policejní vír
Napsal: 01 črc 2013 20:34
Prosím o pomoc mam policejní vír. HDD jsem vytahla a projela avastem. A pak jsem jej zas namontovala do notasu.Ted vám předkládám logy FRST. Děkuji za pomoc.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-06-2013
Ran by michal (administrator) on 01-07-2013 21:19:33
Running from C:\Documents and Settings\michal\Plocha
Microsoft Windows XP Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [preload] C:\Windows\RUNXMLPL.exe [40960 2004-04-20] (Wistron)
HKLM\...\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [102491 2005-01-08] (Synaptics, Inc.)
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [692315 2005-01-08] (Synaptics, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY [x]
HKLM\...\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [339968 2005-02-08] (ATI Technologies, Inc.)
HKLM\...\Run: [eRecoveryService] C:\Windows\System32\Check.exe [245760 2005-03-23] (acer Inc.)
HKLM\...\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.)
HKLM\...\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe [1397760 2005-07-25] (Nero AG)
HKLM\...\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray [143360 2004-11-25] (Nokia)
HKLM\...\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE [1068032 2004-12-09] (Nokia Mobile Phones Ltd.)
HKLM\...\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s [57344 2006-09-28] (SlySoft, Inc.)
HKLM\...\Run: [RegistryMechanic] [x]
HKLM\...\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui [253952 2005-01-31] (Atheros Communications, Inc.)
HKLM\...\Run: [SoundMan] SOUNDMAN.EXE [x]
HKLM\...\Run: [FixCamera] C:\WINDOWS\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp325] C:\WINDOWS\tsnp325.exe [270336 2007-04-21] ()
HKLM\...\Run: [snp325] C:\WINDOWS\vsnp325.exe [835584 2007-04-25] ()
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent [69632 2012-03-20] (Vodafone)
HKLM\...\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [SymInstallStub] C:\WINDOWS\system32\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=5 /debug /desktopshortcut=1 /startmenushortcut=1 /launchedby=3 [335776 2013-06-25] (Symantec Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\...\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [1695232 2008-04-14] (Microsoft Corporation)
HKCU\...\Run: [RAMSaverPro] C:\Program Files\WinTools\RAM Saver Pro\ramsaverpro.exe [77824 2006-12-13] ()
HKCU\...\Run: [ctfmon32.exe] C:\DOCUME~1\ALLUSE~1\DATAAP~1\rundll32.exe C:\DOCUME~1\ALLUSE~1\DATAAP~1\88jee.dat,XFG00 [x] <===== ATTENTION
MountPoints2: {0a6b2edc-8197-11e2-9ff7-000e9bbfc587} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {108d712c-4d0c-11e2-9fcf-000ae4e102c4} - F:\Toshiba\Launcher\start.exe
MountPoints2: {1f374922-5a2d-11e2-9fde-000ae4e102c4} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {1f374923-5a2d-11e2-9fde-000ae4e102c4} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {431be504-7c16-11e2-9ff6-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {45a9bf54-8bce-11e2-a001-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {4904b514-69eb-11e2-9fe4-001e101fcbdc} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {7b6b6e54-8a3d-11e2-9fff-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {a5022804-7109-11e2-9feb-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {b6354008-71df-11e2-9fec-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {bb5ea302-8a3b-11e2-9ffe-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {c09951f2-69dc-11e2-9fe1-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {e49b5bca-69d4-11e2-9fe0-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
BootExecute: autocheck autochk * OODBSC:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
ProxyServer: proxy.karneval.cz:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_07\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_07\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -&Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU -&Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 6275069656
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default
FF user.js: detected! => C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\user.js
FF SearchEngine: ICQ Search
FF Homepage: hxxp://www.centrum.cz/
FF Keyword.URL: hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=
FF NetworkProxy: "ftp", "proxy.karneval.cz"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "gopher", "proxy.karneval.cz"
FF NetworkProxy: "gopher_port", 3128
FF NetworkProxy: "http", "proxy.karneval.cz"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "proxy.karneval.cz"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "proxy.karneval.cz"
FF NetworkProxy: "ssl_port", 3128
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre1.7.0_07\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.2088 - C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1069 - C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Centrum doménový pomocník - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\centrumpomocnik@centrum.cz
FF Extension: Centrum.cz nastavení - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Seznam lištička - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\Extensions.rdf
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\installed-extensions.txt
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Mozilla Firefox 19.0.2\Extensions: [Components] C:\Program Files\Mozilla Firefox\components
FF Extension: No Name - C:\Program Files\Mozilla Firefox\components
FF HKLM\...\Mozilla Firefox 19.0.2\Extensions: [Plugins] C:\Program Files\Mozilla Firefox\plugins
========================== Services (Whitelisted) =================
R2 ACS; C:\WINDOWS\system32\acs.exe [36864 2004-12-27] ()
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.)
R2 InCDsrv; C:\Program Files\Ahead\InCD\InCDsrv.exe [876032 2005-07-25] (Nero AG)
R2 O&O Defrag; C:\WINDOWS\system32\oodag.exe [184320 2004-05-17] (O&O Software GmbH)
S2 SymWSC; C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe [308352 2004-08-05] (Symantec Corporation)
S2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [827499 2004-12-21] (Broadcom Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe" -service -config "C:\Program Files\Java\jre1.7.0_07\lib\deploy\jqs\jqs.conf" [x]
S2 winmgmt; C:\DOCUME~1\ALLUSE~1\DATAAP~1\88jee.dat [x]
==================== Drivers (Whitelisted) ====================
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [17801 2005-04-11] (Meetinghouse Data Communications)
S3 AG120(ZyXEL); C:\Windows\System32\DRIVERS\AG120.sys [332800 2006-07-20] (ZyDAS Technology Corporation)
R3 ALCXWDM; C:\Windows\System32\drivers\ALCXWDM.SYS [4026112 2006-12-29] (Realtek Semiconductor Corp.)
S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [449888 2005-01-10] (Atheros Communications, Inc.)
R3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [970240 2005-02-08] (ATI Technologies Inc.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [179936 2012-10-22] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [55776 2012-10-15] (AVG Technologies CZ, s.r.o. )
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [19936 2012-09-21] (AVG Technologies CZ, s.r.o. )
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [159712 2012-10-02] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [177376 2012-09-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [94048 2012-11-15] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35552 2012-09-14] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [164832 2012-09-21] (AVG Technologies CZ, s.r.o.)
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [369024 2004-12-21] (Broadcom Corporation)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-01-14] (SlySoft, Inc.)
R2 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [15440 2007-01-14] (Elaborate Bytes AG)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
R3 HSFHWATI; C:\Windows\System32\DRIVERS\HSFHWATI.sys [200192 2004-12-15] (Conexant Systems, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [66688 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2012-03-16] (Huawei Technologies Co., Ltd.)
R0 imagedrv; C:\Windows\System32\Drivers\imagedrv.sys [5504 2004-03-02] (Ahead Software AG)
R0 imagesrv; C:\Windows\System32\DRIVERS\imagesrv.sys [125184 2004-03-02] (Ahead Software AG)
R4 InCDfs; C:\Windows\System32\Drivers\InCDfs.sys [101504 2005-07-25] (Nero AG)
R1 InCDPass; C:\Windows\System32\DRIVERS\InCDPass.sys [29696 2005-07-25] (Nero AG)
U1 InCDrec; C:\Windows\System32\Drivers\InCDrec.sys [8704 2005-07-25] (Nero AG)
R1 incdrm; C:\Windows\System32\Drivers\incdrm.sys [28672 2005-07-25] (Nero AG)
R3 int15.sys; C:\Program Files\acer\eRecovery\int15.sys [69632 2005-01-13] ()
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2003-12-05] (Padus, Inc.)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 RTL8023xp; C:\Windows\System32\DRIVERS\Rtlnicxp.sys [70912 2004-12-01] (Realtek Semiconductor Corporation )
S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
S3 SNP325; C:\Windows\System32\DRIVERS\snp325.sys [10343168 2007-04-26] (Sonix Co. Ltd.)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
S4 Abiosdsk; No ImagePath
S4 Atdisk; No ImagePath
S3 Cap7134; system32\DRIVERS\Cap7134.sys [x]
S1 Changer; No ImagePath
S1 lbrtfdc; No ImagePath
S2 osaio; \SystemRoot\system32\drivers\osaio.sys [x]
S2 osanbm; \SystemRoot\system32\drivers\osanbm.sys [x]
S3 PCASp50; System32\Drivers\PCASp50.sys [x]
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S3 PhTVTune; system32\DRIVERS\PhTVTune.sys [x]
S3 POWERKEY; \??\C:\Program Files\Launch Manager\POWERKEY.sys [x]
S4 Simbad; No ImagePath
S3 WDICA; No ImagePath
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-01 21:19 - 2013-07-01 21:19 - 00000000 ____D C:\FRST
2013-07-01 21:17 - 2013-07-01 21:17 - 00000692 ____A C:\Windows\System32\eRLog.ini
2013-07-01 21:15 - 2013-07-01 21:15 - 00000096 ____A C:\Windows\ComponentList.xml
2013-07-01 21:14 - 2013-07-01 21:14 - 00000000 __SHD C:\FOUND.003
2013-06-25 15:19 - 2013-07-01 21:15 - 00000636 ___AH C:\Windows\Tasks\Norton Product InstallerIdle.job
2013-06-25 15:19 - 2013-07-01 21:15 - 00000628 ____A C:\Windows\Tasks\Norton Product Installer.job
2013-06-25 15:17 - 2013-06-25 15:17 - 00000000 __SHD C:\FOUND.002
2013-06-25 15:11 - 2013-06-25 15:11 - 00001566 ____A C:\Windows\wmsetup.log
2013-06-25 15:10 - 2013-06-25 15:10 - 00000000 ____D C:\Windows\System32\Adobe
==================== One Month Modified Files and Folders ========
2013-07-01 21:19 - 2013-07-01 21:19 - 00000000 ____D C:\FRST
2013-07-01 21:18 - 2013-05-22 09:15 - 00010787 ____A C:\Windows\setupapi.log
2013-07-01 21:18 - 2006-02-02 12:41 - 00000714 ____A C:\Documents and Settings\michal\wincmd.ini
2013-07-01 21:17 - 2013-07-01 21:17 - 00000692 ____A C:\Windows\System32\eRLog.ini
2013-07-01 21:17 - 1980-01-01 00:00 - 00001158 ____A C:\Windows\System32\wpa.dbl
2013-07-01 21:16 - 1980-01-01 00:00 - 00000550 ____A C:\Windows\win.ini
2013-07-01 21:15 - 2013-07-01 21:15 - 00000096 ____A C:\Windows\ComponentList.xml
2013-07-01 21:15 - 2013-06-25 15:19 - 00000636 ___AH C:\Windows\Tasks\Norton Product InstallerIdle.job
2013-07-01 21:15 - 2013-06-25 15:19 - 00000628 ____A C:\Windows\Tasks\Norton Product Installer.job
2013-07-01 21:15 - 2004-09-17 12:06 - 00000159 ____A C:\Windows\wiadebug.log
2013-07-01 21:14 - 2013-07-01 21:14 - 00000000 __SHD C:\FOUND.003
2013-07-01 21:14 - 2005-10-31 08:06 - 00363168 ____A C:\Windows\System32\OODBS.lor
2013-07-01 21:14 - 2005-07-11 16:48 - 00000062 __ASH C:\Documents and Settings\michal\Local Settings\desktop.ini
2013-07-01 21:14 - 2004-09-17 12:16 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-07-01 21:14 - 2004-09-17 12:16 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-25 15:25 - 2012-04-20 20:55 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-06-25 15:17 - 2013-06-25 15:17 - 00000000 __SHD C:\FOUND.002
2013-06-25 15:11 - 2013-06-25 15:11 - 00001566 ____A C:\Windows\wmsetup.log
2013-06-25 15:10 - 2013-06-25 15:10 - 00000000 ____D C:\Windows\System32\Adobe
2013-06-25 15:06 - 2013-01-10 09:36 - 01651936 ____A C:\Windows\WindowsUpdate.log
2013-06-10 12:43 - 2005-07-11 16:48 - 00000178 ___SH C:\Documents and Settings\michal\ntuser.ini
2013-06-10 12:43 - 2004-09-17 12:06 - 00000048 ____A C:\Windows\wiaservc.log
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[1980-01-01 00:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[1980-01-01 00:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[1980-01-01 00:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-06-2013
Ran by michal (administrator) on 01-07-2013 21:19:33
Running from C:\Documents and Settings\michal\Plocha
Microsoft Windows XP Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [preload] C:\Windows\RUNXMLPL.exe [40960 2004-04-20] (Wistron)
HKLM\...\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [102491 2005-01-08] (Synaptics, Inc.)
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [692315 2005-01-08] (Synaptics, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY [x]
HKLM\...\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [339968 2005-02-08] (ATI Technologies, Inc.)
HKLM\...\Run: [eRecoveryService] C:\Windows\System32\Check.exe [245760 2005-03-23] (acer Inc.)
HKLM\...\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.)
HKLM\...\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe [1397760 2005-07-25] (Nero AG)
HKLM\...\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray [143360 2004-11-25] (Nokia)
HKLM\...\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE [1068032 2004-12-09] (Nokia Mobile Phones Ltd.)
HKLM\...\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s [57344 2006-09-28] (SlySoft, Inc.)
HKLM\...\Run: [RegistryMechanic] [x]
HKLM\...\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui [253952 2005-01-31] (Atheros Communications, Inc.)
HKLM\...\Run: [SoundMan] SOUNDMAN.EXE [x]
HKLM\...\Run: [FixCamera] C:\WINDOWS\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp325] C:\WINDOWS\tsnp325.exe [270336 2007-04-21] ()
HKLM\...\Run: [snp325] C:\WINDOWS\vsnp325.exe [835584 2007-04-25] ()
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent [69632 2012-03-20] (Vodafone)
HKLM\...\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [SymInstallStub] C:\WINDOWS\system32\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=5 /debug /desktopshortcut=1 /startmenushortcut=1 /launchedby=3 [335776 2013-06-25] (Symantec Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\...\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [1695232 2008-04-14] (Microsoft Corporation)
HKCU\...\Run: [RAMSaverPro] C:\Program Files\WinTools\RAM Saver Pro\ramsaverpro.exe [77824 2006-12-13] ()
HKCU\...\Run: [ctfmon32.exe] C:\DOCUME~1\ALLUSE~1\DATAAP~1\rundll32.exe C:\DOCUME~1\ALLUSE~1\DATAAP~1\88jee.dat,XFG00 [x] <===== ATTENTION
MountPoints2: {0a6b2edc-8197-11e2-9ff7-000e9bbfc587} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {108d712c-4d0c-11e2-9fcf-000ae4e102c4} - F:\Toshiba\Launcher\start.exe
MountPoints2: {1f374922-5a2d-11e2-9fde-000ae4e102c4} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {1f374923-5a2d-11e2-9fde-000ae4e102c4} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {431be504-7c16-11e2-9ff6-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {45a9bf54-8bce-11e2-a001-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {4904b514-69eb-11e2-9fe4-001e101fcbdc} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {7b6b6e54-8a3d-11e2-9fff-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {a5022804-7109-11e2-9feb-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {b6354008-71df-11e2-9fec-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {bb5ea302-8a3b-11e2-9ffe-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {c09951f2-69dc-11e2-9fe1-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {e49b5bca-69d4-11e2-9fe0-000e9bbfc587} - F:\setup_vmb_lite.exe /checkApplicationPresence
BootExecute: autocheck autochk * OODBSC:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
ProxyServer: proxy.karneval.cz:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_07\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_07\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -&Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU -&Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 6275069656
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default
FF user.js: detected! => C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\user.js
FF SearchEngine: ICQ Search
FF Homepage: hxxp://www.centrum.cz/
FF Keyword.URL: hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=
FF NetworkProxy: "ftp", "proxy.karneval.cz"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "gopher", "proxy.karneval.cz"
FF NetworkProxy: "gopher_port", 3128
FF NetworkProxy: "http", "proxy.karneval.cz"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "proxy.karneval.cz"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "proxy.karneval.cz"
FF NetworkProxy: "ssl_port", 3128
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre1.7.0_07\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.2088 - C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1069 - C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Centrum doménový pomocník - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\centrumpomocnik@centrum.cz
FF Extension: Centrum.cz nastavení - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Seznam lištička - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\Extensions.rdf
FF Extension: No Name - C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\Extensions\installed-extensions.txt
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Mozilla Firefox 19.0.2\Extensions: [Components] C:\Program Files\Mozilla Firefox\components
FF Extension: No Name - C:\Program Files\Mozilla Firefox\components
FF HKLM\...\Mozilla Firefox 19.0.2\Extensions: [Plugins] C:\Program Files\Mozilla Firefox\plugins
========================== Services (Whitelisted) =================
R2 ACS; C:\WINDOWS\system32\acs.exe [36864 2004-12-27] ()
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.)
R2 InCDsrv; C:\Program Files\Ahead\InCD\InCDsrv.exe [876032 2005-07-25] (Nero AG)
R2 O&O Defrag; C:\WINDOWS\system32\oodag.exe [184320 2004-05-17] (O&O Software GmbH)
S2 SymWSC; C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe [308352 2004-08-05] (Symantec Corporation)
S2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [827499 2004-12-21] (Broadcom Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe" -service -config "C:\Program Files\Java\jre1.7.0_07\lib\deploy\jqs\jqs.conf" [x]
S2 winmgmt; C:\DOCUME~1\ALLUSE~1\DATAAP~1\88jee.dat [x]
==================== Drivers (Whitelisted) ====================
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [17801 2005-04-11] (Meetinghouse Data Communications)
S3 AG120(ZyXEL); C:\Windows\System32\DRIVERS\AG120.sys [332800 2006-07-20] (ZyDAS Technology Corporation)
R3 ALCXWDM; C:\Windows\System32\drivers\ALCXWDM.SYS [4026112 2006-12-29] (Realtek Semiconductor Corp.)
S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [449888 2005-01-10] (Atheros Communications, Inc.)
R3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [970240 2005-02-08] (ATI Technologies Inc.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [179936 2012-10-22] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [55776 2012-10-15] (AVG Technologies CZ, s.r.o. )
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [19936 2012-09-21] (AVG Technologies CZ, s.r.o. )
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [159712 2012-10-02] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [177376 2012-09-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [94048 2012-11-15] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35552 2012-09-14] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [164832 2012-09-21] (AVG Technologies CZ, s.r.o.)
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [369024 2004-12-21] (Broadcom Corporation)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-01-14] (SlySoft, Inc.)
R2 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [15440 2007-01-14] (Elaborate Bytes AG)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
R3 HSFHWATI; C:\Windows\System32\DRIVERS\HSFHWATI.sys [200192 2004-12-15] (Conexant Systems, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [66688 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2012-03-16] (Huawei Technologies Co., Ltd.)
R0 imagedrv; C:\Windows\System32\Drivers\imagedrv.sys [5504 2004-03-02] (Ahead Software AG)
R0 imagesrv; C:\Windows\System32\DRIVERS\imagesrv.sys [125184 2004-03-02] (Ahead Software AG)
R4 InCDfs; C:\Windows\System32\Drivers\InCDfs.sys [101504 2005-07-25] (Nero AG)
R1 InCDPass; C:\Windows\System32\DRIVERS\InCDPass.sys [29696 2005-07-25] (Nero AG)
U1 InCDrec; C:\Windows\System32\Drivers\InCDrec.sys [8704 2005-07-25] (Nero AG)
R1 incdrm; C:\Windows\System32\Drivers\incdrm.sys [28672 2005-07-25] (Nero AG)
R3 int15.sys; C:\Program Files\acer\eRecovery\int15.sys [69632 2005-01-13] ()
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2003-12-05] (Padus, Inc.)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 RTL8023xp; C:\Windows\System32\DRIVERS\Rtlnicxp.sys [70912 2004-12-01] (Realtek Semiconductor Corporation )
S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
S3 SNP325; C:\Windows\System32\DRIVERS\snp325.sys [10343168 2007-04-26] (Sonix Co. Ltd.)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
S4 Abiosdsk; No ImagePath
S4 Atdisk; No ImagePath
S3 Cap7134; system32\DRIVERS\Cap7134.sys [x]
S1 Changer; No ImagePath
S1 lbrtfdc; No ImagePath
S2 osaio; \SystemRoot\system32\drivers\osaio.sys [x]
S2 osanbm; \SystemRoot\system32\drivers\osanbm.sys [x]
S3 PCASp50; System32\Drivers\PCASp50.sys [x]
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S3 PhTVTune; system32\DRIVERS\PhTVTune.sys [x]
S3 POWERKEY; \??\C:\Program Files\Launch Manager\POWERKEY.sys [x]
S4 Simbad; No ImagePath
S3 WDICA; No ImagePath
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-01 21:19 - 2013-07-01 21:19 - 00000000 ____D C:\FRST
2013-07-01 21:17 - 2013-07-01 21:17 - 00000692 ____A C:\Windows\System32\eRLog.ini
2013-07-01 21:15 - 2013-07-01 21:15 - 00000096 ____A C:\Windows\ComponentList.xml
2013-07-01 21:14 - 2013-07-01 21:14 - 00000000 __SHD C:\FOUND.003
2013-06-25 15:19 - 2013-07-01 21:15 - 00000636 ___AH C:\Windows\Tasks\Norton Product InstallerIdle.job
2013-06-25 15:19 - 2013-07-01 21:15 - 00000628 ____A C:\Windows\Tasks\Norton Product Installer.job
2013-06-25 15:17 - 2013-06-25 15:17 - 00000000 __SHD C:\FOUND.002
2013-06-25 15:11 - 2013-06-25 15:11 - 00001566 ____A C:\Windows\wmsetup.log
2013-06-25 15:10 - 2013-06-25 15:10 - 00000000 ____D C:\Windows\System32\Adobe
==================== One Month Modified Files and Folders ========
2013-07-01 21:19 - 2013-07-01 21:19 - 00000000 ____D C:\FRST
2013-07-01 21:18 - 2013-05-22 09:15 - 00010787 ____A C:\Windows\setupapi.log
2013-07-01 21:18 - 2006-02-02 12:41 - 00000714 ____A C:\Documents and Settings\michal\wincmd.ini
2013-07-01 21:17 - 2013-07-01 21:17 - 00000692 ____A C:\Windows\System32\eRLog.ini
2013-07-01 21:17 - 1980-01-01 00:00 - 00001158 ____A C:\Windows\System32\wpa.dbl
2013-07-01 21:16 - 1980-01-01 00:00 - 00000550 ____A C:\Windows\win.ini
2013-07-01 21:15 - 2013-07-01 21:15 - 00000096 ____A C:\Windows\ComponentList.xml
2013-07-01 21:15 - 2013-06-25 15:19 - 00000636 ___AH C:\Windows\Tasks\Norton Product InstallerIdle.job
2013-07-01 21:15 - 2013-06-25 15:19 - 00000628 ____A C:\Windows\Tasks\Norton Product Installer.job
2013-07-01 21:15 - 2004-09-17 12:06 - 00000159 ____A C:\Windows\wiadebug.log
2013-07-01 21:14 - 2013-07-01 21:14 - 00000000 __SHD C:\FOUND.003
2013-07-01 21:14 - 2005-10-31 08:06 - 00363168 ____A C:\Windows\System32\OODBS.lor
2013-07-01 21:14 - 2005-07-11 16:48 - 00000062 __ASH C:\Documents and Settings\michal\Local Settings\desktop.ini
2013-07-01 21:14 - 2004-09-17 12:16 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-07-01 21:14 - 2004-09-17 12:16 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-25 15:25 - 2012-04-20 20:55 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-06-25 15:17 - 2013-06-25 15:17 - 00000000 __SHD C:\FOUND.002
2013-06-25 15:11 - 2013-06-25 15:11 - 00001566 ____A C:\Windows\wmsetup.log
2013-06-25 15:10 - 2013-06-25 15:10 - 00000000 ____D C:\Windows\System32\Adobe
2013-06-25 15:06 - 2013-01-10 09:36 - 01651936 ____A C:\Windows\WindowsUpdate.log
2013-06-10 12:43 - 2005-07-11 16:48 - 00000178 ___SH C:\Documents and Settings\michal\ntuser.ini
2013-06-10 12:43 - 2004-09-17 12:06 - 00000048 ____A C:\Windows\wiaservc.log
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[1980-01-01 00:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[1980-01-01 00:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[1980-01-01 00:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================