Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-11-2013 01
Ran by Admin (administrator) on ACER on 13-11-2013 21:50:36
Running from C:\Documents and Settings\Admin\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(VER_COMPANY_NAME) C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbrmon.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor Corp.) C:\DOCUME~1\Admin\LOCALS~1\Temp\RtkBtMnt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe
(forum.viry.cz) C:\Documents and Settings\Admin\Plocha\FRSTLauncher.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
() C:\DOCUME~1\Admin\LOCALS~1\DATAAP~1\MSGBOX.EXE
(Microsoft Corporation) C:\WINDOWS\system32\ping.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.exe [16132608 2007-05-28] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\Alcmtr.exe [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AzMixerSel] - C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-06-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1130504 2009-08-28] (Dritek System Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-07] (Synaptics, Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [VideoDownloadConverter Search Scope Monitor] - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrchMn.exe [44784 2013-09-10] (MindSpark)
HKLM\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader] - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe [30096 2013-09-10] (VER_COMPANY_NAME)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-07-30] (Google Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://seznam.cz/
URLSearchHook: HKCU - (No Name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL =
http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL =
http://search.tb.ask.com/search/GGmain. ... earchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
Toolbar: HKLM - VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - VideoDownloadConverter - {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{8CB92BE5-4996-4ECA-8389-0ADEA86F14E0}: [NameServer]10.0.0.138
Chrome:
=======
CHR HomePage: hxxp://
www.google.com
CHR RestoreOnStartup: "hxxp://
www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Wallet) - C:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Instagram for Chrome) - C:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb\4.9.2_0
========================== Services (Whitelisted) =================
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-08-12] (Microsoft Corporation)
S2 VideoDownloadConverter_4zService; C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbarsvc.exe [42504 2013-09-10] (COMPANYVERS_NAME)
==================== Drivers (Whitelisted) ====================
S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [546976 2007-05-02] (Atheros Communications, Inc.)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1318464 2008-08-14] (Atheros Communications, Inc.)
R3 btaudio; C:\Windows\System32\drivers\btaudio.sys [539072 2007-03-23] (Broadcom Corporation.)
R3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [37424 2007-03-23] (Broadcom Corporation.)
R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [876384 2007-03-31] (Broadcom Corporation.)
S3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [149123 2007-03-23] (Broadcom Corporation.)
S3 btwhid; C:\Windows\System32\DRIVERS\btwhid.sys [55352 2007-03-31] (Broadcom Corporation.)
S3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [67960 2007-03-23] (Broadcom Corporation.)
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [210688 2007-03-01] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [988032 2007-03-01] (Conexant Systems, Inc.)
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [24448 2009-12-15] (Huawei Tech. Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R1 tidnet; C:\Windows\System32\DRIVERS\tidnet.sys [19200 2009-09-15] (Telefónica I+D)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113280 2009-12-15] (Huawei Technologies Co., Ltd.)
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-13 21:50 - 2013-11-13 21:51 - 00010933 _____ C:\Documents and Settings\Admin\Plocha\FRST.txt
2013-11-13 21:50 - 2013-11-13 21:50 - 00029696 _____ C:\Documents and Settings\Admin\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-13 21:50 - 2013-11-13 21:50 - 00000000 ____D C:\FRST
2013-11-13 21:47 - 2013-11-13 21:47 - 00112128 _____ (forum.viry.cz) C:\Documents and Settings\Admin\Plocha\FRSTLauncher.exe
2013-11-13 21:45 - 2013-11-13 21:45 - 01090351 _____ (Farbar) C:\Documents and Settings\Admin\Plocha\FRST.exe
2013-11-13 18:23 - 2013-11-13 18:23 - 00267008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-13 18:23 - 2013-11-13 18:23 - 00068256 _____ C:\Documents and Settings\Admin\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-05 23:52 - 2013-11-06 06:12 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\kettler
2013-10-27 05:34 - 2013-10-27 06:50 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\chaloupka, r. + kol, vybrané kapitoly z ltv ve spondylochirurgii, ivpz, berno, 2003
2013-10-17 23:10 - 2013-10-17 23:10 - 00000062 _____ C:\WINDOWS\pcvcdbr.INI
2013-10-17 23:10 - 2013-10-17 23:10 - 00000000 _____ C:\WINDOWS\pcvcdvw.INI
2013-10-17 23:09 - 2013-10-17 23:09 - 00000000 ____D C:\MappedFiles
2013-10-15 14:05 - 2013-10-23 22:53 - 00000000 ____D C:\Documents and Settings\Admin\Data aplikací\dvdcss
==================== One Month Modified Files and Folders =======
2013-11-13 21:51 - 2013-11-13 21:50 - 00010933 _____ C:\Documents and Settings\Admin\Plocha\FRST.txt
2013-11-13 21:50 - 2013-11-13 21:50 - 00029696 _____ C:\Documents and Settings\Admin\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-13 21:50 - 2013-11-13 21:50 - 00000000 ____D C:\FRST
2013-11-13 21:50 - 2012-06-19 17:53 - 00000000 ___HD C:\Documents and Settings\Admin\Local Settings\Data aplikací
2013-11-13 21:50 - 2012-06-19 17:53 - 00000000 ____D C:\Documents and Settings\Admin\Plocha
2013-11-13 21:47 - 2013-11-13 21:47 - 00112128 _____ (forum.viry.cz) C:\Documents and Settings\Admin\Plocha\FRSTLauncher.exe
2013-11-13 21:45 - 2013-11-13 21:45 - 01090351 _____ (Farbar) C:\Documents and Settings\Admin\Plocha\FRST.exe
2013-11-13 21:45 - 2013-10-12 06:40 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-13 21:41 - 2012-06-19 17:47 - 01327736 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-13 18:33 - 2013-10-11 21:18 - 00000396 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-11-13 18:23 - 2013-11-13 18:23 - 00267008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-13 18:23 - 2013-11-13 18:23 - 00068256 _____ C:\Documents and Settings\Admin\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-13 18:23 - 2013-10-12 06:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-13 18:23 - 2013-09-10 19:29 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-11-13 18:23 - 2013-09-10 19:29 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-11-13 18:23 - 2012-06-19 17:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-13 18:21 - 2012-06-19 17:53 - 00000000 ____D C:\Documents and Settings\Admin
2013-11-12 21:14 - 2004-08-18 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-11-11 23:50 - 2013-02-09 21:03 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\ortofit
2013-11-11 21:45 - 2012-06-19 17:52 - 00032496 ____N C:\WINDOWS\SchedLgU.Txt
2013-11-10 17:44 - 2012-06-19 19:36 - 01179606 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-09 11:24 - 2012-06-19 17:53 - 00000272 ___SH C:\Documents and Settings\Admin\ntuser.ini
2013-11-07 18:13 - 2013-09-10 20:48 - 00000000 ____D C:\Documents and Settings\Admin\Data aplikací\vlc
2013-11-06 06:12 - 2013-11-05 23:52 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\kettler
2013-11-05 05:51 - 2012-07-22 13:27 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\okna - jiroš
2013-11-02 22:10 - 2013-09-21 05:51 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\já, trénink
2013-10-28 18:50 - 2012-06-19 17:53 - 00000000 ___RD C:\Documents and Settings\Admin\Dokumenty\Obrázky
2013-10-27 06:50 - 2013-10-27 05:34 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\chaloupka, r. + kol, vybrané kapitoly z ltv ve spondylochirurgii, ivpz, berno, 2003
2013-10-26 19:29 - 2013-08-04 18:02 - 00000092 _____ C:\Documents and Settings\Admin\default.pls
2013-10-26 19:29 - 2012-10-15 19:04 - 00000116 _____ C:\WINDOWS\NeroDigital.ini
2013-10-23 22:53 - 2013-10-15 14:05 - 00000000 ____D C:\Documents and Settings\Admin\Data aplikací\dvdcss
2013-10-17 23:10 - 2013-10-17 23:10 - 00000062 _____ C:\WINDOWS\pcvcdbr.INI
2013-10-17 23:10 - 2013-10-17 23:10 - 00000000 _____ C:\WINDOWS\pcvcdvw.INI
2013-10-17 23:09 - 2013-10-17 23:09 - 00000000 ____D C:\MappedFiles
2013-10-16 21:50 - 2012-08-03 12:42 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-10-15 14:05 - 2012-06-19 17:53 - 00000000 __RHD C:\Documents and Settings\Admin\Data aplikací
2013-10-14 05:06 - 2012-11-15 19:40 - 00000000 ____D C:\Documents and Settings\Admin\Plocha\úvn
Files to move or delete:
====================
C:\Documents and Settings\Admin\Data aplikací\cache.ini
Some content of TEMP:
====================
C:\Documents and Settings\Admin\Local Settings\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-18 13:00] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2004-08-18 13:00] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2004-08-18 13:00] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2004-08-18 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2004-08-18 13:00] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2004-08-18 13:00] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 13:00] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================