Zdravím,
bohužel po cca 3 měsících kdy PC běžel normálně se před několika dny opět dostavilo fatální zpomalení ..
Načítání v prohlížeči, mailu, rozbalování souborů, prostě vše trvá věčnost. Zkusil jsem návrat systému do období kdy PC běžěl
bez problémů ale nepomohlo to.
Nevím si rady, nic jsem do PC nestahoval mimo nového antiviru Avast Free edice, což by mohla být příčina, časově to sedí, ale nejsem schopen to zjistit s jistotou a eliminovat.
Snad mi dokážete opět poradit, prosím tímto o pomoc a děkuji předem.
Přikládám FRST.
Emil
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-03-2017
Ran by Andrejka (administrator) on ANDREJKA-NTB (21-03-2017 21:29:10)
Running from C:\Documents and Settings\Andrejka\Plocha
Loaded Profiles: Andrejka (Available Profiles: Andrejka)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe
() C:\Program Files\HiSuite\HandSetService\HuaweiHiSuiteService.exe
(Microsoft Corporation) C:\WINDOWS\system32\inetsrv\inetinfo.exe
(Nuance Communications, Inc.) C:\Program Files\Dell Printers\paperport\PaperPort\PDFProFiltSrvPP.exe
(Solid Documents, LLC) C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpwdnt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Nuance Communications, Inc.) C:\Program Files\Dell Printers\paperport\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files\Dell Printers\paperport\PDFViewer\pdfPro5Hook.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Acresso Corporation) C:\Documents and Settings\All Users\Data aplikací\FLEXnet\Connect\11\ISUSPM.exe
(TechSmith Corporation) C:\Program Files\TechSmith\Jing\Jing.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Acresso Corporation) C:\Documents and Settings\All Users\Data aplikací\FLEXnet\Connect\11\agent.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [872448 2007-01-05] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [729088 2006-07-13] (Analog Devices, Inc.)
HKLM\...\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2008-04-15] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [IndexSearch] => C:\Program Files\Dell Printers\paperport\PaperPort\IndexSearch.exe [46368 2010-03-16] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] => C:\Program Files\Dell Printers\paperport\PaperPort\pptd40nt.exe [29984 2010-03-16] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] => C:\Program Files\Dell Printers\paperport\PDFViewer\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] => C:\Program Files\Dell Printers\paperport\PDFViewer\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [DLPSP] => C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE [906680 2012-09-26] (Dell Inc.)
HKLM\...\Run: [DLUPDR] => C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE [1103208 2012-09-26] (Dell Inc.)
HKLM\...\Run: [DLQLU] => C:\Program Files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE [1082688 2012-04-11] (Dell Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2017-01-01] (AVAST Software)
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\Run: [ISUSPM] => C:\Documents and Settings\All Users\Data aplikací\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\Run: [Avast-Browser-Cleanup] => "C:\Program Files\AVAST Software\Avast\BrowserCleanup.exe"/RunOnce
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\Run: [Jing] => C:\Program Files\TechSmith\Jing\Jing.exe [2911224 2015-09-11] (TechSmith Corporation)
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\MountPoints2: E - E:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\MountPoints2: {1281c9f6-6f59-11e1-a10a-001a738be232} - E:\AutoRun.exe
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\MountPoints2: {613356c4-c47a-11e6-8b6b-001a738be232} - E:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\MountPoints2: {bd67690e-c42e-11e6-8b69-001a738be232} - E:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\...\MountPoints2: {d2cb244c-c475-11e6-8b6a-001a738be232} - E:\HiSuiteDownLoader.exe
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-01-01] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Andrejka\Data aplikací\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Andrejka\Data aplikací\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Andrejka\Data aplikací\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Andrejka\Data aplikací\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk [2012-02-25]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk [2012-02-25]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\Andrejka\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [2013-07-30]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{75A37866-9C7F-4D61-ADDF-5DA5D4682440}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.seznam.cz/
HKU\S-1-5-21-2052111302-764733703-1801674531-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files\Dell Printers\paperport\PDFViewer\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-01-01] (AVAST Software)
Toolbar: HKU\S-1-5-21-2052111302-764733703-1801674531-1005 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Andrejka\Data aplikací\TomTom\HOME\Profiles\asmwfo1m.default [2015-09-28]
FF Extension: (No Name) - C:\Program Files\TomTom HOME 2\xul\extensions\
MapShare-status@tomtom.com [not found]
FF ProfilePath: C:\Documents and Settings\Andrejka\Data aplikací\Mozilla\Firefox\Profiles\fq3fct29.default-1475819993484 [2017-03-21]
FF Extension: (Pin It button) - C:\Documents and Settings\Andrejka\Data aplikací\Mozilla\Firefox\Profiles\fq3fct29.default-1475819993484\Extensions\
jid1-YcMV6ngYmQRA2w@jetpack.xpi [2017-02-17]
FF Extension: (Skype Click to Call) - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-10-21] [not signed]
FF Extension: (Skype Click to Call) - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-10-21] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-17] [not signed]
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2017-02-22]
FF HKLM\...\Firefox\Extensions: [
sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2017-02-22]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-17] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://
www.google.com/"
CHR Profile: C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default [2017-02-25]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-14]
CHR Extension: (Disk Google) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-04]
CHR Extension: (YouTube) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-04]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-10-04]
CHR Extension: (Avast SafePrice) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-10-04]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-28]
CHR Extension: (Gmail) - C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-14]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2017-01-01] (AVAST Software)
R2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [266295 2007-02-06] (Broadcom Corporation.) [File not signed]
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [4715880 2009-11-20] (DisplayLink Corp.)
R2 HuaweiHiSuiteService.exe; C:\Program Files\HiSuite\HandSetService\HuaweiHiSuiteService.exe [155848 2016-08-26] () [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
R2 PDFProFiltSrvPP; C:\Program Files\Dell Printers\paperport\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-16] (Nuance Communications, Inc.)
R2 SPDFCreatorReadSpool; C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe [164136 2013-03-25] (Solid Documents, LLC)
R2 W3SVC; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
S2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [X]
S2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [X]
S2 Skype C2C Service; "C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHdsKe; C:\WINDOWS\system32\drivers\aswHdsKe.sys [70008 2017-02-23] (AVAST Software)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [34008 2017-01-01] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2017-01-01] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [92256 2017-01-01] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2017-01-01] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [60424 2017-01-01] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [735488 2017-01-01] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [433768 2017-01-01] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [184592 2017-01-01] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [66688 2017-01-01] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [224752 2017-01-01] (AVAST Software)
S3 ATSWPDRV; C:\WINDOWS\System32\DRIVERS\ATSwpDrv.sys [146560 2007-08-28] (AuthenTec, Inc.)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [604928 2006-10-12] (Broadcom Corporation)
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [530861 2007-02-14] (Broadcom Corporation.)
R3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [47504 2016-10-07] (IVT Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [30459 2007-02-14] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [868298 2007-02-14] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [149123 2007-02-14] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [67960 2007-02-14] (Broadcom Corporation.)
R3 DisplayLinkFilter; C:\WINDOWS\System32\DRIVERS\DisplayLinkFilter.sys [7040 2009-11-20] (DisplayLink Corp.)
R3 DisplayLinkmirror; C:\WINDOWS\System32\DRIVERS\DisplayLinkmirrorport.sys [24320 2009-11-20] (DisplayLink Corp.)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\DRIVERS\ew_usbccgpfilter.sys [15360 2016-05-25] (Huawei Technologies Co., Ltd.)
S3 HP24X; C:\WINDOWS\System32\DRIVERS\HP24X.sys [35072 2007-07-17] (Hewlett Packard) [File not signed]
S3 Huawei; C:\WINDOWS\System32\DRIVERS\ewdcsc.sys [24448 2009-12-15] (Huawei Tech. Co., Ltd.) [File not signed]
S3 hwdatacard; C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys [102528 2009-12-15] (Huawei Technologies Co., Ltd.) [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2016-10-07] (REALiX(tm))
S3 hwusbdev; C:\WINDOWS\System32\DRIVERS\ewusbdev.sys [100736 2009-12-15] (Huawei Technologies Co., Ltd.) [File not signed]
R3 IFXTPM; C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS [44800 2008-07-23] (Infineon Technologies AG)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2017-01-07] (Malwarebytes Corporation)
R1 tidnet; C:\WINDOWS\System32\DRIVERS\tidnet.sys [19200 2009-09-15] (Telefónica I+D) [File not signed]
U2 CertPropSvc; no ImagePath
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113280 2009-12-15] (Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2016-05-25] (Huawei Technologies Co., Ltd.)
S3 MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [X]
U1 WS2IFSL; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-21 21:25 - 2017-03-21 21:26 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Andrejka\Plocha\FRSTLauncher.exe
2017-02-25 21:26 - 2017-02-23 20:02 - 00070008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2017-02-23 14:17 - 2017-02-23 14:17 - 00039832 _____ () C:\WINDOWS\system32\Drivers\staport.sys
2017-02-22 14:16 - 2017-01-01 17:44 - 00319760 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-02-21 12:34 - 2017-02-21 12:34 - 00000000 _____ C:\WINDOWS\system32\last.dump
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-21 21:32 - 2012-02-24 21:25 - 00000000 ____D C:\Documents and Settings\Andrejka\Local Settings\Temp
2017-03-21 21:29 - 2017-01-02 11:11 - 00021789 _____ C:\Documents and Settings\Andrejka\Plocha\FRST.txt
2017-03-21 21:26 - 2012-03-16 14:06 - 00000000 ____D C:\Documents and Settings\Andrejka\Dokumenty\Stažené soubory
2017-03-21 21:26 - 2012-02-24 21:25 - 00000000 ____D C:\Documents and Settings\Andrejka\Plocha
2017-03-21 21:12 - 2017-01-02 11:09 - 00000000 ____D C:\FRST
2017-03-21 21:05 - 2017-01-02 09:26 - 01766912 _____ (Farbar) C:\Documents and Settings\Andrejka\Plocha\FRST.exe
2017-03-21 20:49 - 2016-12-22 10:20 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-03-21 18:51 - 2012-02-24 22:06 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-03-21 14:23 - 2015-02-16 13:15 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2017-03-21 14:19 - 2016-06-20 20:00 - 00000464 _____ C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1466449110.job
2017-03-21 07:56 - 2014-03-21 09:13 - 00000228 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2017-03-21 07:56 - 2012-02-24 21:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-21 07:55 - 2014-12-22 19:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-03-20 21:52 - 2015-03-13 09:25 - 00269822 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2017-03-20 21:52 - 2012-02-24 21:25 - 00000178 ___SH C:\Documents and Settings\Andrejka\ntuser.ini
2017-03-20 21:52 - 2012-02-24 21:24 - 00032496 _____ C:\WINDOWS\SchedLgU.Txt
2017-03-20 19:31 - 2016-10-21 20:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-03-20 07:55 - 2001-10-25 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2017-03-18 04:51 - 2012-02-24 21:25 - 00000000 ____D C:\Documents and Settings\Andrejka
2017-03-18 04:50 - 2017-01-02 17:31 - 00000000 ____D C:\AdwCleaner
2017-03-17 20:08 - 2012-02-24 22:11 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2017-03-17 20:08 - 2012-02-24 21:19 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-03-17 18:25 - 2012-04-03 19:38 - 00802904 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2017-03-17 18:25 - 2012-03-13 19:12 - 00144472 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2017-03-17 13:16 - 2015-03-13 12:03 - 00539366 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-2052111302-764733703-1801674531-1005-0.dat
2017-03-17 11:19 - 2015-02-18 13:24 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2017-03-15 15:25 - 2012-02-27 13:54 - 00000000 ____D C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\Temp
2017-03-09 22:48 - 2012-02-24 21:18 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty\Obrázky
2017-03-05 18:39 - 2016-11-01 20:23 - 00000000 ____D C:\Documents and Settings\All Users\Dokumenty\TC
2017-03-05 18:32 - 2012-02-24 21:25 - 00000000 ___HD C:\Documents and Settings\Andrejka\Local Settings\Data aplikací
2017-02-26 19:06 - 2014-04-12 10:51 - 00000000 ____D C:\Documents and Settings\Andrejka\Data aplikací\vlc
2017-02-26 19:03 - 2012-02-24 21:25 - 00000000 ___RD C:\Documents and Settings\Andrejka\Dokumenty\Hudba
2017-02-26 18:10 - 2014-06-03 15:22 - 00000000 ____D C:\Documents and Settings\Andrejka\Data aplikací\.oit
2017-02-26 17:23 - 2012-03-22 20:06 - 00000000 ____D C:\Documents and Settings\Andrejka\Data aplikací\dvdcss
2017-02-22 17:58 - 2012-02-24 22:11 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2017-02-22 17:58 - 2012-02-24 22:11 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2017-02-22 17:58 - 2012-02-24 22:11 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2017-02-22 14:20 - 2015-02-16 13:16 - 00001689 _____ C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2017-02-22 14:19 - 2017-01-01 16:54 - 00000756 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Avast SafeZone 1 Browser.lnk
2017-02-22 14:18 - 2012-02-24 22:06 - 00000000 ___HD C:\WINDOWS\inf
2017-02-22 14:12 - 2012-02-24 21:24 - 00000000 __SHD C:\Documents and Settings\NetworkService
2017-02-22 14:12 - 2012-02-24 21:24 - 00000000 __SHD C:\Documents and Settings\LocalService
2017-02-22 14:12 - 2012-02-24 21:17 - 00000000 ____D C:\WINDOWS\Registration
==================== Files in the root of some directories =======
2014-09-25 07:58 - 2014-09-25 07:59 - 1837224 ____C () C:\Program Files\FSCaptureSetup68.exe
2013-06-02 14:48 - 2013-06-02 14:48 - 4167680 ____C () C:\Program Files\GUT5.tmp
2013-10-15 09:17 - 2013-10-15 09:17 - 50053120 ____C () C:\Program Files\GUT6B.tmp
2014-04-09 21:59 - 2014-04-09 21:17 - 7368478 ____C (FoxPDF Software Inc ) C:\Program Files\PDF toDocConverter.exe
2014-04-09 21:52 - 2014-04-09 21:52 - 0098304 ____C (VeryPDF.com Inc. ) C:\Program Files\pdf2word.exe
2014-04-09 22:14 - 2014-04-09 22:16 - 132290592 ____C (Solid Documents ) C:\Program Files\solidpdftools.exe
2016-12-02 22:35 - 2016-12-02 22:35 - 0000323 _____ () C:\Documents and Settings\Andrejka\Data aplikací\FotoSketcher.ini
2012-02-25 16:09 - 2012-02-25 16:09 - 0000000 ____C () C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\AtStart.txt
2012-03-17 10:02 - 2013-11-30 19:54 - 0120832 _____ () C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-02-25 16:09 - 2012-02-25 16:09 - 0000000 ____C () C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\DSwitch.txt
2017-01-02 09:23 - 2017-01-02 11:08 - 0029696 _____ () C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\MSGBOX.EXE
2012-02-25 16:09 - 2012-02-25 16:09 - 0000000 ____C () C:\Documents and Settings\Andrejka\Local Settings\Data aplikací\QSwitch.txt
Files to move or delete:
====================
C:\Documents and Settings\Andrejka\HWiNFO32.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================