Stránka 1 z 12

Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 02 pro 2013 22:43
od tamuri
Před nějakou dobou jsem chytla Claro Search; velmi pečlivě jsem se ho zbavovala a vypadalo to, že vše je v pořádku. Nedávno jsem otevřela Google Chrom, který vůbec nepoužívám, a uviděla jsem, že má Claro Search jako domovskou stránku. Nic jsem s tím raději nedělala. Včera mi Avira vydala hlášku, že mám vypnutý Web Protection, aktivovat jej ale žádným způsobem nepodařilo - tlačítko On/Off prostě nefunguje. Je možné, že na tom přece jenom zapracovala nějaká havěť. Pokusila jsem se podle Vašeho návodu vytvořit log, který přikládám, prosím ale mít se mnou strpení, protože asi nebudu hned rozumět všem Vaším radám. Děkuji.

log.txt

Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2010-04-16 11:44:33
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 125 GB (82%) free of 153 GB
Total RAM: 2038 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:40, on 16.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Samsung\Samsung SCX-4500 Series\SPanel\PSU\Scan2pc.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\user\Plocha\Skype.exe
C:\PROGRA~1\ICQ6.5\ICQ.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WG2000\WG2000.EXE
C:\Documents and Settings\user\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Logan_S2P] C:\Program Files\Samsung\Samsung SCX-4500 Series\SPanel\PSU\Scan2pc.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Documents and Settings\user\Plocha\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\PROGRA~1\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Gmail Notifier
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: SmarThru4 Capture Selection - C:\Program Files\SmarThru 4\WebCapture.dll2.htm
O8 - Extra context menu item: SmarThru4 Save as HTML - C:\Program Files\SmarThru 4\WebCapture.dll1.htm
O8 - Extra context menu item: SmarThru4 Save Selected Text - C:\Program Files\SmarThru 4\WebCapture.dll.htm
O8 - Extra context menu item: SmarThru4 Web Capture - C:\Program Files\SmarThru 4\WebCapture.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: SmarThru4 Web Capture - {5941A0E4-56C1-4a49-9B18-05762CAC5F9B} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Web Capture - {5941A0E4-56C1-4a49-9B18-05762CAC5F9B} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Capture Selection - {A07BFEF7-DD11-4937-B23B-E70C11D2EDF4} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Capture Selection - {A07BFEF7-DD11-4937-B23B-E70C11D2EDF4} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Save as HTML - {E753A93F-2367-4978-BFA0-83048C1E61CB} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Save as HTML - {E753A93F-2367-4978-BFA0-83048C1E61CB} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Save Selected Text - {F1F53366-3E11-47ab-BF84-580C94F9C9AD} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Save Selected Text - {F1F53366-3E11-47ab-BF84-580C94F9C9AD} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Služba Google Update (gupdate1ca7803e9217740) (gupdate1ca7803e9217740) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe

--
End of file - 8113 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-06-12 958712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2008-04-10 29757440]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-03-21 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-03-21 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-03-21 137752]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2002-09-25 87751]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"SPAMfighter Agent"=C:\Program Files\SPAMfighter\SFAgent.exe [2009-08-27 336520]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"Logan_S2P"=C:\Program Files\Samsung\Samsung SCX-4500 Series\SPanel\PSU\Scan2pc.exe [2009-09-17 253952]
"Samsung PanelMgr"=C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2009-10-16 614400]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"Skype"=C:\Documents and Settings\user\Plocha\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\PROGRA~1\ICQ6.5\ICQ.exe [2009-03-01 172792]
"VoipBuster"=C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe [2009-11-12 9094448]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění
Gmail Notifier
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-03-17 208896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 02 pro 2013 22:47
od vyosek
Zdravim :)

:arrow: Stahnete Shortcut Cleaner http://www.bleepingcomputer.com/downloa ... t-cleaner/
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Spustte tradicne dvouklikem
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v miste spusteni jako sc-cleaner.txt, ten sem vlozte
:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 11:19
od tamuri
Udělala jsem postupně všechno, co jste poradil, a vše jsem Vám zanášela sem do odpovědi, až na to, že po spuštění posledního Cleanera se mi všechno zapsané a neuložené "vycleanerovalo" (což asi dává rozum, jenom mně ne...), takže začnu znova a od konce:

# AdwCleaner v3.014 - Report created 03/12/2013 at 10:38:41
# Updated 01/12/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : user - USER-9E9A9A8968
# Running from : C:\Documents and Settings\user\Dokumenty\Stažené soubory\adwcleaner(1).exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\WINDOWS\assembly\GAC_MSIL\QuickStoresToolbar
Folder Deleted : C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Documents and Settings\user\Local Settings\Data aplikací\AskToolbar
Folder Deleted : C:\Documents and Settings\user\Local Settings\Data aplikací\Babylon
Folder Deleted : C:\Documents and Settings\user\Local Settings\Data aplikací\iac
Folder Deleted : C:\Documents and Settings\user\Local Settings\Data aplikací\PackageAware
Folder Deleted : C:\Documents and Settings\user\Data aplikací\AskToolbar
Folder Deleted : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\SafePCRepair_89
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\1pk299zj.default\Extensions\toolbar@ask.com
File Deleted : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\searchplugins\ask-search.xml
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E601996F-E400-41CA-804B-CD6373A7EEE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E601996F-E400-41CA-804B-CD6373A7EEE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe]
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\OCS
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\TENCENT
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\QuickStores-Toolbar_is1
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Documents and Settings\LocalService\Data aplikací\Mozilla\Firefox\Profiles\pewf1wsw.default\prefs.js ]


[ File : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\5iqcw0bh.default-1359455467984\prefs.js ]


[ File : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\hij7hrio.default-1352792179828\prefs.js ]


[ File : C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\prefs.js ]


-\\ Google Chrome v

[ File : C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Documents and Settings\user\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]

Deleted : urls_to_restore_on_startup
Deleted : homepage

*************************

AdwCleaner[R0].txt - [12219 octets] - [03/12/2013 10:32:51]
AdwCleaner[S0].txt - [12218 octets] - [03/12/2013 10:38:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12279 octets] ##########



teď shortcut Cleaner:

Shortcut Cleaner 1.2.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/

Windows Version: Microsoft Windows XP Service Pack 3
Program started at: 12/03/2013 10:54:00 AM.

Scanning for registry hijacks:

* No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Documents and Settings\user\Nabídka Start\

Searching C:\Documents and Settings\All Users\Nabídka Start\

Searching C:\Documents and Settings\user\Data aplikací\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Documents and Settings\All Users\Plocha\

Searching C:\Documents and Settings\user\Plocha


0 bad shortcuts found.

Program finished at: 12/03/2013 10:54:01 AM
Execution time: 0 hours(s), 0 minute(s), and 0 seconds(s)


Teď Junkware Removal Tool:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Microsoft Windows XP x86
Ran by user on Łt 03.12.2013 at 10:57:49,34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 03.12.2013 at 11:01:04,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Já jsem vždy používala CCleaner, a tady se chci zeptat, zda ho mám i nadále nechat, anebo nahradit něčím?
Děkuji.

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 11:33
od vyosek
:arrow: AdwCleaner restartujte PC = ukonci prohlizec i s rozepsanou odpovedi

:arrow: CCleaner i nadael pouzivejte, to je jiny cistic. CCLeaner cisti docasne soubory a balats co vznika pri cinnosti. Tyto utility slouzi k vycisteni PC od haveti

:arrow: Udelejte log z FRSTLauncheru dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 12:29
od tamuri
Za půlhodiny musím utíkat, narychlo hodím Addition.txt do přílohy jak je, vrátím se odpoledne.
Zatím děkuji!!!
Ne, nějak mi to nevychází s přílohou - jako že stahuje, ale pak ji nevidím, jenom nápis:Soubor nevybrán.
Omlouvám se - možná se to přiložilo i dvakrát, nebo vůbec...

Tady FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-12-2013
Ran by user (administrator) on USER-9E9A9A8968 on 03-12-2013 12:08:44
Running from C:\Documents and Settings\user\Dokumenty\Stažené soubory
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Software602 a.s.) C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Software602) C:\Program Files\Software602\Print2PDF\Print2PDF.exe
(Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Rynga) C:\Program Files\Rynga.com\Rynga\rynga.exe
(Skype Technologies S.A.) C:\Documents and Settings\user\Plocha\Phone\Skype.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.bin
() C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [AGRSMMSG] - C:\WINDOWS\AGRSMMSG.exe [87751 2002-09-25] (Agere Systems)
HKLM\...\Run: [Print2PDF Print Monitor] - C:\Program Files\Software602\Print2PDF\Print2PDF.exe [220992 2011-10-04] (Software602)
HKLM\...\Run: [LWS] - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM\...\Run: [Samsung PanelMgr] - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [614400 2009-10-16] ()
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [RegHunter Registry Cleaner] - "C:\Program Files\Enigma Software Group\RegHunter\RegHunter.exe" -silent
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-12-01] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [Rynga] - C:\Program Files\Rynga.com\Rynga\rynga.exe [19554608 2013-07-22] (Rynga)
HKCU\...\Run: [HideOE] - "C:\Program Files\Outlook Express\HideOE\HideOE.exe"
HKCU\...\Run: [Skype] - C:\Documents and Settings\user\Plocha\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
MountPoints2: {28fc6282-d98d-11e2-a28b-001fc6caf3ac} - E:\iLinker.exe
MountPoints2: {b3bd9da9-b17b-11dd-89d5-806d6172696f} - D:\autorun.exe
Startup: C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění\OpenOffice 4.0.1.lnk
ShortcutTarget: OpenOffice 4.0.1.lnk -> C:\Program Files\OpenOffice 4\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Documents and Settings\user\Plocha\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8466944 2012-06-08] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-08-24] (SuperAdBlocker.com)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @SafePCRepair_89.com/Plugin - C:\Program Files\SafePCRepair_89\bar\1.bin\NP89Stub.dll No File
FF Plugin: @software602.cz/602XML Filler - C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\searchplugins\amazonde-german.xml
FF SearchPlugin: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\searchplugins\youtube-ssl.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: gmailwatcher - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\gmailwatcher@sonthakit.xpi
FF Extension: IrregularVerbs - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\IrregularVerbs@canevas.xul.xpi
FF Extension: ImTranslator - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll No File
CHR Extension: (Avira Toolbar) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.8.0_0
CHR Extension: (Skype Click to Call) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR Extension: (Chrome In-App Payments service) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Documents and Settings\user\Local Settings\Data aplikací\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

========================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2012-09-08] (SUPERAntiSpyware.com)
R2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
S2 gupdate1ca7803e9217740; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-12-08] (Google Inc.)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
S3 ioloService; C:\Program Files\SafePCRepair\ioloToolService.exe [x]
S2 SafePCRepair_89Service; C:\PROGRA~1\SAFEPC~2\bar\1.bin\89barsvc.exe [x]
S2 SkypeUpdate; "C:\Documents and Settings\user\Plocha\Updater\Updater.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-12-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-01] (Avira Operations GmbH & Co. KG)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 FilterService; C:\Windows\System32\DRIVERS\lvuvcflt.sys [23832 2009-10-07] (Logitech Inc.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51056 2004-02-26] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-02-26] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2005-10-21] (HP)
R3 monfilt; C:\Windows\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-08-24] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-08-24] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-01] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [222976 2008-02-14] (VIA Technologies, Inc.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
S3 RkHit; \??\C:\WINDOWS\system32\drivers\RKHit.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 12:05 - 2013-12-03 12:05 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-03 12:05 - 2013-12-03 12:05 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
2013-12-03 11:58 - 2013-12-03 11:58 - 00000000 ____D C:\FRST
2013-12-03 10:52 - 2013-12-03 10:52 - 00019801 _____ C:\Documents and Settings\user\Plocha\Odpověď_VIRY.odt
2013-12-03 10:32 - 2013-12-03 10:38 - 00000000 ____D C:\AdwCleaner
2013-12-03 10:19 - 2013-12-03 10:19 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-03 10:11 - 2013-12-03 10:54 - 00001870 _____ C:\sc-cleaner.txt
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
2013-12-03 09:23 - 2013-12-03 09:23 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-02 22:10 - 2013-12-02 22:10 - 00018617 _____ C:\Documents and Settings\user\Dokumenty\log.odt
2013-12-02 22:08 - 2013-12-02 22:08 - 00015754 _____ C:\Documents and Settings\user\Dokumenty\HijackThis.odt
2013-12-02 08:47 - 2013-12-02 08:50 - 00012480 _____ C:\Documents and Settings\user\Plocha\КОМБИНАЦИИ НА КЛАВИАТУРЕ.odt
2013-12-01 23:28 - 2013-12-03 11:59 - 00000464 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job
2013-12-01 20:14 - 2013-12-01 20:15 - 00003525 _____ C:\WINDOWS\ie8Uninst.log
2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Avira
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
2013-12-01 08:13 - 2013-12-01 08:13 - 00001707 _____ C:\Documents and Settings\All Users\Plocha\Avira Control Center.lnk
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Program Files\Avira
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
2013-12-01 08:13 - 2013-12-01 08:12 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Mozilla
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací\Mozilla
2013-11-30 10:51 - 2013-11-30 10:51 - 00016486 _____ C:\Documents and Settings\user\Dokumenty\Шишки на ногах (hallux).odt
2013-11-30 10:20 - 2013-11-30 10:20 - 00018442 _____ C:\Documents and Settings\user\Dokumenty\Продукты, которые нельзя есть натощак.odt
2013-11-30 10:15 - 2013-11-30 10:15 - 00034660 _____ C:\Documents and Settings\user\Dokumenty\Торт Наполеон (слоёный, быстрый).odt
2013-11-30 09:48 - 2013-11-30 09:48 - 00034137 _____ C:\Documents and Settings\user\Dokumenty\Как избавиться от холки на шее.odt
2013-11-27 11:30 - 2013-11-27 11:31 - 00054074 _____ C:\Documents and Settings\user\Dokumenty\Good News_Happiness Doesn’t Exist.odt
2013-11-23 22:08 - 2013-11-23 22:08 - 00033721 _____ C:\Documents and Settings\user\Dokumenty\НОСКИ.odt
2013-11-18 10:25 - 2013-11-18 10:25 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\SightSpeed Recordings
2013-11-16 08:08 - 2013-11-16 21:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 10:35 - 2013-12-01 23:29 - 00172959 _____ C:\WINDOWS\KB2888505-IE8.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00008892 _____ C:\WINDOWS\KB2900986.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00004392 _____ C:\WINDOWS\updspapi.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-14 08:37 - 2013-11-14 10:35 - 00014535 _____ C:\WINDOWS\KB2868626.log
2013-11-14 08:37 - 2013-11-14 10:35 - 00013508 _____ C:\WINDOWS\KB2862152.log
2013-11-14 08:37 - 2013-11-14 10:35 - 00013037 _____ C:\WINDOWS\KB2876331.log
2013-11-03 16:40 - 2013-11-03 16:40 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\Fighters
2013-11-03 14:24 - 2013-12-01 20:50 - 00050678 _____ C:\WINDOWS\FaxSetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00029274 _____ C:\WINDOWS\ocgen.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00022002 _____ C:\WINDOWS\tsoc.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00017120 _____ C:\WINDOWS\comsetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00010767 _____ C:\WINDOWS\ntdtcsetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00007934 _____ C:\WINDOWS\iis6.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00003254 _____ C:\WINDOWS\ocmsn.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00002812 _____ C:\WINDOWS\msgsocm.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00001917 _____ C:\WINDOWS\imsins.log
2013-11-03 14:24 - 2013-12-01 20:15 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setupact.log
2013-11-03 13:06 - 2013-12-01 20:50 - 00013826 _____ C:\WINDOWS\setupapi.log
2013-11-03 13:01 - 2013-11-03 14:25 - 00000000 ____D C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP

==================== One Month Modified Files and Folders =======

2013-12-03 12:08 - 2010-02-05 19:02 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\Stažené soubory
2013-12-03 12:05 - 2013-12-03 12:05 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-03 12:05 - 2013-12-03 12:05 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
2013-12-03 12:05 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Plocha
2013-12-03 12:05 - 2008-11-13 15:38 - 00000000 ___HD C:\Documents and Settings\user\Local Settings\Data aplikací
2013-12-03 11:59 - 2013-12-01 23:28 - 00000464 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job
2013-12-03 11:58 - 2013-12-03 11:58 - 00000000 ____D C:\FRST
2013-12-03 11:40 - 2008-12-02 19:19 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Skype
2013-12-03 11:29 - 2009-12-08 13:54 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-03 11:15 - 2012-07-15 21:09 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-03 11:06 - 2009-07-02 07:35 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-03 10:54 - 2013-12-03 10:11 - 00001870 _____ C:\sc-cleaner.txt
2013-12-03 10:52 - 2013-12-03 10:52 - 00019801 _____ C:\Documents and Settings\user\Plocha\Odpověď_VIRY.odt
2013-12-03 10:41 - 2008-11-13 15:32 - 01999577 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-03 10:40 - 2012-11-20 10:05 - 00000270 _____ C:\WINDOWS\Tasks\RMAutoUpdate.job
2013-12-03 10:40 - 2010-08-21 11:09 - 00000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2013-12-03 10:40 - 2009-12-08 13:54 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-03 10:40 - 2008-11-13 15:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-03 10:40 - 2008-11-13 13:16 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-03 10:40 - 2008-11-13 13:16 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-12-03 10:39 - 2008-11-13 15:38 - 00000272 ___SH C:\Documents and Settings\user\ntuser.ini
2013-12-03 10:39 - 2008-11-13 15:36 - 00032562 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-03 10:38 - 2013-12-03 10:32 - 00000000 ____D C:\AdwCleaner
2013-12-03 10:38 - 2008-11-13 15:38 - 00000000 __RHD C:\Documents and Settings\user\Data aplikací
2013-12-03 10:36 - 2010-02-10 22:21 - 03603896 ___SH C:\Documents and Settings\user\Plocha\Thumbs.db
2013-12-03 10:36 - 2010-02-10 22:21 - 00005632 ___SH C:\Documents and Settings\user\Thumbs.db
2013-12-03 10:19 - 2013-12-03 10:19 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
2013-12-03 09:27 - 2008-11-13 13:13 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-12-03 09:26 - 2008-11-13 13:14 - 01137738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-03 09:23 - 2013-12-03 09:23 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-03 09:06 - 2009-12-28 21:50 - 00003411 _____ C:\WINDOWS\wg2000.ini
2013-12-03 09:06 - 2009-09-18 15:47 - 00000021 _____ C:\WINDOWS\wk2000.ini
2013-12-03 09:06 - 2009-09-18 15:47 - 00000018 _____ C:\WINDOWS\winklav.ini
2013-12-03 09:00 - 2009-09-19 07:35 - 00000304 _____ C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
2013-12-03 08:59 - 2009-11-26 13:48 - 00000000 ____D C:\Program Files\BigPatience
2013-12-02 22:49 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty
2013-12-02 22:10 - 2013-12-02 22:10 - 00018617 _____ C:\Documents and Settings\user\Dokumenty\log.odt
2013-12-02 22:08 - 2013-12-02 22:08 - 00015754 _____ C:\Documents and Settings\user\Dokumenty\HijackThis.odt
2013-12-02 19:11 - 2010-04-16 10:44 - 00000000 ____D C:\Program Files\trend micro
2013-12-02 08:50 - 2013-12-02 08:47 - 00012480 _____ C:\Documents and Settings\user\Plocha\КОМБИНАЦИИ НА КЛАВИАТУРЕ.odt
2013-12-02 08:13 - 2004-08-18 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-01 23:29 - 2013-11-14 10:35 - 00172959 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00050678 _____ C:\WINDOWS\FaxSetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00029274 _____ C:\WINDOWS\ocgen.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00022002 _____ C:\WINDOWS\tsoc.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00017120 _____ C:\WINDOWS\comsetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00010767 _____ C:\WINDOWS\ntdtcsetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00007934 _____ C:\WINDOWS\iis6.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00003254 _____ C:\WINDOWS\ocmsn.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00002812 _____ C:\WINDOWS\msgsocm.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00001917 _____ C:\WINDOWS\imsins.log
2013-12-01 20:50 - 2013-11-03 13:06 - 00013826 _____ C:\WINDOWS\setupapi.log
2013-12-01 20:15 - 2013-12-01 20:14 - 00003525 _____ C:\WINDOWS\ie8Uninst.log
2013-12-01 20:15 - 2013-11-03 14:24 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-12-01 19:51 - 2009-09-22 17:52 - 00000000 ____D C:\Program Files\Google
2013-12-01 19:51 - 2008-11-13 13:14 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Avira
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
2013-12-01 08:13 - 2013-12-01 08:13 - 00001707 _____ C:\Documents and Settings\All Users\Plocha\Avira Control Center.lnk
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Program Files\Avira
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
2013-12-01 08:13 - 2011-10-19 17:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avira
2013-12-01 08:13 - 2008-11-13 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-01 08:12 - 2013-12-01 08:13 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Mozilla
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací\Mozilla
2013-11-30 20:32 - 2008-11-13 15:36 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2013-11-30 20:32 - 2008-11-13 15:36 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací
2013-11-30 20:05 - 2010-02-02 13:52 - 00000000 ____D C:\WINDOWS\system32\NtmsData
2013-11-30 20:02 - 2012-10-30 09:18 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\CallingID
2013-11-30 18:30 - 2012-10-30 09:18 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\DoNotTrackPlus
2013-11-30 10:51 - 2013-11-30 10:51 - 00016486 _____ C:\Documents and Settings\user\Dokumenty\Шишки на ногах (hallux).odt
2013-11-30 10:20 - 2013-11-30 10:20 - 00018442 _____ C:\Documents and Settings\user\Dokumenty\Продукты, которые нельзя есть натощак.odt
2013-11-30 10:15 - 2013-11-30 10:15 - 00034660 _____ C:\Documents and Settings\user\Dokumenty\Торт Наполеон (слоёный, быстрый).odt
2013-11-30 09:48 - 2013-11-30 09:48 - 00034137 _____ C:\Documents and Settings\user\Dokumenty\Как избавиться от холки на шее.odt
2013-11-30 09:30 - 2008-11-13 15:31 - 00000000 ____D C:\WINDOWS\Registration
2013-11-29 20:47 - 2008-11-18 17:46 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\Разное
2013-11-28 06:41 - 2008-11-18 17:46 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\Рецепты
2013-11-27 11:31 - 2013-11-27 11:30 - 00054074 _____ C:\Documents and Settings\user\Dokumenty\Good News_Happiness Doesn’t Exist.odt
2013-11-23 22:08 - 2013-11-23 22:08 - 00033721 _____ C:\Documents and Settings\user\Dokumenty\НОСКИ.odt
2013-11-21 12:00 - 2011-02-03 08:56 - 00000498 _____ C:\WINDOWS\Tasks\One-Click Tweak.job
2013-11-21 11:22 - 2010-08-18 09:56 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-11-20 11:32 - 2010-02-01 13:19 - 00010896 _____ C:\Documents and Settings\user\Data aplikací\SmarThruOptions.xml
2013-11-18 10:25 - 2013-11-18 10:25 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\SightSpeed Recordings
2013-11-17 06:39 - 2012-04-27 15:05 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-16 21:37 - 2013-11-16 08:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 10:35 - 2013-11-14 10:35 - 00008892 _____ C:\WINDOWS\KB2900986.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00004392 _____ C:\WINDOWS\updspapi.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-14 10:35 - 2013-11-14 08:37 - 00014535 _____ C:\WINDOWS\KB2868626.log
2013-11-14 10:35 - 2013-11-14 08:37 - 00013508 _____ C:\WINDOWS\KB2862152.log
2013-11-14 10:35 - 2013-11-14 08:37 - 00013037 _____ C:\WINDOWS\KB2876331.log
2013-11-14 10:35 - 2013-07-15 22:12 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 10:35 - 2009-09-22 04:33 - 00000000 ____D C:\WINDOWS\ie8updates
2013-11-14 10:32 - 2008-11-19 18:48 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-13 17:42 - 2013-01-31 23:26 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\Dotazníky TEFL
2013-11-12 07:42 - 2013-11-02 20:55 - 00000000 ___RD C:\Documents and Settings\user\Plocha\Phone
2013-11-11 22:18 - 2013-06-03 14:58 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\PHOTOS
2013-11-11 22:04 - 2013-01-16 18:09 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Fighters
2013-11-11 22:02 - 2008-11-18 17:38 - 00000000 ___RD C:\Documents and Settings\user\Plocha\Nepoužívané odkazy plochy
2013-11-10 09:20 - 2013-11-02 09:33 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\clp
2013-11-06 06:36 - 2008-12-02 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2013-11-03 16:40 - 2013-11-03 16:40 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\Fighters
2013-11-03 14:25 - 2013-11-03 13:01 - 00000000 ____D C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP
2013-11-03 14:25 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Nabídka Start\Programy
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setupact.log
2013-11-03 13:06 - 2010-11-24 08:23 - 00069896 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-03 13:01 - 2011-04-23 21:49 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-11-03 12:37 - 2008-11-13 13:08 - 00000000 ____D C:\WINDOWS\Help
2013-11-03 10:17 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Nabídka Start\Programy\Příslušenství
2013-11-03 10:16 - 2010-05-04 11:32 - 00000000 ____D C:\Program Files\Windows Media Connect 2
2013-11-03 09:42 - 2008-11-13 13:13 - 00282128 _____ C:\WINDOWS\system32\FNTCACHE.DAT

Some content of TEMP:
====================
C:\Documents and Settings\user\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\user\Local Settings\Temp\ODFsetup.exe
C:\Documents and Settings\user\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\user\Local Settings\Temp\setup.exe
C:\Documents and Settings\user\Local Settings\Temp\SHSetup.exe
C:\Documents and Settings\user\Local Settings\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2004-08-18 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2004-08-18 13:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 12:32
od vyosek
:arrow: Addition muzete dat jako text do prispevku a nemusite do priloy

:arrow: Ale nectete navody, FRST i FRSTLauncher maji byt na Plose, FRSTLauncher tam mate, FRST.exe uz nikoliv
Running from C:\Documents and Settings\user\Dokumenty\Stažené soubory
:arrow: Takze dejte FRST.exe na plochu a znovu spustte FRSTLauncher, logy pak opet sem

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 12:35
od tamuri
Ále, já to čtu, ale když mi při stahování se nenabízí možnost "uložit" ale jenom "spustit", pak mi nic jiného nezbývá!

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 12:47
od tamuri
Takže znovu oba logy?
Tady:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-12-2013
Ran by user (administrator) on USER-9E9A9A8968 on 03-12-2013 12:41:41
Running from C:\Documents and Settings\user\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Software602 a.s.) C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Software602) C:\Program Files\Software602\Print2PDF\Print2PDF.exe
(Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Rynga) C:\Program Files\Rynga.com\Rynga\rynga.exe
(Skype Technologies S.A.) C:\Documents and Settings\user\Plocha\Phone\Skype.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.bin
() C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Documents and Settings\user\Plocha\FRSTLauncher.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
(Microsoft Corporation) C:\WINDOWS\system32\ping.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [AGRSMMSG] - C:\WINDOWS\AGRSMMSG.exe [87751 2002-09-25] (Agere Systems)
HKLM\...\Run: [Print2PDF Print Monitor] - C:\Program Files\Software602\Print2PDF\Print2PDF.exe [220992 2011-10-04] (Software602)
HKLM\...\Run: [LWS] - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM\...\Run: [Samsung PanelMgr] - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [614400 2009-10-16] ()
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [RegHunter Registry Cleaner] - "C:\Program Files\Enigma Software Group\RegHunter\RegHunter.exe" -silent
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-12-01] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [Rynga] - C:\Program Files\Rynga.com\Rynga\rynga.exe [19554608 2013-07-22] (Rynga)
HKCU\...\Run: [HideOE] - "C:\Program Files\Outlook Express\HideOE\HideOE.exe"
HKCU\...\Run: [Skype] - C:\Documents and Settings\user\Plocha\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
MountPoints2: {28fc6282-d98d-11e2-a28b-001fc6caf3ac} - E:\iLinker.exe
MountPoints2: {b3bd9da9-b17b-11dd-89d5-806d6172696f} - D:\autorun.exe
Startup: C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění\OpenOffice 4.0.1.lnk
ShortcutTarget: OpenOffice 4.0.1.lnk -> C:\Program Files\OpenOffice 4\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Documents and Settings\user\Plocha\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8466944 2012-06-08] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-08-24] (SuperAdBlocker.com)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @SafePCRepair_89.com/Plugin - C:\Program Files\SafePCRepair_89\bar\1.bin\NP89Stub.dll No File
FF Plugin: @software602.cz/602XML Filler - C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\searchplugins\amazonde-german.xml
FF SearchPlugin: C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\searchplugins\youtube-ssl.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: gmailwatcher - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\gmailwatcher@sonthakit.xpi
FF Extension: IrregularVerbs - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\IrregularVerbs@canevas.xul.xpi
FF Extension: ImTranslator - C:\Documents and Settings\user\Data aplikací\Mozilla\Firefox\Profiles\t2d8p9cr.default-1360859005218\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll No File
CHR Extension: (Avira Toolbar) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.8.0_0
CHR Extension: (Skype Click to Call) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR Extension: (Chrome In-App Payments service) - C:\DOCUME~1\user\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Documents and Settings\user\Local Settings\Data aplikací\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

========================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2012-09-08] (SUPERAntiSpyware.com)
R2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
S2 gupdate1ca7803e9217740; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-12-08] (Google Inc.)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
S3 ioloService; C:\Program Files\SafePCRepair\ioloToolService.exe [x]
S2 SafePCRepair_89Service; C:\PROGRA~1\SAFEPC~2\bar\1.bin\89barsvc.exe [x]
S2 SkypeUpdate; "C:\Documents and Settings\user\Plocha\Updater\Updater.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-12-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-01] (Avira Operations GmbH & Co. KG)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 FilterService; C:\Windows\System32\DRIVERS\lvuvcflt.sys [23832 2009-10-07] (Logitech Inc.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51056 2004-02-26] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-02-26] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2005-10-21] (HP)
R3 monfilt; C:\Windows\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-08-24] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-08-24] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-01] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [222976 2008-02-14] (VIA Technologies, Inc.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
S3 RkHit; \??\C:\WINDOWS\system32\drivers\RKHit.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 12:41 - 2013-12-03 12:41 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
2013-12-03 12:33 - 2013-12-03 12:33 - 00036942 _____ C:\Documents and Settings\user\Plocha\FRST2.txt
2013-12-03 12:21 - 2013-12-03 12:41 - 00014646 _____ C:\Documents and Settings\user\Plocha\FRST.txt
2013-12-03 12:15 - 2013-12-03 12:15 - 00021775 _____ C:\Documents and Settings\user\Plocha\Addition.odt
2013-12-03 12:05 - 2013-12-03 12:41 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-03 12:03 - 2013-12-03 12:03 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\user\Plocha\FRSTLauncher.exe
2013-12-03 11:58 - 2013-12-03 11:58 - 00000000 ____D C:\FRST
2013-12-03 11:57 - 2013-12-03 11:57 - 01092389 _____ (Farbar) C:\Documents and Settings\user\Plocha\FRST.exe
2013-12-03 10:52 - 2013-12-03 10:52 - 00019801 _____ C:\Documents and Settings\user\Plocha\Odpověď_VIRY.odt
2013-12-03 10:32 - 2013-12-03 10:38 - 00000000 ____D C:\AdwCleaner
2013-12-03 10:19 - 2013-12-03 10:19 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-03 10:11 - 2013-12-03 10:54 - 00001870 _____ C:\sc-cleaner.txt
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
2013-12-03 09:23 - 2013-12-03 09:23 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-02 22:10 - 2013-12-02 22:10 - 00018617 _____ C:\Documents and Settings\user\Dokumenty\log.odt
2013-12-02 22:08 - 2013-12-02 22:08 - 00015754 _____ C:\Documents and Settings\user\Dokumenty\HijackThis.odt
2013-12-02 08:47 - 2013-12-02 08:50 - 00012480 _____ C:\Documents and Settings\user\Plocha\КОМБИНАЦИИ НА КЛАВИАТУРЕ.odt
2013-12-01 23:28 - 2013-12-03 12:29 - 00000464 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job
2013-12-01 20:14 - 2013-12-01 20:15 - 00003525 _____ C:\WINDOWS\ie8Uninst.log
2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Avira
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
2013-12-01 08:13 - 2013-12-01 08:13 - 00001707 _____ C:\Documents and Settings\All Users\Plocha\Avira Control Center.lnk
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Program Files\Avira
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
2013-12-01 08:13 - 2013-12-01 08:12 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2013-12-01 08:13 - 2013-12-01 08:12 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Mozilla
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací\Mozilla
2013-11-30 10:51 - 2013-11-30 10:51 - 00016486 _____ C:\Documents and Settings\user\Dokumenty\Шишки на ногах (hallux).odt
2013-11-30 10:20 - 2013-11-30 10:20 - 00018442 _____ C:\Documents and Settings\user\Dokumenty\Продукты, которые нельзя есть натощак.odt
2013-11-30 10:15 - 2013-11-30 10:15 - 00034660 _____ C:\Documents and Settings\user\Dokumenty\Торт Наполеон (слоёный, быстрый).odt
2013-11-30 09:48 - 2013-11-30 09:48 - 00034137 _____ C:\Documents and Settings\user\Dokumenty\Как избавиться от холки на шее.odt
2013-11-27 11:30 - 2013-11-27 11:31 - 00054074 _____ C:\Documents and Settings\user\Dokumenty\Good News_Happiness Doesn’t Exist.odt
2013-11-23 22:08 - 2013-11-23 22:08 - 00033721 _____ C:\Documents and Settings\user\Dokumenty\НОСКИ.odt
2013-11-18 10:25 - 2013-11-18 10:25 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\SightSpeed Recordings
2013-11-16 08:08 - 2013-11-16 21:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 10:35 - 2013-12-01 23:29 - 00172959 _____ C:\WINDOWS\KB2888505-IE8.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00008892 _____ C:\WINDOWS\KB2900986.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00004392 _____ C:\WINDOWS\updspapi.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-14 08:37 - 2013-11-14 10:35 - 00014535 _____ C:\WINDOWS\KB2868626.log
2013-11-14 08:37 - 2013-11-14 10:35 - 00013508 _____ C:\WINDOWS\KB2862152.log
2013-11-14 08:37 - 2013-11-14 10:35 - 00013037 _____ C:\WINDOWS\KB2876331.log
2013-11-03 16:40 - 2013-11-03 16:40 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\Fighters
2013-11-03 14:24 - 2013-12-01 20:50 - 00050678 _____ C:\WINDOWS\FaxSetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00029274 _____ C:\WINDOWS\ocgen.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00022002 _____ C:\WINDOWS\tsoc.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00017120 _____ C:\WINDOWS\comsetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00010767 _____ C:\WINDOWS\ntdtcsetup.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00007934 _____ C:\WINDOWS\iis6.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00003254 _____ C:\WINDOWS\ocmsn.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00002812 _____ C:\WINDOWS\msgsocm.log
2013-11-03 14:24 - 2013-12-01 20:50 - 00001917 _____ C:\WINDOWS\imsins.log
2013-11-03 14:24 - 2013-12-01 20:15 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setupact.log
2013-11-03 13:06 - 2013-12-01 20:50 - 00013826 _____ C:\WINDOWS\setupapi.log
2013-11-03 13:01 - 2013-11-03 14:25 - 00000000 ____D C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP

==================== One Month Modified Files and Folders =======

2013-12-03 12:41 - 2013-12-03 12:41 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
2013-12-03 12:41 - 2013-12-03 12:21 - 00014646 _____ C:\Documents and Settings\user\Plocha\FRST.txt
2013-12-03 12:41 - 2013-12-03 12:05 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-03 12:41 - 2010-02-05 19:02 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\Stažené soubory
2013-12-03 12:41 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Plocha
2013-12-03 12:41 - 2008-11-13 15:38 - 00000000 ___HD C:\Documents and Settings\user\Local Settings\Data aplikací
2013-12-03 12:40 - 2008-12-02 19:19 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Skype
2013-12-03 12:33 - 2013-12-03 12:33 - 00036942 _____ C:\Documents and Settings\user\Plocha\FRST2.txt
2013-12-03 12:29 - 2013-12-01 23:28 - 00000464 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job
2013-12-03 12:29 - 2009-12-08 13:54 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-03 12:15 - 2013-12-03 12:15 - 00021775 _____ C:\Documents and Settings\user\Plocha\Addition.odt
2013-12-03 12:15 - 2012-07-15 21:09 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-03 12:03 - 2013-12-03 12:03 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\user\Plocha\FRSTLauncher.exe
2013-12-03 11:58 - 2013-12-03 11:58 - 00000000 ____D C:\FRST
2013-12-03 11:57 - 2013-12-03 11:57 - 01092389 _____ (Farbar) C:\Documents and Settings\user\Plocha\FRST.exe
2013-12-03 11:06 - 2009-07-02 07:35 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-03 10:54 - 2013-12-03 10:11 - 00001870 _____ C:\sc-cleaner.txt
2013-12-03 10:52 - 2013-12-03 10:52 - 00019801 _____ C:\Documents and Settings\user\Plocha\Odpověď_VIRY.odt
2013-12-03 10:41 - 2008-11-13 15:32 - 01999577 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-03 10:40 - 2012-11-20 10:05 - 00000270 _____ C:\WINDOWS\Tasks\RMAutoUpdate.job
2013-12-03 10:40 - 2010-08-21 11:09 - 00000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2013-12-03 10:40 - 2009-12-08 13:54 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-03 10:40 - 2008-11-13 15:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-03 10:40 - 2008-11-13 13:16 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-03 10:40 - 2008-11-13 13:16 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-12-03 10:39 - 2008-11-13 15:38 - 00000272 ___SH C:\Documents and Settings\user\ntuser.ini
2013-12-03 10:39 - 2008-11-13 15:36 - 00032562 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-03 10:38 - 2013-12-03 10:32 - 00000000 ____D C:\AdwCleaner
2013-12-03 10:38 - 2008-11-13 15:38 - 00000000 __RHD C:\Documents and Settings\user\Data aplikací
2013-12-03 10:36 - 2010-02-10 22:21 - 03603896 ___SH C:\Documents and Settings\user\Plocha\Thumbs.db
2013-12-03 10:36 - 2010-02-10 22:21 - 00005632 ___SH C:\Documents and Settings\user\Thumbs.db
2013-12-03 10:19 - 2013-12-03 10:19 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
2013-12-03 09:27 - 2008-11-13 13:13 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-12-03 09:26 - 2008-11-13 13:14 - 01137738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-03 09:23 - 2013-12-03 09:23 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-03 09:06 - 2009-12-28 21:50 - 00003411 _____ C:\WINDOWS\wg2000.ini
2013-12-03 09:06 - 2009-09-18 15:47 - 00000021 _____ C:\WINDOWS\wk2000.ini
2013-12-03 09:06 - 2009-09-18 15:47 - 00000018 _____ C:\WINDOWS\winklav.ini
2013-12-03 09:00 - 2009-09-19 07:35 - 00000304 _____ C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
2013-12-03 08:59 - 2009-11-26 13:48 - 00000000 ____D C:\Program Files\BigPatience
2013-12-02 22:49 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty
2013-12-02 22:10 - 2013-12-02 22:10 - 00018617 _____ C:\Documents and Settings\user\Dokumenty\log.odt
2013-12-02 22:08 - 2013-12-02 22:08 - 00015754 _____ C:\Documents and Settings\user\Dokumenty\HijackThis.odt
2013-12-02 19:11 - 2010-04-16 10:44 - 00000000 ____D C:\Program Files\trend micro
2013-12-02 08:50 - 2013-12-02 08:47 - 00012480 _____ C:\Documents and Settings\user\Plocha\КОМБИНАЦИИ НА КЛАВИАТУРЕ.odt
2013-12-02 08:13 - 2004-08-18 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-01 23:29 - 2013-11-14 10:35 - 00172959 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00050678 _____ C:\WINDOWS\FaxSetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00029274 _____ C:\WINDOWS\ocgen.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00022002 _____ C:\WINDOWS\tsoc.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00017120 _____ C:\WINDOWS\comsetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00010767 _____ C:\WINDOWS\ntdtcsetup.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00007934 _____ C:\WINDOWS\iis6.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00003254 _____ C:\WINDOWS\ocmsn.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00002812 _____ C:\WINDOWS\msgsocm.log
2013-12-01 20:50 - 2013-11-03 14:24 - 00001917 _____ C:\WINDOWS\imsins.log
2013-12-01 20:50 - 2013-11-03 13:06 - 00013826 _____ C:\WINDOWS\setupapi.log
2013-12-01 20:15 - 2013-12-01 20:14 - 00003525 _____ C:\WINDOWS\ie8Uninst.log
2013-12-01 20:15 - 2013-11-03 14:24 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-12-01 19:51 - 2009-09-22 17:52 - 00000000 ____D C:\Program Files\Google
2013-12-01 19:51 - 2008-11-13 13:14 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\Avira
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
2013-12-01 08:13 - 2013-12-01 08:13 - 00001707 _____ C:\Documents and Settings\All Users\Plocha\Avira Control Center.lnk
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Program Files\Avira
2013-12-01 08:13 - 2013-12-01 08:13 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
2013-12-01 08:13 - 2011-10-19 17:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avira
2013-12-01 08:13 - 2008-11-13 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-01 08:12 - 2013-12-01 08:13 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2013-12-01 08:12 - 2013-12-01 08:13 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Mozilla
2013-11-30 20:32 - 2013-11-30 20:32 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací\Mozilla
2013-11-30 20:32 - 2008-11-13 15:36 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2013-11-30 20:32 - 2008-11-13 15:36 - 00000000 ____D C:\Documents and Settings\LocalService\Data aplikací
2013-11-30 20:05 - 2010-02-02 13:52 - 00000000 ____D C:\WINDOWS\system32\NtmsData
2013-11-30 20:02 - 2012-10-30 09:18 - 00000000 ____D C:\Documents and Settings\user\Data aplikací\CallingID
2013-11-30 18:30 - 2012-10-30 09:18 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\DoNotTrackPlus
2013-11-30 10:51 - 2013-11-30 10:51 - 00016486 _____ C:\Documents and Settings\user\Dokumenty\Шишки на ногах (hallux).odt
2013-11-30 10:20 - 2013-11-30 10:20 - 00018442 _____ C:\Documents and Settings\user\Dokumenty\Продукты, которые нельзя есть натощак.odt
2013-11-30 10:15 - 2013-11-30 10:15 - 00034660 _____ C:\Documents and Settings\user\Dokumenty\Торт Наполеон (слоёный, быстрый).odt
2013-11-30 09:48 - 2013-11-30 09:48 - 00034137 _____ C:\Documents and Settings\user\Dokumenty\Как избавиться от холки на шее.odt
2013-11-30 09:30 - 2008-11-13 15:31 - 00000000 ____D C:\WINDOWS\Registration
2013-11-29 20:47 - 2008-11-18 17:46 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\Разное
2013-11-28 06:41 - 2008-11-18 17:46 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\Рецепты
2013-11-27 11:31 - 2013-11-27 11:30 - 00054074 _____ C:\Documents and Settings\user\Dokumenty\Good News_Happiness Doesn’t Exist.odt
2013-11-23 22:08 - 2013-11-23 22:08 - 00033721 _____ C:\Documents and Settings\user\Dokumenty\НОСКИ.odt
2013-11-21 12:00 - 2011-02-03 08:56 - 00000498 _____ C:\WINDOWS\Tasks\One-Click Tweak.job
2013-11-21 11:22 - 2010-08-18 09:56 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-11-20 11:32 - 2010-02-01 13:19 - 00010896 _____ C:\Documents and Settings\user\Data aplikací\SmarThruOptions.xml
2013-11-18 10:25 - 2013-11-18 10:25 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\SightSpeed Recordings
2013-11-17 06:39 - 2012-04-27 15:05 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-16 21:37 - 2013-11-16 08:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 10:35 - 2013-11-14 10:35 - 00008892 _____ C:\WINDOWS\KB2900986.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00004392 _____ C:\WINDOWS\updspapi.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-14 10:35 - 2013-11-14 10:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-14 10:35 - 2013-11-14 08:37 - 00014535 _____ C:\WINDOWS\KB2868626.log
2013-11-14 10:35 - 2013-11-14 08:37 - 00013508 _____ C:\WINDOWS\KB2862152.log
2013-11-14 10:35 - 2013-11-14 08:37 - 00013037 _____ C:\WINDOWS\KB2876331.log
2013-11-14 10:35 - 2013-07-15 22:12 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 10:35 - 2009-09-22 04:33 - 00000000 ____D C:\WINDOWS\ie8updates
2013-11-14 10:32 - 2008-11-19 18:48 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-13 17:42 - 2013-01-31 23:26 - 00000000 ____D C:\Documents and Settings\user\Dokumenty\Dotazníky TEFL
2013-11-12 07:42 - 2013-11-02 20:55 - 00000000 ___RD C:\Documents and Settings\user\Plocha\Phone
2013-11-11 22:18 - 2013-06-03 14:58 - 00000000 ___RD C:\Documents and Settings\user\Dokumenty\PHOTOS
2013-11-11 22:04 - 2013-01-16 18:09 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Fighters
2013-11-11 22:02 - 2008-11-18 17:38 - 00000000 ___RD C:\Documents and Settings\user\Plocha\Nepoužívané odkazy plochy
2013-11-10 09:20 - 2013-11-02 09:33 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\clp
2013-11-06 06:36 - 2008-12-02 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2013-11-03 16:40 - 2013-11-03 16:40 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\Fighters
2013-11-03 14:25 - 2013-11-03 13:01 - 00000000 ____D C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP
2013-11-03 14:25 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Nabídka Start\Programy
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-03 14:24 - 2013-11-03 14:24 - 00000000 _____ C:\WINDOWS\setupact.log
2013-11-03 13:06 - 2010-11-24 08:23 - 00069896 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-03 13:01 - 2011-04-23 21:49 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-11-03 12:37 - 2008-11-13 13:08 - 00000000 ____D C:\WINDOWS\Help
2013-11-03 10:17 - 2008-11-13 15:38 - 00000000 ___RD C:\Documents and Settings\user\Nabídka Start\Programy\Příslušenství
2013-11-03 10:16 - 2010-05-04 11:32 - 00000000 ____D C:\Program Files\Windows Media Connect 2
2013-11-03 09:42 - 2008-11-13 13:13 - 00282128 _____ C:\WINDOWS\system32\FNTCACHE.DAT

Some content of TEMP:
====================
C:\Documents and Settings\user\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\user\Local Settings\Temp\ODFsetup.exe
C:\Documents and Settings\user\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\user\Local Settings\Temp\setup.exe
C:\Documents and Settings\user\Local Settings\Temp\SHSetup.exe
C:\Documents and Settings\user\Local Settings\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2004-08-18 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2004-08-18 13:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2004-08-18 13:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================


A druhý:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-12-2013
Ran by user at 2013-12-03 12:42:03
Running from C:\Documents and Settings\user\Plocha
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Avira FireWall (Disabled) {11638345-E4FC-4BEE-BB73-EC754659C5F6}

==================== Installed Programs ======================

7-Zip 9.22beta
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Czech (Version: 11.0.05)
Adobe Shockwave Player 11.6 (Version: 11.6.8.638)
Aktualizace systému Windows Internet Explorer 8 (KB973874) (Version: 1)
Aktualizace systému Windows Internet Explorer 8 (KB976662) (Version: 1)
Aktualizace systému Windows Internet Explorer 8 (KB976749) (Version: 1)
Aktualizace systému Windows Internet Explorer 8 (KB980182) (Version: 1)
Aktualizace systému Windows XP (KB2141007) (Version: 1)
Aktualizace systému Windows XP (KB2345886) (Version: 1)
Aktualizace systému Windows XP (KB2467659) (Version: 1)
Aktualizace systému Windows XP (KB2541763) (Version: 1)
Aktualizace systému Windows XP (KB2607712) (Version: 1)
Aktualizace systému Windows XP (KB2616676) (Version: 1)
Aktualizace systému Windows XP (KB2641690) (Version: 1)
Aktualizace systému Windows XP (KB2661254-v2) (Version: 2)
Aktualizace systému Windows XP (KB2718704) (Version: 1)
Aktualizace systému Windows XP (KB2736233) (Version: 1)
Aktualizace systému Windows XP (KB2749655) (Version: 1)
Aktualizace systému Windows XP (KB2863058) (Version: 1)
Aktualizace systému Windows XP (KB951072-v2) (Version: 2)
Aktualizace systému Windows XP (KB951978) (Version: 1)
Aktualizace systému Windows XP (KB955759) (Version: 1)
Aktualizace systému Windows XP (KB955839) (Version: 1)
Aktualizace systému Windows XP (KB967715) (Version: 1)
Aktualizace systému Windows XP (KB968389) (Version: 1)
Aktualizace systému Windows XP (KB971029) (Version: 1)
Aktualizace systému Windows XP (KB971737) (Version: 1)
Aktualizace systému Windows XP (KB973687) (Version: 1)
Aktualizace systému Windows XP (KB973815) (Version: 1)
Aktualizace zabezpečení aplikace Windows Media Player (KB2378111)
Aktualizace zabezpečení aplikace Windows Media Player (KB2834904)
Aktualizace zabezpečení aplikace Windows Media Player (KB2834904-v2)
Aktualizace zabezpečení aplikace Windows Media Player (KB952069)
Aktualizace zabezpečení aplikace Windows Media Player (KB954155)
Aktualizace zabezpečení aplikace Windows Media Player (KB968816)
Aktualizace zabezpečení aplikace Windows Media Player (KB973540)
Aktualizace zabezpečení aplikace Windows Media Player (KB975558)
Aktualizace zabezpečení aplikace Windows Media Player (KB978695)
Aktualizace zabezpečení aplikace Windows Media Player (KB979402)
Aktualizace zabezpečení aplikace Windows Media Player 11 (KB954154)
Aktualizace zabezpečení pro Microsoft Windows (KB2564958)
Aktualizace zabezpečení produktu Windows XP (KB941569)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127-v2) (Version: 2)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB953838) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB956390) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB963027) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB969897) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB972260) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2183461) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2360131) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2416400) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2482017) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2497640) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2510531) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2530548) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2544521) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2559049) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2586448) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2618444) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2647516) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2675157) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2699988) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2722913) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2744842) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2761465) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2792100) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2797052) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2799329) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2809289) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2817183) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2829530) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2838727) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2846071) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2847204) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2862772) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2870699) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2879017) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2888505) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB971961) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB972260) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB974455) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB976325) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB978207) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB981332) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB982381) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2079403) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2115168) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2121546) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2160329) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2229593) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2259922) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2279986) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2286198) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2296011) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2296199) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2347290) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2360937) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2387149) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2393802) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2412687) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2419632) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2423089) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2436673) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2440591) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2443105) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2476490) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2476687) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2478960) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2478971) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2479628) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2479943) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2481109) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2483185) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2485376) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2485663) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2503658) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2503665) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2506212) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2506223) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2507618) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2507938) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2508272) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2508429) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2509553) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2511455) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2524375) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2535512) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2536276) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2536276-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB2544893) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2544893-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB2555917) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2562937) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2566454) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2567053) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2567680) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2570222) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2570947) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2584146) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2585542) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2592799) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2598479) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2603381) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2618451) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2619339) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2620712) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2621440) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2624667) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2631813) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2633171) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2639417) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2641653) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2646524) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2647518) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2653956) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2655992) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2659262) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2660465) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2661637) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2676562) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2685939) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2686509) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2691442) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2695962) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2698365) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2705219) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2707511) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2709162) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2712808) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2718523) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2719985) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2723135) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2724197) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2727528) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2731847) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2753842) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2753842-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB2757638) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2758857) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2761226) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2770660) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2778344) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2779030) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2780091) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2799494) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2802968) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2807986) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2808735) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2813170) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2813345) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2820197) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2820917) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2829361) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2834886) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2839229) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2845187) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2847311) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2849470) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2850851) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2850869) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2859537) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2862152) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2862330) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2862335) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2864063) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2868038) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2868626) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2876217) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2876315) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2876331) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2883150) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2900986) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB923561) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB938464) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB938464-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB946648) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB950762) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB950974) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB951066) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB951376-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB951698) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB951748) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB952004) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB952954) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB954211) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB954459) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB954600) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB955069) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956390) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956391) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956572) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956744) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956802) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956803) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956841) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB956844) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB957095) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB957097) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB958644) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB958687) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB958690) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB958869) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB959426) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB960225) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB960715) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB960803) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB960859) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB961371-v2) (Version: 2)
Aktualizace zabezpečení systému Windows XP (KB961373) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB961501) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB968537) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB969059) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB969898) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB969947) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB970238) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB970430) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971468) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971486) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971557) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971633) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971657) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB971961) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB972270) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973346) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973354) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973507) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973525) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973869) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB973904) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB974112) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB974318) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB974392) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB974571) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975025) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975467) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975560) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975561) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975562) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB975713) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB977165) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB977816) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB977914) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978037) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978251) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978262) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978338) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978542) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978601) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB978706) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB979309) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB979482) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB979559) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB979683) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB979687) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB980195) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB980218) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB980232) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB980436) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB981322) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB981852) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB981957) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB981997) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB982132) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB982214) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB982665) (Version: 1)
Avira Free Antivirus (Version: 14.0.1.749)
Avira SearchFree Toolbar (Version: 12.6.0.1898)
BigPatience
CameraHelperMsi (Version: 13.31.1038.0)
CCleaner (Version: 4.06)
Codec Pack - All In 1 6.0.3.0
DivX Converter (Version: 7.1.0)
DivX Plus DirectShow Filters
DivX Setup (Version: 2.6.1.84)
DivX Version Checker (Version: 7.1.0.9)
erLT (Version: 1.20.138.34)
Google Drive (Version: 1.12.5329.1887)
Google Earth (Version: 7.1.2.2019)
Google Update Helper (Version: 1.3.21.165)
High Definition Audio Driver Package - KB888111 (Version: 20040219.000000)
HijackThis 2.0.2 (Version: 2.0.2)
ICQ 7.2 Build #3525 Banner Remover 1.0
ICQ7 (Version: 7.0)
Intel(R) Graphics Media Accelerator Driver
IrfanView (remove only) (Version: 4.35)
Jpeg Resampler Vs 6+
Logitech Vid HD (Version: 7.2 (7240))
Logitech Webcam Software (Version: 2.30)
Logitech Webcam Software Driver Package (Version: 12.10.1110)
LWS Facebook (Version: 13.31.1038.0)
LWS Gallery (Version: 13.31.1038.0)
LWS Help_main (Version: 13.31.1044.0)
LWS Launcher (Version: 13.31.1038.0)
LWS Motion Detection (Version: 13.30.1395.0)
LWS Pictures And Video (Version: 13.31.1038.0)
LWS Twitter (Version: 13.30.1346.0)
LWS Video Mask Maker (Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (Version: 13.31.1038.0)
LWS WLM Plugin (Version: 1.30.1201.0)
LWS YouTube Plugin (Version: 13.31.1038.0)
Microcom InPorte Home
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Czech Language Pack (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2833941)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (Version: 4.0.30319)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Millennium6 (Version: 6.0)
Mozilla Firefox 25.0.1 (x86 cs) (Version: 25.0.1)
Mozilla Maintenance Service (Version: 25.0.1)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
Nonoh (Version: 4.08 build 645)
O2 Internet Konfigurator
OpenOffice 4.0.1 (Version: 4.01.9714)
Oprava hotfix aplikace Windows Media Player 11 (KB939683)
Oprava Hotfix systému Windows XP (KB2158563) (Version: 1)
Oprava Hotfix systému Windows XP (KB2443685) (Version: 1)
Oprava Hotfix systému Windows XP (KB2570791) (Version: 1)
Oprava Hotfix systému Windows XP (KB2633952) (Version: 1)
Oprava Hotfix systému Windows XP (KB2756822) (Version: 1)
Oprava Hotfix systému Windows XP (KB2779562) (Version: 1)
Oprava Hotfix systému Windows XP (KB952287) (Version: 1)
Oprava Hotfix systému Windows XP (KB961118) (Version: 1)
Oprava Hotfix systému Windows XP (KB970653-v3) (Version: 3)
Oprava Hotfix systému Windows XP (KB976098-v2) (Version: 2)
Oprava Hotfix systému Windows XP (KB979306) (Version: 1)
Oprava Hotfix systému Windows XP (KB981793) (Version: 1)
OUTDATEfighter (Version: 1.1.81)
overland (Version: 2.1.5)
Platform (Version: 1.26)
rajče verze 58 sestavení 212
Readiris Pro 10
REALTEK GbE & FE Ethernet PCI-E NIC Driver (Version: 1.16.0000)
Russian Phonetic YaZHert - WinRus.com (Version: 1.0.3.40)
Rynga (Version: 4.09 build 660)
Samsung SCX-4500 Series
Skype Click to Call (Version: 6.9.12585)
Skype™ 6.10 (Version: 6.10.104)
SmarThru 4
Software602 Form Filler (Version: 4.12)
Software602 Print2PDF (Version: 9.1.11.0421)
SPAMfighter (Version: 7.6.14)
SUPERAntiSpyware (Version: 4.41.1000)
swMSM (Version: 12.0.0.1)
Total Commander (Remove or Repair)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
VIA Platforma Ovladače zařízení (Version: 1.26)
VoipBuster (Version: 4.03 build 546)
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
Windows XP Service Pack 3 (Version: 20080414.031517)

==================== Restore Points =========================


==================== Hosts content: ==========================

2004-08-18 13:00 - 2011-09-05 14:09 - 00000934 ____N C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 ar.atwola.com
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de


==================== Scheduled Tasks (whitelisted) =============

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\One-Click Tweak.job => C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe
Task: C:\WINDOWS\Tasks\RMAutoUpdate.job => C:\Program Files\PC Tools Registry Mechanic\SULauncher.exe
Task: C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job => C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job => C:\WINDOWS\system32\msfeedssync.exe

==================== Loaded Modules (whitelisted) =============

2010-02-01 13:13 - 2007-01-11 04:28 - 00022723 _____ () C:\WINDOWS\system32\sx450sl3.dll
2011-03-16 12:49 - 2010-12-02 01:13 - 00214528 _____ () C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Software602.dll
2013-12-01 08:13 - 2013-12-01 08:12 - 00394808 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
2011-08-12 11:18 - 2011-08-12 11:18 - 02145304 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtCore4.dll
2011-08-12 11:18 - 2011-08-12 11:18 - 07956504 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtGui4.dll
2011-08-12 11:18 - 2011-08-12 11:18 - 00342552 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtXml4.dll
2011-08-12 11:18 - 2011-08-12 11:18 - 00029208 _____ () C:\Program Files\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2011-08-12 11:18 - 2011-08-12 11:18 - 00128536 _____ () C:\Program Files\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2011-11-11 14:09 - 2011-11-11 14:09 - 00336408 _____ () C:\Program Files\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
2004-08-18 13:00 - 2008-04-14 04:21 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2013-09-20 13:50 - 2013-11-02 14:42 - 00988160 _____ () C:\Program Files\OpenOffice 4\program\libxml2.dll
2013-09-17 04:54 - 2013-11-02 14:42 - 00170496 _____ () C:\Program Files\OpenOffice 4\program\libxslt.dll
2013-11-16 08:08 - 2013-11-16 08:08 - 03363952 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:31E74682
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Class Guid: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Manufacturer: (Standardní klávesnice)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Myš Microsoft pro port PS/2
Description: Myš Microsoft pro port PS/2
Class Guid: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/03/2013 09:47:56 AM) (Source: Application Hang) (User: )
Description: Zablokovaná aplikace msimn.exe, verze 6.0.2900.5512, zablokovaný modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error: (12/01/2013 07:54:26 PM) (Source: Application Hang) (User: )
Description: Chybný blok 1180947459

Error: (12/01/2013 07:54:15 PM) (Source: Application Hang) (User: )
Description: Chybný blok 1180947459

Error: (12/01/2013 07:54:14 PM) (Source: Application Hang) (User: )
Description: Zablokovaná aplikace iexplore.exe, verze 8.0.6001.18702, zablokovaný modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error: (12/01/2013 07:54:09 PM) (Source: Application Hang) (User: )
Description: Zablokovaná aplikace iexplore.exe, verze 8.0.6001.18702, zablokovaný modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error: (12/01/2013 10:48:21 AM) (Source: Application Error) (User: )
Description: Chybný blok -402916403
Výměna klíčů nezajistila nastavení zabezpečeného připojení po ověření 802.1x. Aktuální nastavení bylo označeno za neplatné a bezdrátové připojení bude odpojeno.

Error: (12/01/2013 10:48:09 AM) (Source: Application Error) (User: )
Description: Chybující aplikace toolbar.exe, verze 21.4.0.1982, chybující modul unknown, verze 0.0.0.0, adresa chyby 0x10008870.
Zpracování události, specifické pro médium ([toolbar.exe!ws!])

Error: (12/01/2013 10:19:43 AM) (Source: Application Hang) (User: )
Description: Chybný blok 1180947459

Error: (12/01/2013 10:19:35 AM) (Source: Application Hang) (User: )
Description: Zablokovaná aplikace iexplore.exe, verze 8.0.6001.18702, zablokovaný modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error: (11/26/2013 00:57:40 PM) (Source: Avira Antivirus) (User: NT AUTHORITY)
Description: Не удалось загрузить файл AvShadow.
Код ошибки: 0x3e5


System errors:
=============
Error: (12/03/2013 10:42:19 AM) (Source: DCOM) (User: USER-9E9A9A8968)
Description: Služba DCOM zjistila chybu %/ComService při pokusu o spuštění služby SkypeUpdate s argumenty /ComService
za účelem spuštění serveru:
{CC957078-B838-47C4-A7CF-626E7A82FC58}

Error: (12/03/2013 10:42:16 AM) (Source: Service Control Manager) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
i8042prt

Error: (12/03/2013 10:40:18 AM) (Source: Service Control Manager) (User: )
Description: Služba SSPORT neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (12/03/2013 10:40:18 AM) (Source: Service Control Manager) (User: )
Description: Služba SafePCRepairService neuspěla při spuštění v důsledku následující chyby:
%%3

Error: (12/03/2013 09:53:37 AM) (Source: DCOM) (User: USER-9E9A9A8968)
Description: Služba DCOM zjistila chybu %/ComService při pokusu o spuštění služby SkypeUpdate s argumenty /ComService
za účelem spuštění serveru:
{CC957078-B838-47C4-A7CF-626E7A82FC58}

Error: (12/03/2013 09:53:33 AM) (Source: Service Control Manager) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
i8042prt

Error: (12/03/2013 09:51:30 AM) (Source: Service Control Manager) (User: )
Description: Služba SSPORT neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (12/03/2013 08:04:02 AM) (Source: DCOM) (User: USER-9E9A9A8968)
Description: Služba DCOM zjistila chybu %/ComService při pokusu o spuštění služby SkypeUpdate s argumenty /ComService
za účelem spuštění serveru:
{CC957078-B838-47C4-A7CF-626E7A82FC58}

Error: (12/03/2013 08:03:38 AM) (Source: Service Control Manager) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
i8042prt

Error: (12/03/2013 08:02:40 AM) (Source: Service Control Manager) (User: )
Description: Služba SSPORT neuspěla při spuštění v důsledku následující chyby:
%%2


Microsoft Office Sessions:
=========================
Error: (12/03/2013 09:47:56 AM) (Source: Application Hang)(User: )
Description: msimn.exe6.0.2900.5512hungapp0.0.0.000000000

Error: (12/01/2013 07:54:26 PM) (Source: Application Hang)(User: )
Description: 1180947459

Error: (12/01/2013 07:54:15 PM) (Source: Application Hang)(User: )
Description: 1180947459

Error: (12/01/2013 07:54:14 PM) (Source: Application Hang)(User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000

Error: (12/01/2013 07:54:09 PM) (Source: Application Hang)(User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000

Error: (12/01/2013 10:48:21 AM) (Source: Application Error)(User: )
Description: -402916403

Error: (12/01/2013 10:48:09 AM) (Source: Application Error)(User: )
Description: toolbar.exe21.4.0.1982unknown0.0.0.010008870

Error: (12/01/2013 10:19:43 AM) (Source: Application Hang)(User: )
Description: 1180947459

Error: (12/01/2013 10:19:35 AM) (Source: Application Hang)(User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000

Error: (11/26/2013 00:57:40 PM) (Source: Avira Antivirus)(User: NT AUTHORITY)
Description: AvShadow0x3e5


==================== Memory info ===========================

Percentage of memory in use: 40%
Total physical RAM: 2038.11 MB
Available physical RAM: 1217.61 MB
Total Pagefile: 3931.35 MB
Available Pagefile: 2983.35 MB
Total Virtual: 2047.88 MB
Available Virtual: 1945.39 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:106.43 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (Move upp-int) (CDROM) (Total:0.1 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 149 GB) (Disk ID: AA54AA54)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 12:55
od vyosek
Deeeekuji, dam si obed a mrknu na to :thumbsup:

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 13:20
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [] - [x]
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [RegHunter Registry Cleaner] - "C:\Program Files\Enigma Software Group\RegHunter\RegHunter.exe" -silent
    HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
    HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
    HKCU\...\Run: [HideOE] - "C:\Program Files\Outlook Express\HideOE\HideOE.exe"
    HKCU\...\Run: [Skype] - C:\Documents and Settings\user\Plocha\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
    MountPoints2: {28fc6282-d98d-11e2-a28b-001fc6caf3ac} - E:\iLinker.exe
    MountPoints2: {b3bd9da9-b17b-11dd-89d5-806d6172696f} - D:\autorun.exe
    Startup: C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění\OpenOffice 4.0.1.lnk
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
    SearchScopes: HKLM - DefaultScope value is missing.
    BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    
    CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Documents and Settings\user\Local Settings\Data aplikací\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx
    CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
    CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
    
    R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
    S3 ioloService; C:\Program Files\SafePCRepair\ioloToolService.exe [x]
    S2 SafePCRepair_89Service; C:\PROGRA~1\SAFEPC~2\bar\1.bin\89barsvc.exe [x]
    
    DisableService: gupdate1ca7803e9217740
    DisableService: SkypeUpdate
    
    2013-12-03 12:41 - 2013-12-03 12:41 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
    2013-12-03 12:33 - 2013-12-03 12:33 - 00036942 _____ C:\Documents and Settings\user\Plocha\FRST2.txt
    2013-12-03 12:21 - 2013-12-03 12:41 - 00014646 _____ C:\Documents and Settings\user\Plocha\FRST.txt
    2013-12-03 12:15 - 2013-12-03 12:15 - 00021775 _____ C:\Documents and Settings\user\Plocha\Addition.odt
    2013-12-03 12:05 - 2013-12-03 12:41 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
    2013-12-03 12:03 - 2013-12-03 12:03 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\user\Plocha\FRSTLauncher.exe
    2013-12-03 10:11 - 2013-12-03 10:54 - 00001870 _____ C:\sc-cleaner.txt
    2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
    2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
    2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
    2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
    2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
    2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
    C:\Program Files\Enigma Software Group
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\One-Click Tweak.job => C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe
    Task: C:\WINDOWS\Tasks\RMAutoUpdate.job => C:\Program Files\PC Tools Registry Mechanic\SULauncher.exe
    Task: C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job => C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job => C:\WINDOWS\system32\msfeedssync.exe
    
    AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:31E74682
    AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 19:49
od tamuri
Tak jsem se o to pokusila, i když mi nebylo docela jasné, co znamená "Presunte vytvoreny fixlist vedle FRST".
Dvě možnosti:
1. umístit je na Ploše vedle sebe???
2. vložit fixlist.txt do FRST.txt ???
Zvolila jsem možnost č.1, i když obě mi přijdou divné...
Počkám, třeba se ještě dnes ukážete.
Slibuji ale, že i kdyby se nám nepovedlo napravit páteř mému PC, budu muset "podpořit" forum, protože nemohu být nespokojená, když se tolik pro nás obětujete (málem jste zůstal bez oběda!). Třeba to nebude světoborná částka (jsem nepr.duch), ale bude to z celého srdce. Jen ještě shvíli počkám, aby mi ten insekt nevlezl do mého bankovního účtu!

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-12-2013 02
Ran by user at 2013-12-03 19:33:12 Run:1
Running from C:\Documents and Settings\user\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [RegHunter Registry Cleaner] - "C:\Program Files\Enigma Software Group\RegHunter\RegHunter.exe" -silent
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKCU\...\Run: [HideOE] - "C:\Program Files\Outlook Express\HideOE\HideOE.exe"
HKCU\...\Run: [Skype] - C:\Documents and Settings\user\Plocha\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
MountPoints2: {28fc6282-d98d-11e2-a28b-001fc6caf3ac} - E:\iLinker.exe
MountPoints2: {b3bd9da9-b17b-11dd-89d5-806d6172696f} - D:\autorun.exe
Startup: C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění\OpenOffice 4.0.1.lnk

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File

CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Documents and Settings\user\Local Settings\Data aplikací\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
S3 ioloService; C:\Program Files\SafePCRepair\ioloToolService.exe [x]
S2 SafePCRepair_89Service; C:\PROGRA~1\SAFEPC~2\bar\1.bin\89barsvc.exe [x]

DisableService: gupdate1ca7803e9217740
DisableService: SkypeUpdate

2013-12-03 12:41 - 2013-12-03 12:41 - 00015327 _____ C:\Documents and Settings\user\Plocha\LM.bat
2013-12-03 12:33 - 2013-12-03 12:33 - 00036942 _____ C:\Documents and Settings\user\Plocha\FRST2.txt
2013-12-03 12:21 - 2013-12-03 12:41 - 00014646 _____ C:\Documents and Settings\user\Plocha\FRST.txt
2013-12-03 12:15 - 2013-12-03 12:15 - 00021775 _____ C:\Documents and Settings\user\Plocha\Addition.odt
2013-12-03 12:05 - 2013-12-03 12:41 - 00029696 _____ C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-03 12:03 - 2013-12-03 12:03 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\user\Plocha\FRSTLauncher.exe
2013-12-03 10:11 - 2013-12-03 10:54 - 00001870 _____ C:\sc-cleaner.txt
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\iolo
2013-12-03 09:27 - 2013-12-03 09:27 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\iolo
2013-12-01 09:35 - 2013-12-01 09:35 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-12-01 08:16 - 2013-12-01 08:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork
2013-12-01 08:15 - 2013-12-01 08:15 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\APN
C:\Program Files\Enigma Software Group

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\One-Click Tweak.job => C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe
Task: C:\WINDOWS\Tasks\RMAutoUpdate.job => C:\Program Files\PC Tools Registry Mechanic\SULauncher.exe
Task: C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job => C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job => C:\WINDOWS\system32\msfeedssync.exe

AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:31E74682
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RegHunter Registry Cleaner => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\HideOE => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{28fc6282-d98d-11e2-a28b-001fc6caf3ac} => Key deleted successfully.
HKCR\CLSID\{28fc6282-d98d-11e2-a28b-001fc6caf3ac} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3bd9da9-b17b-11dd-89d5-806d6172696f} => Key deleted successfully.
HKCR\CLSID\{b3bd9da9-b17b-11dd-89d5-806d6172696f} => Key not found.
C:\Documents and Settings\user\Nabídka Start\Programy\Po spuštění\OpenOffice 4.0.1.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaabfjnbeinlpljodiajipidiompfl => Key deleted successfully.
C:\Documents and Settings\user\Local Settings\Data aplikací\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx => Moved successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh => Key deleted successfully.
C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx => Moved successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Key deleted successfully.
C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx => Moved successfully.
APNMCP => Service deleted successfully.
ioloService => Service deleted successfully.
SafePCRepair_89Service => Service deleted successfully.
gupdate1ca7803e9217740 service was disabled
SkypeUpdate service was disabled
"C:\Documents and Settings\user\Plocha\LM.bat" => File/Directory not found.
"C:\Documents and Settings\user\Plocha\FRST2.txt" => File/Directory not found.
C:\Documents and Settings\user\Plocha\FRST.txt => Moved successfully.
"C:\Documents and Settings\user\Plocha\Addition.odt" => File/Directory not found.
"C:\Documents and Settings\user\Local Settings\Data aplikací\MSGBOX.EXE" => File/Directory not found.
C:\Documents and Settings\user\Plocha\FRSTLauncher.exe => Moved successfully.
C:\sc-cleaner.txt => Moved successfully.
C:\Documents and Settings\user\Local Settings\Data aplikací\iolo => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\iolo => Moved successfully.
C:\Documents and Settings\user\Local Settings\Data aplikací\AskPartnerNetwork => Moved successfully.
C:\Program Files\AskPartnerNetwork => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AskPartnerNetwork => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\APN => Moved successfully.
"C:\Program Files\Enigma Software Group" => File/Directory not found.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\WINDOWS\Tasks\One-Click Tweak.job => Moved successfully.
C:\WINDOWS\Tasks\RMAutoUpdate.job => Moved successfully.
C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job not found.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{57794725-A15C-4F8D-9494-92480DB32069}.job => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":31E74682" ADS removed successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":D1B5B4F1" ADS removed successfully.
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========



The system needs a manual reboot.

==== End of Fixlog ====

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 20:01
od vyosek
Udelala jste to dobre :thumbsup:

Jak se chova PC nyni?? Jsou nejake problemy, muzeme uklidit??

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 20:12
od tamuri
Už jsem podpořila, heč!
Přes PayPal, třeba je to safer. Budu věřit.

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 20:15
od tamuri
Aha, už jste tady!
Nevím ještě, jak se chová - neee, vím! Mrkla jsem se na Aviru, a tam již je WEB Protection aktivován!!!!
O, díky-díky, šlechetný zachránče, a hezký večer (ne snad celý u kompjuteru...). A vůbec všechno nej.

Re: Asi mám v PC nezvaného návštěvníka, prosím o kontrolu!

Napsal: 03 pro 2013 20:18
od vyosek
Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|

:arrow: Za podporu fora jmenem celeho tymu dekuji :thumbsup: Stasten a vesel i vam :happy: