Policie ČR na slovenký sposob
Napsal: 09 čer 2013 14:06
Ahojte, bol by som vdacny za fixlist, virus bude asi zhodny s tym českým.
Tu je log s FRST :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2013
Ran by Notebook (administrator) on 09-06-2013 14:58:42
Running from G:\
Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Safe Mode (minimal)
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] [x]
HKLM\...\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [288312 2009-07-27] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe [1183744 2007-02-21] (Analog Devices, Inc.)
HKLM\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4282728 2012-08-21] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE [1683456 2013-01-16] (Bandoo Media Inc)
HKLM\...\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [1495712 2013-06-07] (APN)
HKLM\...\Run: [InboxToolbar] "C:\Program Files\Inbox Toolbar\Inbox.exe" /STARTUP [1713288 2013-03-18] (Inbox.com, Inc.)
HKLM\...\Run: [SiteRanker] "C:\Program Files\SiteRanker\SiteRankTray.exe" [320000 2013-03-20] (Crawler, LLC)
HKCU\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd)
HKCU\...\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background [448736 2013-03-18] (Sony)
HKCU\...\Run: [RebateInformer] C:\PROGRA~1\REBATE~1\REBATE~1.EXE /STARTUP [1430664 2013-03-21] (Inbox.com, Inc.)
HKCU\...\Run: [AGupdate] C:\Program Files\AppGraffiti\AGupdate.exe [894048 2013-03-19] (Omega Partners Ltd)
HKCU\...\Run: [ctfmon32.exe] C:\PROGRA~2\rundll32.exe C:\PROGRA~2\qqeb9.dat,XFG00 [173568 2013-06-09] (?????????? ??????????)
MountPoints2: {a9b6b617-8bc4-11e1-ab29-001560c41f73} - F:\SETUP.EXE /AUTORUN
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk
ShortcutTarget: regmonstd.lnk -> C:\PROGRA~2\qqeb9.dat (?????????? ??????????)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RT-Updater.lnk
ShortcutTarget: RT-Updater.lnk -> C:\Ross-Tech\VCDS\VCDS.EXE (Ross-Tech, LLC)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?l=dis&o=APN1 ... 2013-03-31
URLSearchHook: SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - "C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll" No File
HKLM SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
HKCU SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~1\SITERA~1\SiteRank.dll (Crawler, LLC)
BHO: Ask Shopping Toolbar - {4B4D502D-5341-5400-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMP-SAT\Passport.dll" No File
BHO: KMP Media Toolbar - {4B4D5056-3600-A76A-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMPV6\Passport.dll" No File
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~1\APPGRA~1\APPGRA~1.DLL (Omega Partners Ltd)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: DataMngr - {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL (Bandoo Media Inc)
BHO: No Name - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - C:\PROGRA~1\REBATE~1\RebateI.dll (Inbox.com, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC)
Toolbar: HKLM - KMP Media Toolbar - {4B4D5056-3600-A76A-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMPV6\Passport.dll" No File
Toolbar: HKLM - Ask Shopping Toolbar - {4B4D502D-5341-5400-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMP-SAT\Passport.dll" No File
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
Handler: rebinfo - {AF808758-C780-404C-A4EE-4526323FD9B6} - C:\PROGRA~1\REBATE~1\RebateI.dll (Inbox.com, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR DefaultSearchURL: (Search Results) - http://dts.search-results.com/sr?src=cr ... earchTerms}
CHR DefaultSuggestURL: (Search Results) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
CHR Extension: (KMP Media Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaknbnblifjbchcfcaibjkccmfhmed\11.40826_0
CHR Extension: (Ask Shopping Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaampmbjjgfcidbopolonnhcejcoipm\11.38337_0
CHR Extension: (AppGraffiti) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl\1.0.1.0_0
CHR Extension: (Inbox Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgjagobplilmcdfelodhgefiidomnfl\1.0.0.9_0
CHR Extension: (avast! WebRep) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_1
CHR Extension: (Torch Share) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_1
CHR Extension: (RebateInformer) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\odbbfaealmlpnodchplhdomkgpdkeeal\1.0.0.10_0
========================== Services (Whitelisted) =================
S2 24x7HelpSvc; C:\Program Files\24x7Help\App24x7Svc.exe [342608 2013-03-17] (PCRx.com, LLC)
S2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [169640 2013-06-07] (APN LLC.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-08-21] (AVAST Software)
S2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
S2 Winmgmt; C:\PROGRA~2\qqeb9.dat [173568 2013-06-09] (?????????? ??????????)
==================== Drivers (Whitelisted) ====================
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-08-21] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-08-21] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [44784 2012-08-21] (AVAST Software)
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [729752 2012-08-21] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [355632 2012-08-21] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-08-21] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-04-21] (DT Soft Ltd)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.)
S2 HOSTNT; C:\Windows\System32\Drivers\HOSTNT.sys [4032 2012-07-28] ()
S3 RT-USB; C:\Windows\System32\drivers\RT-USB.SYS [59464 2010-06-16] (Ross-Tech LLC)
S2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2007-01-10] (Samsung Electronics)
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\FRST
2013-06-09 05:39 - 2013-06-09 05:39 - 00002649 ____A C:\ProgramData\9beqq.js
2013-06-09 00:52 - 2013-06-09 00:52 - 00003288 ____N C:\bootsqm.dat
2013-06-09 00:45 - 2013-06-09 14:53 - 95023320 ___AT C:\ProgramData\9beqq.pad
2013-06-09 00:45 - 2013-06-09 14:53 - 00000000 ____A C:\ProgramData\kjhy64.txt
2013-06-09 00:45 - 2013-06-09 00:45 - 00173568 ____A (?????????? ??????????) C:\ProgramData\qqeb9.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00044544 ____A (Microsoft Corporation) C:\ProgramData\rundll32.exe
2013-06-06 12:54 - 2013-06-06 12:54 - 00000000 ____A C:\Users\Notebook\Desktop\Nový textový dokument (2).txt
2013-06-04 22:55 - 2013-06-04 23:00 - 164413215 ____A C:\Users\Notebook\Desktop\Mientras.duermes.2011.BRRip.XviD-5rFF.rar
2013-06-03 22:04 - 2013-06-03 22:14 - 00000000 ____D C:\Users\Notebook\Desktop\psych
2013-06-03 21:55 - 2013-06-03 21:55 - 00198062 ____A C:\Users\Notebook\Desktop\psychotest-osobnost-inteligence-vykon-povaha_4.52.zip
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\MSDOS.SYS
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\IO.SYS
2013-06-02 14:57 - 2013-06-02 14:57 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Kastner software
2013-06-02 14:56 - 2013-06-02 14:56 - 00002124 ____A C:\Users\Public\Desktop\FORM studio.lnk
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\ProgramData\KASTNER software
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\Program Files\KASTNER software
2013-06-02 14:54 - 2013-06-02 14:54 - 18695816 ____A (KASTNER software s.r.o. ) C:\Users\Notebook\Desktop\fsstart.exe
2013-05-21 19:34 - 2013-05-21 19:34 - 00000234 ____A C:\Users\Notebook\Desktop\Nový textový dokument.txt
2013-05-19 16:36 - 2013-04-05 00:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-19 16:36 - 2013-04-05 00:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-19 16:36 - 2013-04-05 00:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-19 16:36 - 2013-04-05 00:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-19 16:36 - 2013-04-05 00:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-19 16:36 - 2013-04-05 00:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-19 16:36 - 2013-04-04 23:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-19 16:36 - 2013-04-04 23:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-19 16:36 - 2013-04-04 23:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-19 16:36 - 2013-04-04 23:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-19 16:36 - 2013-04-04 23:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-19 16:36 - 2013-04-04 23:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-19 16:36 - 2013-04-04 23:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-19 16:36 - 2013-04-04 23:50 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-19 16:30 - 2013-05-05 21:25 - 12324864 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-19 16:30 - 2013-05-05 21:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-19 14:51 - 2012-08-22 19:16 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2013-05-19 14:51 - 2012-07-04 21:45 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2013-05-19 14:50 - 2013-04-10 05:14 - 02347520 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-19 14:50 - 2013-03-19 06:53 - 00186368 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-19 14:50 - 2013-03-19 05:33 - 00040960 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00242176 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2013-05-19 14:50 - 2012-10-03 18:40 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2013-05-19 14:50 - 2012-10-03 17:21 - 00035328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2013-05-19 14:50 - 2012-08-21 22:12 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe
2013-05-19 14:49 - 2013-04-10 07:18 - 00728424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-19 14:49 - 2013-04-10 07:18 - 00218984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-19 14:49 - 2012-11-23 04:48 - 00049152 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-05-19 14:49 - 2012-10-09 19:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2013-05-19 14:49 - 2012-10-09 19:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2013-05-19 14:48 - 2013-02-27 07:05 - 00101720 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-19 14:48 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-19 14:48 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-19 14:48 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-19 14:48 - 2013-02-27 06:49 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-18 22:37 - 2013-05-18 22:37 - 00000000 ____D C:\Windows\System32\SPReview
==================== One Month Modified Files and Folders ========
2013-06-09 14:53 - 2013-06-09 00:45 - 95023320 ___AT C:\ProgramData\9beqq.pad
2013-06-09 14:53 - 2013-06-09 00:45 - 00000000 ____A C:\ProgramData\kjhy64.txt
2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\FRST
2013-06-09 14:29 - 2012-05-25 00:05 - 00000924 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-09 14:29 - 2009-07-14 06:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-09 14:29 - 2009-07-14 06:39 - 00085037 ____A C:\Windows\setupact.log
2013-06-09 07:32 - 2011-06-26 06:19 - 01381893 ____A C:\Windows\WindowsUpdate.log
2013-06-09 05:39 - 2013-06-09 05:39 - 00002649 ____A C:\ProgramData\9beqq.js
2013-06-09 05:37 - 2012-05-25 00:05 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 05:27 - 2012-05-25 00:05 - 00000914 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-09 01:02 - 2009-07-14 06:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-09 01:02 - 2009-07-14 06:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-09 00:52 - 2013-06-09 00:52 - 00003288 ____N C:\bootsqm.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00173568 ____A (?????????? ??????????) C:\ProgramData\qqeb9.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00044544 ____A (Microsoft Corporation) C:\ProgramData\rundll32.exe
2013-06-08 22:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\DriverStore
2013-06-07 20:42 - 2012-05-25 00:06 - 00002129 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-06 12:54 - 2013-06-06 12:54 - 00000000 ____A C:\Users\Notebook\Desktop\Nový textový dokument (2).txt
2013-06-05 22:17 - 2012-01-16 12:26 - 00000138 ____A C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url
2013-06-04 23:07 - 2013-03-31 15:54 - 00000000 ____D C:\Program Files\The KMPlayer
2013-06-04 23:00 - 2013-06-04 22:55 - 164413215 ____A C:\Users\Notebook\Desktop\Mientras.duermes.2011.BRRip.XviD-5rFF.rar
2013-06-04 16:00 - 2011-06-28 23:21 - 01478586 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-03 22:14 - 2013-06-03 22:04 - 00000000 ____D C:\Users\Notebook\Desktop\psych
2013-06-03 21:55 - 2013-06-03 21:55 - 00198062 ____A C:\Users\Notebook\Desktop\psychotest-osobnost-inteligence-vykon-povaha_4.52.zip
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\MSDOS.SYS
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\IO.SYS
2013-06-02 14:57 - 2013-06-02 14:57 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Kastner software
2013-06-02 14:56 - 2013-06-02 14:56 - 00002124 ____A C:\Users\Public\Desktop\FORM studio.lnk
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\ProgramData\KASTNER software
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\Program Files\KASTNER software
2013-06-02 14:54 - 2013-06-02 14:54 - 18695816 ____A (KASTNER software s.r.o. ) C:\Users\Notebook\Desktop\fsstart.exe
2013-05-28 07:06 - 2012-04-22 14:39 - 00008098 ____A C:\Windows\PFRO.log
2013-05-27 17:59 - 2012-10-09 20:42 - 00000000 ____D C:\Program Files\Sony Ericsson
2013-05-21 19:34 - 2013-05-21 19:34 - 00000234 ____A C:\Users\Notebook\Desktop\Nový textový dokument.txt
2013-05-20 22:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-05-19 23:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-05-19 20:26 - 2009-07-14 06:33 - 00357192 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-19 10:01 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Windows Journal
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Portable Devices
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\DVD Maker
2013-05-19 10:00 - 2009-07-14 10:44 - 00000000 ____D C:\Windows\System32\cs
2013-05-19 10:00 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-05-19 10:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
2013-05-19 10:00 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\System
2013-05-18 22:44 - 2009-07-14 04:05 - 00152576 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2013-05-18 22:37 - 2013-05-18 22:37 - 00000000 ____D C:\Windows\System32\SPReview
2013-05-17 19:35 - 2013-04-06 23:14 - 00000000 ____D C:\Users\Notebook\Desktop\ewa
2013-05-15 16:12 - 2011-06-29 00:01 - 72607752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-14 22:27 - 2012-05-25 00:04 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-14 22:27 - 2011-11-13 12:52 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-05-12 10:51 - 2011-11-12 16:56 - 00000000 ____D C:\Program Files\Opera
Files to move or delete:
====================
C:\ProgramData\rundll32.exe
C:\ProgramData\9beqq.pad
C:\ProgramData\qqeb9.dat
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-03 15:07
==================== End Of Log ============================
dakujem
Tu je log s FRST :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2013
Ran by Notebook (administrator) on 09-06-2013 14:58:42
Running from G:\
Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Safe Mode (minimal)
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] [x]
HKLM\...\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [288312 2009-07-27] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe [1183744 2007-02-21] (Analog Devices, Inc.)
HKLM\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4282728 2012-08-21] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE [1683456 2013-01-16] (Bandoo Media Inc)
HKLM\...\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [1495712 2013-06-07] (APN)
HKLM\...\Run: [InboxToolbar] "C:\Program Files\Inbox Toolbar\Inbox.exe" /STARTUP [1713288 2013-03-18] (Inbox.com, Inc.)
HKLM\...\Run: [SiteRanker] "C:\Program Files\SiteRanker\SiteRankTray.exe" [320000 2013-03-20] (Crawler, LLC)
HKCU\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd)
HKCU\...\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background [448736 2013-03-18] (Sony)
HKCU\...\Run: [RebateInformer] C:\PROGRA~1\REBATE~1\REBATE~1.EXE /STARTUP [1430664 2013-03-21] (Inbox.com, Inc.)
HKCU\...\Run: [AGupdate] C:\Program Files\AppGraffiti\AGupdate.exe [894048 2013-03-19] (Omega Partners Ltd)
HKCU\...\Run: [ctfmon32.exe] C:\PROGRA~2\rundll32.exe C:\PROGRA~2\qqeb9.dat,XFG00 [173568 2013-06-09] (?????????? ??????????)
MountPoints2: {a9b6b617-8bc4-11e1-ab29-001560c41f73} - F:\SETUP.EXE /AUTORUN
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk
ShortcutTarget: regmonstd.lnk -> C:\PROGRA~2\qqeb9.dat (?????????? ??????????)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RT-Updater.lnk
ShortcutTarget: RT-Updater.lnk -> C:\Ross-Tech\VCDS\VCDS.EXE (Ross-Tech, LLC)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?l=dis&o=APN1 ... 2013-03-31
URLSearchHook: SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - "C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll" No File
HKLM SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
HKCU SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ie ... earchTerms}
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~1\SITERA~1\SiteRank.dll (Crawler, LLC)
BHO: Ask Shopping Toolbar - {4B4D502D-5341-5400-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMP-SAT\Passport.dll" No File
BHO: KMP Media Toolbar - {4B4D5056-3600-A76A-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMPV6\Passport.dll" No File
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~1\APPGRA~1\APPGRA~1.DLL (Omega Partners Ltd)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: DataMngr - {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL (Bandoo Media Inc)
BHO: No Name - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - C:\PROGRA~1\REBATE~1\RebateI.dll (Inbox.com, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC)
Toolbar: HKLM - KMP Media Toolbar - {4B4D5056-3600-A76A-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMPV6\Passport.dll" No File
Toolbar: HKLM - Ask Shopping Toolbar - {4B4D502D-5341-5400-76A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\KMP-SAT\Passport.dll" No File
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
Handler: rebinfo - {AF808758-C780-404C-A4EE-4526323FD9B6} - C:\PROGRA~1\REBATE~1\RebateI.dll (Inbox.com, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR DefaultSearchURL: (Search Results) - http://dts.search-results.com/sr?src=cr ... earchTerms}
CHR DefaultSuggestURL: (Search Results) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
CHR Extension: (KMP Media Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaknbnblifjbchcfcaibjkccmfhmed\11.40826_0
CHR Extension: (Ask Shopping Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaampmbjjgfcidbopolonnhcejcoipm\11.38337_0
CHR Extension: (AppGraffiti) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl\1.0.1.0_0
CHR Extension: (Inbox Toolbar) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgjagobplilmcdfelodhgefiidomnfl\1.0.0.9_0
CHR Extension: (avast! WebRep) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_1
CHR Extension: (Torch Share) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_1
CHR Extension: (RebateInformer) - C:\Users\Notebook\AppData\Local\Google\Chrome\User Data\Default\Extensions\odbbfaealmlpnodchplhdomkgpdkeeal\1.0.0.10_0
========================== Services (Whitelisted) =================
S2 24x7HelpSvc; C:\Program Files\24x7Help\App24x7Svc.exe [342608 2013-03-17] (PCRx.com, LLC)
S2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [169640 2013-06-07] (APN LLC.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-08-21] (AVAST Software)
S2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
S2 Winmgmt; C:\PROGRA~2\qqeb9.dat [173568 2013-06-09] (?????????? ??????????)
==================== Drivers (Whitelisted) ====================
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-08-21] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-08-21] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [44784 2012-08-21] (AVAST Software)
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [729752 2012-08-21] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [355632 2012-08-21] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-08-21] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-04-21] (DT Soft Ltd)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.)
S2 HOSTNT; C:\Windows\System32\Drivers\HOSTNT.sys [4032 2012-07-28] ()
S3 RT-USB; C:\Windows\System32\drivers\RT-USB.SYS [59464 2010-06-16] (Ross-Tech LLC)
S2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2007-01-10] (Samsung Electronics)
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\FRST
2013-06-09 05:39 - 2013-06-09 05:39 - 00002649 ____A C:\ProgramData\9beqq.js
2013-06-09 00:52 - 2013-06-09 00:52 - 00003288 ____N C:\bootsqm.dat
2013-06-09 00:45 - 2013-06-09 14:53 - 95023320 ___AT C:\ProgramData\9beqq.pad
2013-06-09 00:45 - 2013-06-09 14:53 - 00000000 ____A C:\ProgramData\kjhy64.txt
2013-06-09 00:45 - 2013-06-09 00:45 - 00173568 ____A (?????????? ??????????) C:\ProgramData\qqeb9.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00044544 ____A (Microsoft Corporation) C:\ProgramData\rundll32.exe
2013-06-06 12:54 - 2013-06-06 12:54 - 00000000 ____A C:\Users\Notebook\Desktop\Nový textový dokument (2).txt
2013-06-04 22:55 - 2013-06-04 23:00 - 164413215 ____A C:\Users\Notebook\Desktop\Mientras.duermes.2011.BRRip.XviD-5rFF.rar
2013-06-03 22:04 - 2013-06-03 22:14 - 00000000 ____D C:\Users\Notebook\Desktop\psych
2013-06-03 21:55 - 2013-06-03 21:55 - 00198062 ____A C:\Users\Notebook\Desktop\psychotest-osobnost-inteligence-vykon-povaha_4.52.zip
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\MSDOS.SYS
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\IO.SYS
2013-06-02 14:57 - 2013-06-02 14:57 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Kastner software
2013-06-02 14:56 - 2013-06-02 14:56 - 00002124 ____A C:\Users\Public\Desktop\FORM studio.lnk
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\ProgramData\KASTNER software
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\Program Files\KASTNER software
2013-06-02 14:54 - 2013-06-02 14:54 - 18695816 ____A (KASTNER software s.r.o. ) C:\Users\Notebook\Desktop\fsstart.exe
2013-05-21 19:34 - 2013-05-21 19:34 - 00000234 ____A C:\Users\Notebook\Desktop\Nový textový dokument.txt
2013-05-19 16:36 - 2013-04-05 00:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-19 16:36 - 2013-04-05 00:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-19 16:36 - 2013-04-05 00:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-19 16:36 - 2013-04-05 00:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-19 16:36 - 2013-04-05 00:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-19 16:36 - 2013-04-05 00:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-19 16:36 - 2013-04-04 23:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-19 16:36 - 2013-04-04 23:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-19 16:36 - 2013-04-04 23:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-19 16:36 - 2013-04-04 23:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-19 16:36 - 2013-04-04 23:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-19 16:36 - 2013-04-04 23:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-19 16:36 - 2013-04-04 23:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-19 16:36 - 2013-04-04 23:50 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-19 16:30 - 2013-05-05 21:25 - 12324864 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-19 16:30 - 2013-05-05 21:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-19 14:51 - 2012-08-22 19:16 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2013-05-19 14:51 - 2012-07-04 21:45 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2013-05-19 14:50 - 2013-04-10 05:14 - 02347520 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-19 14:50 - 2013-03-19 06:53 - 00186368 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-19 14:50 - 2013-03-19 05:33 - 00040960 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00242176 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2013-05-19 14:50 - 2012-10-03 18:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2013-05-19 14:50 - 2012-10-03 18:40 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2013-05-19 14:50 - 2012-10-03 17:21 - 00035328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2013-05-19 14:50 - 2012-08-21 22:12 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe
2013-05-19 14:49 - 2013-04-10 07:18 - 00728424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-19 14:49 - 2013-04-10 07:18 - 00218984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-19 14:49 - 2012-11-23 04:48 - 00049152 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-05-19 14:49 - 2012-10-09 19:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2013-05-19 14:49 - 2012-10-09 19:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2013-05-19 14:48 - 2013-02-27 07:05 - 00101720 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-19 14:48 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-19 14:48 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-19 14:48 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-19 14:48 - 2013-02-27 06:49 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-18 22:37 - 2013-05-18 22:37 - 00000000 ____D C:\Windows\System32\SPReview
==================== One Month Modified Files and Folders ========
2013-06-09 14:53 - 2013-06-09 00:45 - 95023320 ___AT C:\ProgramData\9beqq.pad
2013-06-09 14:53 - 2013-06-09 00:45 - 00000000 ____A C:\ProgramData\kjhy64.txt
2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\FRST
2013-06-09 14:29 - 2012-05-25 00:05 - 00000924 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-09 14:29 - 2009-07-14 06:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-09 14:29 - 2009-07-14 06:39 - 00085037 ____A C:\Windows\setupact.log
2013-06-09 07:32 - 2011-06-26 06:19 - 01381893 ____A C:\Windows\WindowsUpdate.log
2013-06-09 05:39 - 2013-06-09 05:39 - 00002649 ____A C:\ProgramData\9beqq.js
2013-06-09 05:37 - 2012-05-25 00:05 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 05:27 - 2012-05-25 00:05 - 00000914 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-09 01:02 - 2009-07-14 06:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-09 01:02 - 2009-07-14 06:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-09 00:52 - 2013-06-09 00:52 - 00003288 ____N C:\bootsqm.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00173568 ____A (?????????? ??????????) C:\ProgramData\qqeb9.dat
2013-06-09 00:45 - 2013-06-09 00:45 - 00044544 ____A (Microsoft Corporation) C:\ProgramData\rundll32.exe
2013-06-08 22:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\DriverStore
2013-06-07 20:42 - 2012-05-25 00:06 - 00002129 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-06 12:54 - 2013-06-06 12:54 - 00000000 ____A C:\Users\Notebook\Desktop\Nový textový dokument (2).txt
2013-06-05 22:17 - 2012-01-16 12:26 - 00000138 ____A C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url
2013-06-04 23:07 - 2013-03-31 15:54 - 00000000 ____D C:\Program Files\The KMPlayer
2013-06-04 23:00 - 2013-06-04 22:55 - 164413215 ____A C:\Users\Notebook\Desktop\Mientras.duermes.2011.BRRip.XviD-5rFF.rar
2013-06-04 16:00 - 2011-06-28 23:21 - 01478586 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-03 22:14 - 2013-06-03 22:04 - 00000000 ____D C:\Users\Notebook\Desktop\psych
2013-06-03 21:55 - 2013-06-03 21:55 - 00198062 ____A C:\Users\Notebook\Desktop\psychotest-osobnost-inteligence-vykon-povaha_4.52.zip
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\MSDOS.SYS
2013-06-03 21:39 - 2013-06-03 21:39 - 00000000 _RASH C:\IO.SYS
2013-06-02 14:57 - 2013-06-02 14:57 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Kastner software
2013-06-02 14:56 - 2013-06-02 14:56 - 00002124 ____A C:\Users\Public\Desktop\FORM studio.lnk
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\ProgramData\KASTNER software
2013-06-02 14:56 - 2013-06-02 14:56 - 00000000 ____D C:\Program Files\KASTNER software
2013-06-02 14:54 - 2013-06-02 14:54 - 18695816 ____A (KASTNER software s.r.o. ) C:\Users\Notebook\Desktop\fsstart.exe
2013-05-28 07:06 - 2012-04-22 14:39 - 00008098 ____A C:\Windows\PFRO.log
2013-05-27 17:59 - 2012-10-09 20:42 - 00000000 ____D C:\Program Files\Sony Ericsson
2013-05-21 19:34 - 2013-05-21 19:34 - 00000234 ____A C:\Users\Notebook\Desktop\Nový textový dokument.txt
2013-05-20 22:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-05-19 23:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-05-19 20:26 - 2009-07-14 06:33 - 00357192 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-19 10:01 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Windows Journal
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Portable Devices
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-05-19 10:01 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\DVD Maker
2013-05-19 10:00 - 2009-07-14 10:44 - 00000000 ____D C:\Windows\System32\cs
2013-05-19 10:00 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-05-19 10:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
2013-05-19 10:00 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\System
2013-05-18 22:44 - 2009-07-14 04:05 - 00152576 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2013-05-18 22:37 - 2013-05-18 22:37 - 00000000 ____D C:\Windows\System32\SPReview
2013-05-17 19:35 - 2013-04-06 23:14 - 00000000 ____D C:\Users\Notebook\Desktop\ewa
2013-05-15 16:12 - 2011-06-29 00:01 - 72607752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-14 22:27 - 2012-05-25 00:04 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-14 22:27 - 2011-11-13 12:52 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-05-12 10:51 - 2011-11-12 16:56 - 00000000 ____D C:\Program Files\Opera
Files to move or delete:
====================
C:\ProgramData\rundll32.exe
C:\ProgramData\9beqq.pad
C:\ProgramData\qqeb9.dat
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-03 15:07
==================== End Of Log ============================
dakujem