Ahoj, dostal se mi do počítače virus HTML/Refresh.BC trojský kůň a nedaří se mi ho odstranit. Prosím Vás o pomoc. Díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-02-2016
Ran by User (administrator) on USER-PC (29-02-2016 12:31:02)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User & DefaultAppPool)
Platform: Microsoft Windows 10 Home Version 1511 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Prolific Technology Inc.) C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
() C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD13\PowerDVD13Agent.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Logitech Inc.) C:\Program Files\Logitech\Profiler\LWEMon.exe
() C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
() C:\Users\User\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\User\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-10] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2008-03-17] (CANON INC.)
HKLM\...\Run: [Adobe_ID0ENQBO] => C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [378224 2008-08-15] (Adobe Systems Incorporated)
HKLM\...\Run: [NBKeyScan] => C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2010-06-29] (Nullsoft, Inc.)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3508624 2012-01-04] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [336992 2012-08-24] (Power Software Ltd)
HKLM\...\Run: [PowerDVD13Agent] => C:\Program Files\CyberLink\PowerDVD13\PowerDVD13Agent.exe [517144 2013-07-05] (CyberLink Corp.)
HKLM\...\Run: [TrueImageMonitor.exe] => C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2615624 2007-10-23] (Acronis)
HKLM\...\Run: [AcronisTimounterMonitor] => C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [906648 2007-10-23] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [140568 2007-10-23] (Acronis)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5089480 2015-07-08] (ESET)
HKLM\...\Run: [FileZilla Server Interface] => C:\Program Files\FileZilla Server\FileZilla Server Interface.exe [2539984 2015-11-30] (FileZilla Project)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Profiler\lwemon.exe [77824 2003-08-07] (Logitech Inc.)
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [KiesHelper] => C:\Program Files\Samsung\Kies\KiesHelper.exe [937872 2012-01-04] (Samsung)
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [KiesPDLR] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-01-04] ()
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [Google Update] => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-05] (Google Inc.)
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [721504 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\User\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\User\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6638296 2016-02-12] (Piriform Ltd)
Lsa: [Authentication Packages] msv1_0 relog_ap
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\..\Interfaces\{058b97d8-7f2e-4e1a-ae76-a56aca455eb0}: [NameServer] 192.168.1.1,192.168.1.0
Internet Explorer:
==================
HKU\S-1-5-21-1951563654-3073323279-456428730-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {323F3B04-0912-4AF4-8345-EFB8463D7326} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {463BCB82-336B-4F54-9A2E-8C53ABD414E2} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {56B424C8-5590-4AC8-899F-CF8C5172095F} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {59DE134B-B2E4-4B62-9DB7-B4CD9A94D69E} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {68AF5C5F-0BF4-4593-A00A-DD4474D87CEE} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {8B0C8882-1F84-4F3F-8ADD-FE25259C4572} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {94A5CC35-6D8F-466E-8227-7BD6E525F075} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {B03DF80E-D367-4271-84DB-C18A18725CB5} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
SearchScopes: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> {C138B8A1-611C-41CE-87C5-0F96FBB86697} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO: WebTransBHO Class -> {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} -> C:\ProgramData\LangSoft\WebIE.dll [2009-11-20] ()
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04] (Sun Microsystems, Inc.)
BHO: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll [2009-11-20] ()
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-1951563654-3073323279-456428730-1000 -> Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tjijti7m.default-1456665912529
FF Homepage: hxxps://www.seznam.cz/
about:preferences
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-10] ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-05-04] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-12-13] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-12-13] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1951563654-3073323279-456428730-1000: @tools.google.com/Google Update;version=3 -> C:\Users\User\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-1951563654-3073323279-456428730-1000: @tools.google.com/Google Update;version=9 -> C:\Users\User\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-1951563654-3073323279-456428730-1000: google.com/WidevineMediaOptimizer -> C:\Users\User\AppData\Roaming\IDM\bin\npwidevinemediaoptimizer.dll [2014-06-09] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011-05-04] (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2010-12-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2010-06-29] (Nullsoft, Inc.)
FF Extension: Adblock Plus - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tjijti7m.default-1456665912529\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-28]
FF Extension: Seznam lištička - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tjijti7m.default-1456665912529\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2016-02-28]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=13.2.0.4&sap=hp","hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=14.2.0.1&pid=avg&sg=&sap=hp","hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=15.2.0.5&pid=avg&sg=0&sap=hp","hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=18.0.5.292&sap=hp
hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=14.2.0.1&pid=avg&sg=0&sap=hp
hxxp://isearch.avg.com/?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&pr=sa&d=2012-11-25 03:14:16&v=15.2.0.5&pid=avg&sg=0&sap=hp","hxxp://isearch.avg.com?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&coid=&cmpid=&pr=sa&d=2012-11-25 03:14:16&v=18.1.0.443&pid=avg&sg=0&sap=hp","hxxp://isearch.avg.com?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&coid=&cmpid=&pr=sa&d=2012-11-25 03:14:16&v=18.1.7.644&pid=avg&sg=0&sap=hp","hxxp://isearch.avg.com?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&coid=&cmpid=&pr=sa&d=2012-11-25 03:14:16&v=18.1.9.786&pid=avg&sg=0&sap=hp","hxxp://isearch.avg.com?cid={02BFDB91-64A6-4183-922E-F9422B50E1EC}&mid=166dffff68bc47d0bcded1409bb4951a-88cee84a07759e4f40a090de8c2fc553edb85675&lang=cs&ds=st011&coid=&cmpid=&pr=sa&d=2012-11-25 03:14:16&v=18.1.9.799&pid=avg&sg=0&sap=hp"
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\48.0.2564.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\48.0.2564.116\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\48.0.2564.116\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Email) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-08-13]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-02-10]
CHR Extension: (Page Refresh) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmooaemjmediafeacjplpbpenjnpcneg [2016-01-08]
CHR Extension: (Super Auto Refresh) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkhjakkgopekjlempoplnjclgedabddk [2015-09-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-11-16]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [427288 2007-10-23] (Acronis)
S3 Adobe Version Cue CS4; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [288112 2010-02-03] (Adobe Systems Incorporated)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-11-20] (Advanced Micro Devices, Inc.) [File not signed]
R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-07-05] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; C:\Program Files\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-07-05] (CyberLink)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1353720 2015-07-08] (ESET)
S3 FileZilla Server; C:\Program Files\FileZilla Server\FileZilla Server.exe [827856 2015-11-30] (FileZilla Project)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [915600 2014-12-13] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18186896 2014-12-13] (NVIDIA Corporation)
R2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.) [File not signed]
R3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [657408 2009-10-27] (Nokia) [File not signed]
R2 TryAndDecideService; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [495832 2007-10-23] ()
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [280376 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23256 2015-10-30] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [121208 2012-05-02] (SlySoft, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices)
R3 AVerA706; C:\WINDOWS\system32\DRIVERS\AVerA706.sys [1169920 2009-06-10] (AVerMedia TECHNOLOGIES, Inc.)
S3 AVerBDA3x; C:\WINDOWS\System32\DRIVERS\AVerBDA3x.sys [1183744 2007-08-29] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R1 DVDHelp; C:\WINDOWS\System32\drivers\DVDHelp.sys [25624 2015-08-10] ()
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [202704 2015-07-14] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [199608 2015-07-14] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [144536 2015-07-14] (ESET)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
R2 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [185176 2015-07-14] (ESET)
R1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [46656 2015-07-14] (ESET)
R0 epfwwfp; C:\WINDOWS\System32\DRIVERS\epfwwfp.sys [60552 2015-07-14] (ESET)
S3 fdrawcmd; C:\Windows\system32\drivers\fdrawcmd.sys [27896 2010-04-24] (simonowen.com)
R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [73728 2008-03-31] (EZB Systems, Inc.) [File not signed]
R3 L1E; C:\WINDOWS\System32\drivers\L1E62x86.sys [55296 2015-10-30] (Atheros Communications, Inc.)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad32v.sys [32912 2014-11-22] (NVIDIA Corporation)
S3 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2010-07-27] (microOLAP Technologies LTD)
R1 SCDEmu; C:\WINDOWS\system32\Drivers\SCDEmu.sys [113104 2012-08-24] (Power Software Ltd)
R0 tdrpman; C:\WINDOWS\System32\DRIVERS\tdrpman.sys [368736 2013-11-06] (Acronis)
R2 tifsfilter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [44384 2013-11-06] (Acronis)
R3 VIAHdAudAddService; C:\WINDOWS\system32\drivers\viahduaa.sys [575184 2015-06-22] (VIA Technologies, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37400 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [246104 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [98648 2015-10-30] (Microsoft Corporation)
R3 WmBEnum; C:\WINDOWS\system32\drivers\WmBEnum.sys [10144 2003-05-14] (Logitech Inc.)
R3 WmXlCore; C:\WINDOWS\system32\drivers\WmXlCore.sys [44288 2003-05-14] (Logitech Inc.)
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [76560 2013-07-06] (CyberLink Corp.)
S3 Epfwndis; \SystemRoot\system32\DRIVERS\Epfwndis.sys [X]
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-29 12:31 - 2016-02-29 12:31 - 00027725 _____ C:\Users\User\Desktop\FRST.txt
2016-02-29 12:30 - 2016-02-29 12:31 - 00000000 ____D C:\FRST
2016-02-29 12:24 - 2016-02-29 12:29 - 00112640 _____ (forum.viry.cz) C:\Users\User\Desktop\FRSTLauncher.exe
2016-02-29 12:21 - 2016-02-29 12:21 - 01107968 _____ C:\Users\User\Downloads\RSIT.exe
2016-02-29 12:09 - 2016-02-29 12:09 - 01722368 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2016-02-29 11:35 - 2016-02-29 11:35 - 00001034 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-02-29 11:35 - 2016-02-29 11:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-02-29 11:35 - 2016-02-29 11:35 - 00000000 ____D C:\Program Files\CCleaner
2016-02-29 11:34 - 2016-02-29 11:34 - 14188232 _____ C:\Users\User\Downloads\ccsetup515.exe
2016-02-28 14:56 - 2016-02-28 14:56 - 00182224 ____H C:\WINDOWS\system32\mlfcache.dat
2016-02-28 14:54 - 2016-02-28 14:54 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
2016-02-28 14:54 - 2016-02-28 14:54 - 00002495 _____ C:\Users\Public\Desktop\Safari.lnk
2016-02-28 14:54 - 2016-02-28 14:54 - 00000000 ____D C:\Program Files\Safari
2016-02-28 14:53 - 2016-02-28 14:53 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-02-28 14:53 - 2016-02-28 14:53 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-02-28 14:53 - 2016-02-28 14:53 - 00000000 ____D C:\Program Files\Apple Software Update
2016-02-28 14:25 - 2016-02-28 14:25 - 00000000 ____D C:\Users\User\Desktop\Původní data aplikace Firefox
2016-02-12 01:14 - 2016-02-28 14:02 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-02-10 02:31 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-10 02:31 - 2016-01-27 07:15 - 05798240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-10 02:31 - 2016-01-27 07:15 - 01560848 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-10 02:31 - 2016-01-27 07:15 - 01541792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-10 02:31 - 2016-01-27 07:12 - 00279376 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-10 02:31 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-02-10 02:31 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-10 02:31 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-10 02:31 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-10 02:31 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-10 02:31 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-10 02:31 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-10 02:31 - 2016-01-27 06:47 - 01714016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-10 02:31 - 2016-01-27 06:47 - 00483680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-10 02:31 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msorcl32.dll
2016-02-10 02:31 - 2016-01-27 06:15 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-10 02:31 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-10 02:31 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-10 02:31 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-02-10 02:31 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-10 02:31 - 2016-01-27 06:11 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-10 02:31 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-10 02:31 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-10 02:31 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-10 02:31 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-10 02:31 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-10 02:31 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-10 02:31 - 2016-01-27 05:58 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-10 02:31 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-10 02:31 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-10 02:31 - 2016-01-27 05:52 - 02977280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-10 02:31 - 2016-01-27 05:51 - 01903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-10 02:31 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-10 02:31 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-10 02:31 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-10 02:31 - 2016-01-27 05:49 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-10 02:31 - 2016-01-27 05:44 - 00942592 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-10 02:31 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-06 00:13 - 2016-02-06 02:09 - 00000000 ____D C:\Users\User\AppData\Local\Deployment
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-29 12:26 - 2012-03-29 13:05 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-29 12:26 - 2010-11-27 03:25 - 00000000 ____D C:\Users\User\Documents\Nová složka
2016-02-29 12:13 - 2015-05-17 00:39 - 00000974 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1951563654-3073323279-456428730-1000UA.job
2016-02-29 12:13 - 2015-05-17 00:39 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1951563654-3073323279-456428730-1000Core.job
2016-02-29 11:56 - 2015-11-04 22:16 - 00000000 ____D C:\Users\User\AppData\Roaming\MPC-HC
2016-02-29 11:56 - 2015-08-30 00:51 - 00000000 ____D C:\Users\User\AppData\Roaming\BitTorrent
2016-02-29 11:56 - 2014-03-18 17:38 - 00000000 ____D C:\ProgramData\VSO
2016-02-29 11:56 - 2012-10-29 22:15 - 00000000 ____D C:\Users\User\AppData\Roaming\FileZilla
2016-02-29 11:56 - 2010-04-23 22:28 - 00000000 ____D C:\Users\User\AppData\Roaming\TeamViewer
2016-02-29 11:56 - 2009-12-26 12:34 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2016-02-29 11:56 - 2009-11-17 02:46 - 00000000 ____D C:\Users\User\AppData\Roaming\Vso
2016-02-29 11:47 - 2015-12-12 08:14 - 00000000 ___DC C:\WINDOWS\Panther
2016-02-29 11:47 - 2015-10-30 06:48 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-02-29 11:47 - 2015-10-30 06:47 - 00000000 ____D C:\WINDOWS\INF
2016-02-29 11:47 - 2015-08-26 10:49 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2016-02-29 11:46 - 2015-05-17 04:51 - 00000964 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-29 11:26 - 2015-12-12 08:22 - 01996112 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-29 11:26 - 2015-10-30 16:08 - 00829308 _____ C:\WINDOWS\system32\perfh005.dat
2016-02-29 11:26 - 2015-10-30 16:08 - 00185116 _____ C:\WINDOWS\system32\perfc005.dat
2016-02-29 11:25 - 2014-07-28 11:09 - 00000000 ____D C:\Users\User\AppData\Roaming\Seznam.cz
2016-02-29 11:19 - 2015-12-12 09:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-29 11:19 - 2015-12-12 08:19 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-29 11:19 - 2015-05-17 04:51 - 00000960 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-29 11:18 - 2015-10-30 06:13 - 01835008 ___SH C:\WINDOWS\system32\config\BBI
2016-02-29 02:20 - 2015-10-21 02:07 - 00000000 ____D C:\Users\User\Documents\Má složka
2016-02-29 00:50 - 2015-12-21 14:25 - 00000757 _____ C:\Users\User\Desktop\Nový textový dokument (2).txt
2016-02-28 23:54 - 2015-10-30 06:48 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-28 15:09 - 2012-04-25 09:49 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-02-28 14:54 - 2013-04-24 13:38 - 00000000 ____D C:\Program Files\Seznam.cz
2016-02-28 14:02 - 2011-03-23 18:45 - 00001186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-02-28 14:02 - 2009-11-13 21:22 - 00001174 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-02-28 13:49 - 2016-01-10 12:55 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2016-02-28 01:59 - 2015-07-15 10:07 - 00000958 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-02-27 22:36 - 2015-10-30 06:48 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-27 12:54 - 2015-09-20 04:36 - 00000000 ___RD C:\Users\User\Documents\ABC
2016-02-26 18:45 - 2015-10-21 20:50 - 00000000 ____D C:\Program Files\FastShare
2016-02-25 20:07 - 2015-06-13 22:43 - 00001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-02-25 20:07 - 2011-01-31 20:32 - 00000000 ____D C:\Program Files\Opera
2016-02-19 22:16 - 2012-10-20 00:52 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2016-02-19 21:49 - 2015-08-13 22:10 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-19 21:49 - 2013-12-25 19:02 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-11 22:37 - 2015-08-13 22:32 - 00002384 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-11 22:37 - 2015-08-13 22:32 - 00000000 ___RD C:\Users\User\OneDrive
2016-02-11 16:56 - 2015-10-30 06:48 - 00000000 ____D C:\WINDOWS\rescache
2016-02-10 12:14 - 2015-08-13 22:27 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 12:11 - 2015-10-30 16:10 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 04:20 - 2009-07-14 03:04 - 00000492 _____ C:\WINDOWS\win.ini
2016-02-10 04:17 - 2015-10-30 06:39 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-10 04:17 - 2013-07-19 02:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-10 03:48 - 2009-11-04 18:39 - 144254680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-08 13:55 - 2010-01-31 00:25 - 00000000 ____D C:\Users\User\AppData\Local\ElevatedDiagnostics
2016-02-03 20:01 - 2015-10-30 06:49 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 06:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-02-02 09:52 - 2013-04-24 13:38 - 00000000 ____D C:\Users\User\Documents\Seznam DVD 2011
==================== Files in the root of some directories =======
2014-07-28 11:10 - 2014-07-28 11:13 - 0000547 _____ () C:\Users\User\AppData\Roaming\FreeDesktopClock.ini
2009-11-17 02:46 - 2015-08-12 18:47 - 0087608 _____ () C:\Users\User\AppData\Roaming\inst.exe
2009-11-17 02:46 - 2015-08-12 18:47 - 0007887 _____ () C:\Users\User\AppData\Roaming\pcouffin.cat
2009-11-17 02:46 - 2015-08-12 18:47 - 0001144 _____ () C:\Users\User\AppData\Roaming\pcouffin.inf
2009-11-17 02:47 - 2015-08-12 18:47 - 0000055 _____ () C:\Users\User\AppData\Roaming\pcouffin.log
2009-11-17 02:46 - 2015-08-12 18:47 - 0047360 _____ (VSO Software) C:\Users\User\AppData\Roaming\pcouffin.sys
2009-12-22 21:33 - 2011-01-06 01:57 - 0003584 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-12-22 21:53 - 2010-03-07 12:59 - 0004096 ____H () C:\Users\User\AppData\Local\keyfile3.drm
2012-04-05 04:27 - 2012-11-16 00:01 - 0022297 _____ () C:\Users\User\AppData\Local\SRDownloader.err
2010-11-27 03:29 - 2012-11-16 02:05 - 0001280 _____ () C:\Users\User\AppData\Local\SRDownloader.nast
2012-12-27 00:49 - 2013-04-15 21:05 - 0000088 ___SH () C:\ProgramData\.zreglib
2010-09-24 20:36 - 2010-09-24 20:45 - 0000000 _____ () C:\ProgramData\CLDShowX.ini
2015-08-12 18:37 - 2015-08-12 18:46 - 0000177 _____ () C:\ProgramData\Temp.log
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
Multiple Image Resizer .NET (HKU\S-1-5-21-1951563654-3073323279-456428730-1000\...\InstallShield_{011D0235-589D-4B60-B952-3507C7E8D8D8}) (Version: 2.0.0.0 - Acumen Business Systems Ltd)
Multiple Image Resizer .NET (Version: 2.0.0.0 - Acumen Business Systems Ltd) Hidden
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_20_0_0_306_pepper.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1951563654-3073323279-456428730-1000Core.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1951563654-3073323279-456428730-1000UA.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\User\Desktop" je 25 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Virus HTML/Refresh.BC trojský kůň
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Virus HTML/Refresh.BC trojský kůň
- Přílohy
-
- Addition.rar
- (8.45 KiB) Staženo 51 x
Re: Virus HTML/Refresh.BC trojský kůň
ahoj,
pravdepodobne ide o falosny poplach sposobeny zlou aktualizáciou ESET produktu - objavuje po vyhladavani v Google - pouzivaj docasne iny vyhladavac - Bing, Yahoo apod.
pravdepodobne ide o falosny poplach sposobeny zlou aktualizáciou ESET produktu - objavuje po vyhladavani v Google - pouzivaj docasne iny vyhladavac - Bing, Yahoo apod.

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Virus HTML/Refresh.BC trojský kůň
Byla jsem zoufalá, od rána jsem nemohla otevřít žádnou www, aniž by mi hned nenaskočilo info o tom viru, a některé stránky byly blokované úplně. Je to 10 minut, co se všechno vrátilo zase do normálu. Díky za radu a přeji hezký den.
Re: Virus HTML/Refresh.BC trojský kůň
rad som pomohol
prajem pohodovy den
prajem pohodovy den

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/