45 - 2016-02-23 11:45 - 00000000 ___SD C:\ComboFix
2016-02-23 11:36 - 2016-02-23 11:36 - 00000000 ____D C:\Documents and Settings\Uzivatel\Data aplikací\QuickScan
2016-02-23 11:13 - 2016-02-23 11:13 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\QuickScan
2016-02-23 11:11 - 2016-02-23 11:11 - 00000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
2016-02-23 11:05 - 2016-02-23 11:05 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\GHISLER
2016-02-23 11:03 - 2016-02-23 11:03 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-02-23 11:03 - 2016-02-23 11:03 - 00000079 _____ C:\WINDOWS\wininit.ini
2016-02-23 11:02 - 2016-02-23 11:02 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Opera Software
2016-02-23 11:02 - 2016-02-23 11:02 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Opera Software
2016-02-23 11:02 - 2016-02-23 11:02 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\GHISLER
2016-02-17 16:12 - 2016-02-17 16:12 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2016-02-17 16:09 - 2016-02-23 12:02 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\temp
2016-02-17 16:09 - 2016-02-17 16:09 - 00008575 _____ C:\ComboFix.txt
2016-02-17 16:09 - 2016-02-17 16:09 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2016-02-17 16:09 - 2016-02-17 16:09 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\temp
2016-02-17 16:01 - 2011-06-26 07:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2016-02-17 16:01 - 2010-11-07 18:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2016-02-17 16:01 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00098816 _____ C:\WINDOWS\sed.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00080412 _____ C:\WINDOWS\grep.exe
2016-02-17 16:01 - 2000-08-31 01:00 - 00068096 _____ C:\WINDOWS\zip.exe
2016-02-17 16:00 - 2016-02-23 11:43 - 00000000 ____D C:\Qoobox
2016-02-17 16:00 - 2016-02-17 16:08 - 00000000 ____D C:\WINDOWS\erdnt
2016-02-17 16:00 - 2016-02-17 16:00 - 00000000 ___RD C:\Documents and Settings\Uzivatel\Nabídka Start\Programy\Nástroje pro správu
2016-02-17 16:00 - 2016-02-17 16:00 - 00000000 ___RD C:\Documents and Settings\Uzivatel\Dokumenty\Filmy
2016-02-17 14:22 - 2016-02-17 14:22 - 00050705 _____ C:\Documents and Settings\Uzivatel\Plocha\ob-19.pdf
2016-02-16 18:10 - 2016-02-16 18:10 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-16 18:10 - 2016-02-16 18:10 - 00000000 ____D C:\Documents and Settings\NetworkService\Nabídka Start\Programy
2016-02-16 18:10 - 2016-02-16 18:10 - 00000000 ____D C:\Documents and Settings\NetworkService\Nabídka Start
2016-02-16 18:10 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Documents and Settings\All Users\Plocha\Post Win10 Spybot-install.exe
2016-02-16 18:08 - 2016-02-18 17:46 - 00065536 _____ C:\WINDOWS\system32\config\SpybotSD.evt
2016-02-16 18:07 - 2016-02-23 11:03 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2016-02-15 13:23 - 2016-02-15 13:23 - 00090112 _____ C:\WINDOWS\Minidump\Mini021516-01.dmp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-23 12:02 - 2016-01-06 12:13 - 00000000 ____D C:\Documents and Settings\Administrator\Plocha
2016-02-23 12:01 - 2016-01-06 12:13 - 00000000 ___HD C:\Documents and Settings\Administrator\Local Settings\Data aplikací
2016-02-23 11:59 - 2016-01-06 12:13 - 00000000 ____D C:\Documents and Settings\Administrator\Dokumenty
2016-02-23 11:48 - 2016-01-06 12:13 - 00208438 _____ C:\WINDOWS\ntbtlog.txt
2016-02-23 11:47 - 2008-04-14 13:00 - 00012984 _____ C:\WINDOWS\system32\wpa.dbl
2016-02-23 11:46 - 2014-09-16 21:11 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2016-02-23 11:46 - 2014-09-16 20:50 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-23 11:46 - 2014-09-16 20:24 - 00000178 ___SH C:\Documents and Settings\Uzivatel\ntuser.ini
2016-02-23 11:46 - 2014-09-16 20:23 - 00032478 _____ C:\WINDOWS\SchedLgU.Txt
2016-02-23 11:46 - 2014-09-16 20:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-23 11:45 - 2014-09-16 20:24 - 00000000 ____D C:\Documents and Settings\Uzivatel\Local Settings\Temp
2016-02-23 11:39 - 2014-10-02 13:01 - 00000408 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1412251274.job
2016-02-23 11:38 - 2014-09-16 21:32 - 00000228 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-02-23 11:38 - 2014-09-16 20:50 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-23 11:36 - 2014-09-16 20:24 - 00000000 __RHD C:\Documents and Settings\Uzivatel\Data aplikací
2016-02-23 11:32 - 2016-01-06 12:13 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2016-02-23 11:11 - 2016-01-06 12:13 - 00000000 ____D C:\Documents and Settings\Administrator\Oblíbené položky
2016-02-23 11:11 - 2016-01-06 12:13 - 00000000 ____D C:\Documents and Settings\Administrator
2016-02-23 11:03 - 2014-09-16 22:09 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-02-23 11:03 - 2014-09-16 22:09 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-02-23 11:02 - 2016-01-06 12:13 - 00000000 __RHD C:\Documents and Settings\Administrator\Data aplikací
2016-02-23 10:38 - 2015-10-29 09:33 - 00000360 _____ C:\WINDOWS\Tasks\Canon OIP Product Extended Survey Program.job
2016-02-23 10:15 - 2014-10-02 13:02 - 00000000 ____D C:\Documents and Settings\Uzivatel\Data aplikací\602Installer
2016-02-18 17:46 - 2014-10-02 13:06 - 00131072 _____ C:\WINDOWS\system32\config\OAlerts.evt
2016-02-18 17:40 - 2014-10-02 13:31 - 00000000 ____D C:\Documents and Settings\Uzivatel\Dokumenty\Soubory aplikace Outlook
2016-02-18 14:48 - 2014-09-16 20:24 - 00000000 ___RD C:\Documents and Settings\Uzivatel\Dokumenty
2016-02-17 16:12 - 2014-09-16 22:09 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-02-17 16:09 - 2014-09-16 22:09 - 00000000 ___HD C:\Documents and Settings\Default User
2016-02-17 16:08 - 2008-04-14 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-02-17 16:00 - 2014-09-16 20:24 - 00000000 ___RD C:\Documents and Settings\Uzivatel\Nabídka Start\Programy
2016-02-17 14:52 - 2014-09-16 20:24 - 00000000 ___RD C:\Documents and Settings\Uzivatel\Dokumenty\Obrázky
2016-02-17 14:22 - 2014-09-16 20:24 - 00000000 ____D C:\Documents and Settings\Uzivatel\Plocha
2016-02-17 01:46 - 2014-09-16 20:24 - 00000000 ___HD C:\Documents and Settings\Uzivatel\Local Settings\Data aplikací
2016-02-16 18:10 - 2014-09-16 20:23 - 00000000 __SHD C:\Documents and Settings\NetworkService
2016-02-16 03:04 - 2014-09-16 21:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-16 03:00 - 2014-09-16 21:07 - 144254680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-15 14:47 - 2014-09-16 20:51 - 00001819 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome.lnk
2016-02-15 14:47 - 2014-09-16 20:51 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2016-02-15 13:23 - 2014-12-17 16:43 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-15 10:27 - 2014-10-02 13:01 - 00000000 ____D C:\Program Files\Opera
2016-02-08 15:00 - 2014-09-16 21:32 - 00000222 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-01-28 16:19 - 2015-01-05 12:23 - 00014042 _____ C:\Documents and Settings\Uzivatel\Plocha\members_cooperative.csv
2016-01-28 16:14 - 2015-08-04 11:44 - 00007725 _____ C:\Documents and Settings\Uzivatel\Plocha\svazdruzstev.csv
2016-01-28 16:09 - 2015-07-16 13:15 - 00005370 _____ C:\Documents and Settings\Uzivatel\Plocha\a.csv
2016-01-27 10:49 - 2014-09-16 22:03 - 00000000 ___HD C:\WINDOWS\inf
2016-01-26 09:51 - 2014-10-08 10:51 - 00000000 ____D C:\Exekuce
==================== Files in the root of some directories =======
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:298.09 GB) (Free:278.76 GB) NTFS ==>[drive with boot components (Windows XP)]
Available physical RAM: 1582.68 MB
Total physical RAM: 2047.11 MB
Percentage of memory in use: 22%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 298.1 GB) (Disk ID: 6F006F00)
Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_20_0_0_267_pepper.exe
Task: C:\WINDOWS\Tasks\Canon OIP Product Extended Survey Program.job => C:\Program Files\Canon\OIPPESP\Cnpspcnt.exe6/Config C:\Program Files\Canon\OIPPESP\CnpspCfg.xml
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1412251274.job => C:\Program Files\Opera\launcher.exe
Task: C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET NOD32 Antivirus 9.0.351.2 (Enabled - Up to date) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Administrator\Plocha" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"="C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe:*:Enabled:Google Chrome"
"C:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"C:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Common Files\\soft602\\langserv.exe"="C:\\Program Files\\Common Files\\soft602\\langserv.exe:*:Enabled:Software602 Spell Checker"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
a ještě log z hijackthis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:49:50, on 23.2.2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [MFNetworkScanUtility] C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
--
End of file - 5043 bytes





Přispějete na provoz fóra?