Všechno beru z5

nakonec jsem se do nouzového režimu dostal. Sice sám nevím jak, ale podařilo se.
Tím pádem sem mužu vložit log.
--------------------------------------------------------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03
Ran by tina (administrator) on TINA-PC on 17-09-2013 14:29:07
Running from F:\
Windows Vista (TM) Ultimate Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode:
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [AVG9_TRAY] - C:\PROGRA~1\AVG\AVG9\avgtray.exe [2077536 2012-02-05] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [facemoods] - C:\Program Files\facemoods.com\facemoods\1.4.17.1\facemoodssrv.exe [323584 2010-10-26] (facemoods.com)
HKLM\...\Run: [TaskTray] - [x]
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1430824 2009-02-06] (Synaptics Incorporated)
HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2010-11-30] (Nullsoft, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [NokiaMServer] - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
HKCU\...\Run: [NokiaOviSuite2] - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [703360 2011-01-31] (Nokia)
HKCU\...\Run: [] - [x]
MountPoints2: {665ddaf9-fc89-11df-a088-000000000000} - F:\Axesstel_Setup.exe
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\tina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qrrj14fr.lnk
ShortcutTarget: qrrj14fr.lnk -> C:\PROGRA~2\rf41jrrq.plz ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://start.facemoods.com/?a=tweak
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
SearchScopes: HKCU - DefaultScope {0D7562AE-8EF6-416d-A838-AB665251703A} URL =
http://start.facemoods.com/?a=tweak&s={searchTerms}&f=4
SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL =
http://start.facemoods.com/?a=tweak&s={searchTerms}&f=4
BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.1\bh\facemoods.dll (facemoods.com BHO)
BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.1\facemoodsTlbr.dll (facemoods.com)
Toolbar: HKLM - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
Toolbar: HKCU -uTorrentBar Toolbar - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
FireFox:
========
FF ProfilePath: C:\Users\tina\AppData\Roaming\Mozilla\Firefox\Profiles\z0kwav2s.default
FF SelectedSearchEngine: Search
FF Homepage: hxxp://
www.seznam.cz/
FF Keyword.URL: hxxp://start.facemoods.com/results.php?f=5&a=tweak&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\fcmdSrchtweak.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Conduit Engine - C:\Users\tina\AppData\Roaming\Mozilla\Firefox\Profiles\z0kwav2s.default\Extensions\
engine@conduit.com
FF Extension: Facemoods - C:\Users\tina\AppData\Roaming\Mozilla\Firefox\Profiles\z0kwav2s.default\Extensions\
ffxtlbr@Facemoods.com
FF Extension: Microsoft .NET Framework Assistant - C:\Users\tina\AppData\Roaming\Mozilla\Firefox\Profiles\z0kwav2s.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: uTorrentBar Community Toolbar - C:\Users\tina\AppData\Roaming\Mozilla\Firefox\Profiles\z0kwav2s.default\Extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}] - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
FF Extension: Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
FF HKLM\...\Thunderbird\Extensions: [{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}] - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\
FF Extension: Thunderbird Address Book Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\
========================== Services (Whitelisted) =================
S2 avg9emc; C:\Program Files\AVG\AVG9\avgemc.exe [921952 2010-11-30] (AVG Technologies CZ, s.r.o.)
R2 avg9wd; C:\Program Files\AVG\AVG9\avgwdsvc.exe [308136 2010-11-30] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [5897808 2010-11-30] (AVG Technologies CZ, s.r.o.)
S2 Winmgmt; C:\PROGRA~2\rf41jrrq.plz [89600 2013-09-10] ()
==================== Drivers (Whitelisted) ====================
R3 AVGIDSDrivervtx; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [122448 2010-11-30] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSErHrvtx; C:\Windows\System32\Drivers\AVGIDSvx.sys [25168 2010-11-30] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFiltervtx; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [30288 2010-11-30] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSShimvtx; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [27216 2010-11-30] (AVG Technologies CZ, s.r.o. )
R1 AvgLdx86; C:\Windows\System32\Drivers\avgldx86.sys [226016 2013-01-16] (AVG Technologies CZ, s.r.o.)
R1 AvgMfx86; C:\Windows\System32\Drivers\avgmfx86.sys [29712 2011-09-13] (AVG Technologies CZ, s.r.o.)
R0 AvgRkx86; C:\Windows\System32\Drivers\avgrkx86.sys [52872 2010-11-30] (AVG Technologies CZ, s.r.o.)
R1 AvgTdiX; C:\Windows\System32\Drivers\avgtdix.sys [243152 2011-05-06] (AVG Technologies CZ, s.r.o.)
S3 Axtmvflt; C:\Windows\System32\DRIVERS\Axtmvflt.sys [3456 2007-03-22] (Axesstel)
S3 Axtmvmdm; C:\Windows\System32\DRIVERS\Axtmvmdm.sys [40064 2007-03-26] (Axesstel)
S3 Axtmvprt; C:\Windows\System32\Drivers\Axtmvprt.sys [38784 2007-03-26] (Axesstel)
R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-19] (Microsoft Corporation)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [192056 2008-01-19] (Společnost Microsoft)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1081912 2008-01-19] (Společnost Microsoft)
S3 se45bus; C:\Windows\System32\DRIVERS\se45bus.sys [61536 2006-11-30] (MCCI)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-17 14:29 - 2013-09-17 14:29 - 00000000 ____D C:\FRST
2013-09-10 17:52 - 2013-09-13 10:20 - 00000000 _____ C:\ProgramData\qrrj14fr.ctrl
2013-09-10 17:52 - 2013-09-10 17:56 - 95025368 ____T C:\ProgramData\qrrj14fr.pff
2013-09-10 17:52 - 2013-09-10 17:52 - 00089600 _____ C:\ProgramData\rf41jrrq.plz
2013-08-28 15:03 - 2013-08-28 15:15 - 00000000 ____D C:\Windows\system32\MRT
2013-08-26 14:08 - 2013-08-26 14:08 - 00005489 _____ C:\Users\tina\Downloads\smime(5).p7s
2013-08-26 14:06 - 2013-08-26 14:06 - 00005489 _____ C:\Users\tina\Downloads\smime(4).p7s
2013-08-26 14:04 - 2013-08-26 14:04 - 00005489 _____ C:\Users\tina\Downloads\smime(3).p7s
2013-08-26 14:03 - 2013-08-26 14:03 - 00005489 _____ C:\Users\tina\Downloads\smime(2).p7s
2013-08-26 14:02 - 2013-08-26 14:02 - 00005489 _____ C:\Users\tina\Downloads\smime.p7s
==================== One Month Modified Files and Folders =======
2013-09-17 14:30 - 2006-11-02 14:51 - 01434647 _____ C:\Windows\WindowsUpdate.log
2013-09-17 14:29 - 2013-09-17 14:29 - 00000000 ____D C:\FRST
2013-09-17 14:24 - 2006-11-02 15:00 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-17 09:39 - 2006-11-02 14:46 - 00033792 _____ C:\Windows\system32\umstartup.etl
2013-09-17 09:38 - 2010-11-26 18:28 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-09-17 09:38 - 2006-11-02 15:00 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-17 09:38 - 2006-11-02 14:51 - 00043847 _____ C:\Windows\setupact.log
2013-09-17 09:34 - 2006-11-02 14:46 - 00004512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-17 09:34 - 2006-11-02 14:46 - 00004512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-13 10:21 - 2010-11-26 18:00 - 00006648 _____ C:\Users\tina\AppData\Local\d3d9caps.dat
2013-09-13 10:20 - 2013-09-10 17:52 - 00000000 _____ C:\ProgramData\qrrj14fr.ctrl
2013-09-13 09:43 - 2010-11-30 16:31 - 00000000 ____D C:\ProgramData\PC Suite
2013-09-10 17:56 - 2013-09-10 17:52 - 95025368 ____T C:\ProgramData\qrrj14fr.pff
2013-09-10 17:52 - 2013-09-10 17:52 - 00089600 _____ C:\ProgramData\rf41jrrq.plz
2013-09-10 17:27 - 2006-11-02 12:33 - 01418258 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-28 15:15 - 2013-08-28 15:03 - 00000000 ____D C:\Windows\system32\MRT
2013-08-28 15:03 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-26 14:08 - 2013-08-26 14:08 - 00005489 _____ C:\Users\tina\Downloads\smime(5).p7s
2013-08-26 14:06 - 2013-08-26 14:06 - 00005489 _____ C:\Users\tina\Downloads\smime(4).p7s
2013-08-26 14:04 - 2013-08-26 14:04 - 00005489 _____ C:\Users\tina\Downloads\smime(3).p7s
2013-08-26 14:03 - 2013-08-26 14:03 - 00005489 _____ C:\Users\tina\Downloads\smime(2).p7s
2013-08-26 14:02 - 2013-08-26 14:02 - 00005489 _____ C:\Users\tina\Downloads\smime.p7s
Files to move or delete:
====================
C:\ProgramData\qrrj14fr.ctrl
C:\ProgramData\qrrj14fr.pff
C:\ProgramData\rf41jrrq.plz
Some content of TEMP:
====================
C:\Users\tina\AppData\Local\Temp\AMPing.exe
C:\Users\tina\AppData\Local\Temp\bbidbiceimuifbpskqj.bfg
C:\Users\tina\AppData\Local\Temp\firefoxjre_exe-1.exe
C:\Users\tina\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\tina\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\tina\AppData\Local\Temp\GLFF0F8.tmp.ConduitEngineSetup.exe
C:\Users\tina\AppData\Local\Temp\ietE1F5.tmp.exe
C:\Users\tina\AppData\Local\Temp\installapi.exe
C:\Users\tina\AppData\Local\Temp\InstallManager_BAB_BAB.exe
C:\Users\tina\AppData\Local\Temp\NEventMessages.dll
C:\Users\tina\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\tina\AppData\Local\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-13 10:50
==================== End Of Log ============================