Netbook neskutečně pomalý
Napsal: 04 led 2014 21:33
Zdravím vespolek,
soused mě poprosil o pomoc se svým netbookem. Při normální bootu je tak neskutečně pomalý, že se např. Ovládací panely otvírají víc než půl hodiny. V Nouzovém jede svižně.
Projeto ADWCleanerem (smazal pár toolbarů, log mám) a MBAM (bez nálezu)
Předem díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-01-2014
Ran by NB500 (administrator) on NB500-TOSH on 04-01-2014 21:27:09
Running from C:\Users\NB500\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) ===================
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [31648 2010-07-09] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [521640 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe [521528 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [742776 2010-05-08] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1697064 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1349032 2010-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [22840 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [] - [x]
HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S0].txt [7985 2014-01-04] ()
MountPoints2: {8f9e8e0a-59e3-11e0-b4e9-1c75087eb703} - E:\Autorun\setup32.exe
MountPoints2: {97b676ca-590c-11e0-adf7-1c75087eb703} - E:\Axesstel_Setup.exe
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
URLSearchHook: HKCU - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {9785D3BF-B8B7-4548-A9CF-41A4DFB5DB00} URL =
SearchScopes: HKCU - {718DFEA4-AB3C-4A38-8F92-8540CC9FECC7} URL = http://websearch.ask.com/redirect?clien ... 8755F8CBE7
SearchScopes: HKCU - {754D5866-34B4-4DAB-A69A-6D2128BB2EF4} URL = http://rover.ebay.com/rover/1/710-71511 ... earchTerms}
SearchScopes: HKCU - {9785D3BF-B8B7-4548-A9CF-41A4DFB5DB00} URL =
SearchScopes: HKCU - {D1F22BBD-05D3-47A2-800B-115456DEFA0F} URL = http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: No Name - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Users\NB500\AppData\Roaming\Mozilla\Firefox\Profiles\lpul71wv.default
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=1.6.0_39 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @mcafee.com/SAFFPlugin - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchProvider: Ask
CHR DefaultSearchURL: http://www.google.com
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\NB500\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~1\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (SiteAdvisor) - C:\Users\NB500\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx
========================== Services (Whitelisted) =================
S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2010-01-28] (TOSHIBA CORPORATION)
S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
S2 IconMan_R; C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.)
S3 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)
S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-10-06] (TOSHIBA Corporation)
S2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [189880 2010-11-11] (TOSHIBA Corporation)
S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2010-02-05] (TOSHIBA Corporation)
==================== Drivers (Whitelisted) ====================
S3 AF9035BDA; C:\Windows\System32\Drivers\AF9035BDA.sys [462952 2009-07-16] (AfaTech )
S3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 Axtmvflt; C:\Windows\System32\DRIVERS\Axtmvflt.sys [3456 2007-06-27] (Axesstel)
S3 Axtmvmdm; C:\Windows\System32\DRIVERS\Axtmvmdm.sys [40064 2007-06-27] (Axesstel)
S3 Axtmvprt; C:\Windows\System32\Drivers\Axtmvprt.sys [38784 2007-06-27] (Axesstel)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [146872 2012-04-20] (McAfee, Inc.)
R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [36208 2009-07-30] (COMPAL ELECTRONIC INC.)
S3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
R3 RTL8192Ce; C:\Windows\System32\DRIVERS\rtl8192Ce.sys [999016 2010-10-18] (Realtek Semiconductor Corporation )
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-04 21:27 - 2014-01-04 21:27 - 00012202 _____ C:\Users\NB500\Desktop\FRST.txt
2014-01-04 21:27 - 2014-01-04 21:27 - 00000000 ____D C:\FRST
2014-01-04 21:26 - 2014-01-04 21:26 - 01064761 _____ (Farbar) C:\Users\NB500\Desktop\FRST.exe
2014-01-04 21:26 - 2014-01-04 21:26 - 00112640 _____ (forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
2014-01-04 17:42 - 2014-01-04 17:54 - 00008041 _____ C:\Windows\WindowsUpdate.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00006212 _____ C:\Windows\PFRO.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000056 _____ C:\Windows\setupact.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:37 - 2014-01-04 17:37 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\NB500\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Users\NB500\AppData\Roaming\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-04 17:37 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-04 16:02 - 2014-01-04 16:02 - 00000000 ____D C:\Program Files\Defraggler
2014-01-04 15:56 - 2014-01-04 15:56 - 04645232 _____ (Piriform Ltd) C:\Users\NB500\Downloads\ccsetup409.exe
2014-01-04 15:56 - 2014-01-04 15:56 - 04208656 _____ (Piriform Ltd) C:\Users\NB500\Downloads\dfsetup216.exe
2014-01-04 15:14 - 2014-01-04 15:14 - 03218352 _____ (McAfee, Inc.) C:\Users\NB500\Downloads\MCPR.exe
2014-01-04 15:13 - 2014-01-04 15:16 - 00000000 ____D C:\AdwCleaner
2014-01-04 15:12 - 2014-01-04 15:12 - 01233962 _____ C:\Users\NB500\Downloads\AdwCleaner.exe
2013-12-30 11:56 - 2013-12-30 11:57 - 00000000 ____D C:\Program Files\GUM65C4.tmp
2013-12-30 11:56 - 2013-12-30 11:56 - 49940480 _____ C:\Program Files\GUT6661.tmp
2013-12-21 08:08 - 2013-12-21 08:09 - 00000000 ____D C:\Program Files\GUMA8FB.tmp
2013-12-21 08:08 - 2013-12-21 08:08 - 49940480 _____ C:\Program Files\GUTA94A.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 49940480 _____ C:\Program Files\GUT1F72.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 00000000 ____D C:\Program Files\GUM1EE5.tmp
2013-12-19 12:37 - 2013-12-19 12:38 - 01816576 _____ C:\Users\NB500\Desktop\vzdelavani_zdravotne_postizenych_deti.ppt
2013-12-15 12:38 - 2013-12-15 12:38 - 00034158 _____ C:\Users\NB500\Desktop\Reseni_magickeho_ctverce.odp
2013-12-15 12:38 - 2013-12-15 12:38 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Reseni_magickeho_ctverce.odp#
2013-12-13 20:33 - 2013-12-13 21:38 - 00000000 ____D C:\Users\NB500\AppData\Local\{385E3F62-E4F3-4CDA-AFB4-A8056A71A9C4}
2013-12-13 20:33 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{C46A04FA-E5E5-4E2A-BD4B-DEF7ACF20631}
2013-12-12 06:42 - 2013-12-12 06:43 - 00000000 ____D C:\Program Files\GUM531E.tmp
2013-12-12 06:42 - 2013-12-12 06:42 - 49940480 _____ C:\Program Files\GUT537D.tmp
2013-12-06 20:54 - 2013-12-06 20:54 - 00034964 _____ C:\Users\NB500\Desktop\Zápis13ml.xlsx
==================== One Month Modified Files and Folders =======
2014-01-04 21:27 - 2014-01-04 21:27 - 00012202 _____ C:\Users\NB500\Desktop\FRST.txt
2014-01-04 21:27 - 2014-01-04 21:27 - 00000000 ____D C:\FRST
2014-01-04 21:26 - 2014-01-04 21:26 - 01064761 _____ (Farbar) C:\Users\NB500\Desktop\FRST.exe
2014-01-04 21:26 - 2014-01-04 21:26 - 00112640 _____ (forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
2014-01-04 21:24 - 2013-10-01 21:11 - 00000000 ____D C:\Program Files\Mozilla Firefox
2014-01-04 17:54 - 2014-01-04 17:42 - 00008041 _____ C:\Windows\WindowsUpdate.log
2014-01-04 17:47 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-04 17:47 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-04 17:41 - 2012-11-30 21:45 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 17:40 - 2012-10-29 15:42 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-04 17:39 - 2014-01-04 17:39 - 00006212 _____ C:\Windows\PFRO.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000056 _____ C:\Windows\setupact.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:39 - 2010-11-16 19:46 - 00000000 ____D C:\ProgramData\McAfee
2014-01-04 17:39 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-04 17:37 - 2014-01-04 17:37 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\NB500\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Users\NB500\AppData\Roaming\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-04 17:37 - 2012-10-29 15:42 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 16:41 - 2012-11-30 21:47 - 00002136 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-04 16:02 - 2014-01-04 16:02 - 00000000 ____D C:\Program Files\Defraggler
2014-01-04 16:01 - 2010-11-16 17:58 - 00000000 ____D C:\Windows\Panther
2014-01-04 15:57 - 2012-12-09 11:33 - 00000972 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-04 15:57 - 2012-12-09 11:33 - 00000000 ____D C:\Program Files\CCleaner
2014-01-04 15:56 - 2014-01-04 15:56 - 04645232 _____ (Piriform Ltd) C:\Users\NB500\Downloads\ccsetup409.exe
2014-01-04 15:56 - 2014-01-04 15:56 - 04208656 _____ (Piriform Ltd) C:\Users\NB500\Downloads\dfsetup216.exe
2014-01-04 15:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\config\Journal
2014-01-04 15:16 - 2014-01-04 15:13 - 00000000 ____D C:\AdwCleaner
2014-01-04 15:14 - 2014-01-04 15:14 - 03218352 _____ (McAfee, Inc.) C:\Users\NB500\Downloads\MCPR.exe
2014-01-04 15:12 - 2014-01-04 15:12 - 01233962 _____ C:\Users\NB500\Downloads\AdwCleaner.exe
2014-01-03 17:55 - 2010-11-16 18:17 - 00005210 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-30 11:57 - 2013-12-30 11:56 - 00000000 ____D C:\Program Files\GUM65C4.tmp
2013-12-30 11:56 - 2013-12-30 11:56 - 49940480 _____ C:\Program Files\GUT6661.tmp
2013-12-21 08:09 - 2013-12-21 08:08 - 00000000 ____D C:\Program Files\GUMA8FB.tmp
2013-12-21 08:08 - 2013-12-21 08:08 - 49940480 _____ C:\Program Files\GUTA94A.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 49940480 _____ C:\Program Files\GUT1F72.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 00000000 ____D C:\Program Files\GUM1EE5.tmp
2013-12-19 12:38 - 2013-12-19 12:37 - 01816576 _____ C:\Users\NB500\Desktop\vzdelavani_zdravotne_postizenych_deti.ppt
2013-12-15 12:38 - 2013-12-15 12:38 - 00034158 _____ C:\Users\NB500\Desktop\Reseni_magickeho_ctverce.odp
2013-12-15 12:38 - 2013-12-15 12:38 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Reseni_magickeho_ctverce.odp#
2013-12-13 21:38 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{385E3F62-E4F3-4CDA-AFB4-A8056A71A9C4}
2013-12-13 20:35 - 2013-05-26 19:44 - 00000000 ____D C:\Users\NB500\AppData\Local\Windows Live
2013-12-13 20:33 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{C46A04FA-E5E5-4E2A-BD4B-DEF7ACF20631}
2013-12-12 06:43 - 2013-12-12 06:42 - 00000000 ____D C:\Program Files\GUM531E.tmp
2013-12-12 06:42 - 2013-12-12 06:42 - 49940480 _____ C:\Program Files\GUT537D.tmp
2013-12-12 06:42 - 2012-11-30 21:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-12 06:42 - 2012-11-30 21:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-09 14:01 - 2013-11-26 12:28 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Klima školy.doc#
2013-12-06 20:54 - 2013-12-06 20:54 - 00034964 _____ C:\Users\NB500\Desktop\Zápis13ml.xlsx
Some content of TEMP:
====================
C:\Users\NB500\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-14 10:02
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (WINDOWS) (Fixed) (Total:116.44 GB) (Free:83.98 GB) NTFS
Drive d: (Data) (Fixed) (Total:116.05 GB) (Free:100.22 GB) NTFS
Available physical RAM: 445.52 MB
Total physical RAM: 1013.42 MB
Percentage of memory in use: 56%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 5D67747B)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=116 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=116 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\NB500\Desktop" je 118 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPLTarget
C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify
"C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE3 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL
C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO
"C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation
%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC
Re�im ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk
C:\PROGRA~1\ArcSoft\TOTALM~1.5\TMMONI~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^NB500^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
soused mě poprosil o pomoc se svým netbookem. Při normální bootu je tak neskutečně pomalý, že se např. Ovládací panely otvírají víc než půl hodiny. V Nouzovém jede svižně.
Projeto ADWCleanerem (smazal pár toolbarů, log mám) a MBAM (bez nálezu)
Předem díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-01-2014
Ran by NB500 (administrator) on NB500-TOSH on 04-01-2014 21:27:09
Running from C:\Users\NB500\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) ===================
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [31648 2010-07-09] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [521640 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe [521528 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [742776 2010-05-08] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1697064 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1349032 2010-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [22840 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [] - [x]
HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S0].txt [7985 2014-01-04] ()
MountPoints2: {8f9e8e0a-59e3-11e0-b4e9-1c75087eb703} - E:\Autorun\setup32.exe
MountPoints2: {97b676ca-590c-11e0-adf7-1c75087eb703} - E:\Axesstel_Setup.exe
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
URLSearchHook: HKCU - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {9785D3BF-B8B7-4548-A9CF-41A4DFB5DB00} URL =
SearchScopes: HKCU - {718DFEA4-AB3C-4A38-8F92-8540CC9FECC7} URL = http://websearch.ask.com/redirect?clien ... 8755F8CBE7
SearchScopes: HKCU - {754D5866-34B4-4DAB-A69A-6D2128BB2EF4} URL = http://rover.ebay.com/rover/1/710-71511 ... earchTerms}
SearchScopes: HKCU - {9785D3BF-B8B7-4548-A9CF-41A4DFB5DB00} URL =
SearchScopes: HKCU - {D1F22BBD-05D3-47A2-800B-115456DEFA0F} URL = http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: No Name - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Users\NB500\AppData\Roaming\Mozilla\Firefox\Profiles\lpul71wv.default
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=1.6.0_39 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @mcafee.com/SAFFPlugin - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchProvider: Ask
CHR DefaultSearchURL: http://www.google.com
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\NB500\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~1\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (SiteAdvisor) - C:\Users\NB500\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx
========================== Services (Whitelisted) =================
S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2010-01-28] (TOSHIBA CORPORATION)
S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
S2 IconMan_R; C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.)
S3 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)
S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-10-06] (TOSHIBA Corporation)
S2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [189880 2010-11-11] (TOSHIBA Corporation)
S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2010-02-05] (TOSHIBA Corporation)
==================== Drivers (Whitelisted) ====================
S3 AF9035BDA; C:\Windows\System32\Drivers\AF9035BDA.sys [462952 2009-07-16] (AfaTech )
S3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 Axtmvflt; C:\Windows\System32\DRIVERS\Axtmvflt.sys [3456 2007-06-27] (Axesstel)
S3 Axtmvmdm; C:\Windows\System32\DRIVERS\Axtmvmdm.sys [40064 2007-06-27] (Axesstel)
S3 Axtmvprt; C:\Windows\System32\Drivers\Axtmvprt.sys [38784 2007-06-27] (Axesstel)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [146872 2012-04-20] (McAfee, Inc.)
R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [36208 2009-07-30] (COMPAL ELECTRONIC INC.)
S3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
R3 RTL8192Ce; C:\Windows\System32\DRIVERS\rtl8192Ce.sys [999016 2010-10-18] (Realtek Semiconductor Corporation )
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-04 21:27 - 2014-01-04 21:27 - 00012202 _____ C:\Users\NB500\Desktop\FRST.txt
2014-01-04 21:27 - 2014-01-04 21:27 - 00000000 ____D C:\FRST
2014-01-04 21:26 - 2014-01-04 21:26 - 01064761 _____ (Farbar) C:\Users\NB500\Desktop\FRST.exe
2014-01-04 21:26 - 2014-01-04 21:26 - 00112640 _____ (forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
2014-01-04 17:42 - 2014-01-04 17:54 - 00008041 _____ C:\Windows\WindowsUpdate.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00006212 _____ C:\Windows\PFRO.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000056 _____ C:\Windows\setupact.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:37 - 2014-01-04 17:37 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\NB500\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Users\NB500\AppData\Roaming\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-04 17:37 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-04 16:02 - 2014-01-04 16:02 - 00000000 ____D C:\Program Files\Defraggler
2014-01-04 15:56 - 2014-01-04 15:56 - 04645232 _____ (Piriform Ltd) C:\Users\NB500\Downloads\ccsetup409.exe
2014-01-04 15:56 - 2014-01-04 15:56 - 04208656 _____ (Piriform Ltd) C:\Users\NB500\Downloads\dfsetup216.exe
2014-01-04 15:14 - 2014-01-04 15:14 - 03218352 _____ (McAfee, Inc.) C:\Users\NB500\Downloads\MCPR.exe
2014-01-04 15:13 - 2014-01-04 15:16 - 00000000 ____D C:\AdwCleaner
2014-01-04 15:12 - 2014-01-04 15:12 - 01233962 _____ C:\Users\NB500\Downloads\AdwCleaner.exe
2013-12-30 11:56 - 2013-12-30 11:57 - 00000000 ____D C:\Program Files\GUM65C4.tmp
2013-12-30 11:56 - 2013-12-30 11:56 - 49940480 _____ C:\Program Files\GUT6661.tmp
2013-12-21 08:08 - 2013-12-21 08:09 - 00000000 ____D C:\Program Files\GUMA8FB.tmp
2013-12-21 08:08 - 2013-12-21 08:08 - 49940480 _____ C:\Program Files\GUTA94A.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 49940480 _____ C:\Program Files\GUT1F72.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 00000000 ____D C:\Program Files\GUM1EE5.tmp
2013-12-19 12:37 - 2013-12-19 12:38 - 01816576 _____ C:\Users\NB500\Desktop\vzdelavani_zdravotne_postizenych_deti.ppt
2013-12-15 12:38 - 2013-12-15 12:38 - 00034158 _____ C:\Users\NB500\Desktop\Reseni_magickeho_ctverce.odp
2013-12-15 12:38 - 2013-12-15 12:38 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Reseni_magickeho_ctverce.odp#
2013-12-13 20:33 - 2013-12-13 21:38 - 00000000 ____D C:\Users\NB500\AppData\Local\{385E3F62-E4F3-4CDA-AFB4-A8056A71A9C4}
2013-12-13 20:33 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{C46A04FA-E5E5-4E2A-BD4B-DEF7ACF20631}
2013-12-12 06:42 - 2013-12-12 06:43 - 00000000 ____D C:\Program Files\GUM531E.tmp
2013-12-12 06:42 - 2013-12-12 06:42 - 49940480 _____ C:\Program Files\GUT537D.tmp
2013-12-06 20:54 - 2013-12-06 20:54 - 00034964 _____ C:\Users\NB500\Desktop\Zápis13ml.xlsx
==================== One Month Modified Files and Folders =======
2014-01-04 21:27 - 2014-01-04 21:27 - 00012202 _____ C:\Users\NB500\Desktop\FRST.txt
2014-01-04 21:27 - 2014-01-04 21:27 - 00000000 ____D C:\FRST
2014-01-04 21:26 - 2014-01-04 21:26 - 01064761 _____ (Farbar) C:\Users\NB500\Desktop\FRST.exe
2014-01-04 21:26 - 2014-01-04 21:26 - 00112640 _____ (forum.viry.cz) C:\Users\NB500\Desktop\FRSTLauncher.exe
2014-01-04 21:24 - 2013-10-01 21:11 - 00000000 ____D C:\Program Files\Mozilla Firefox
2014-01-04 17:54 - 2014-01-04 17:42 - 00008041 _____ C:\Windows\WindowsUpdate.log
2014-01-04 17:47 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-04 17:47 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-04 17:41 - 2012-11-30 21:45 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 17:40 - 2012-10-29 15:42 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-04 17:39 - 2014-01-04 17:39 - 00006212 _____ C:\Windows\PFRO.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000056 _____ C:\Windows\setupact.log
2014-01-04 17:39 - 2014-01-04 17:39 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:39 - 2010-11-16 19:46 - 00000000 ____D C:\ProgramData\McAfee
2014-01-04 17:39 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-04 17:37 - 2014-01-04 17:37 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\NB500\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Users\NB500\AppData\Roaming\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-04 17:37 - 2014-01-04 17:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-04 17:37 - 2012-10-29 15:42 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 16:41 - 2012-11-30 21:47 - 00002136 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-04 16:02 - 2014-01-04 16:02 - 00000000 ____D C:\Program Files\Defraggler
2014-01-04 16:01 - 2010-11-16 17:58 - 00000000 ____D C:\Windows\Panther
2014-01-04 15:57 - 2012-12-09 11:33 - 00000972 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-04 15:57 - 2012-12-09 11:33 - 00000000 ____D C:\Program Files\CCleaner
2014-01-04 15:56 - 2014-01-04 15:56 - 04645232 _____ (Piriform Ltd) C:\Users\NB500\Downloads\ccsetup409.exe
2014-01-04 15:56 - 2014-01-04 15:56 - 04208656 _____ (Piriform Ltd) C:\Users\NB500\Downloads\dfsetup216.exe
2014-01-04 15:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\config\Journal
2014-01-04 15:16 - 2014-01-04 15:13 - 00000000 ____D C:\AdwCleaner
2014-01-04 15:14 - 2014-01-04 15:14 - 03218352 _____ (McAfee, Inc.) C:\Users\NB500\Downloads\MCPR.exe
2014-01-04 15:12 - 2014-01-04 15:12 - 01233962 _____ C:\Users\NB500\Downloads\AdwCleaner.exe
2014-01-03 17:55 - 2010-11-16 18:17 - 00005210 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-30 11:57 - 2013-12-30 11:56 - 00000000 ____D C:\Program Files\GUM65C4.tmp
2013-12-30 11:56 - 2013-12-30 11:56 - 49940480 _____ C:\Program Files\GUT6661.tmp
2013-12-21 08:09 - 2013-12-21 08:08 - 00000000 ____D C:\Program Files\GUMA8FB.tmp
2013-12-21 08:08 - 2013-12-21 08:08 - 49940480 _____ C:\Program Files\GUTA94A.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 49940480 _____ C:\Program Files\GUT1F72.tmp
2013-12-20 07:56 - 2013-12-20 07:56 - 00000000 ____D C:\Program Files\GUM1EE5.tmp
2013-12-19 12:38 - 2013-12-19 12:37 - 01816576 _____ C:\Users\NB500\Desktop\vzdelavani_zdravotne_postizenych_deti.ppt
2013-12-15 12:38 - 2013-12-15 12:38 - 00034158 _____ C:\Users\NB500\Desktop\Reseni_magickeho_ctverce.odp
2013-12-15 12:38 - 2013-12-15 12:38 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Reseni_magickeho_ctverce.odp#
2013-12-13 21:38 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{385E3F62-E4F3-4CDA-AFB4-A8056A71A9C4}
2013-12-13 20:35 - 2013-05-26 19:44 - 00000000 ____D C:\Users\NB500\AppData\Local\Windows Live
2013-12-13 20:33 - 2013-12-13 20:33 - 00000000 ____D C:\Users\NB500\AppData\Local\{C46A04FA-E5E5-4E2A-BD4B-DEF7ACF20631}
2013-12-12 06:43 - 2013-12-12 06:42 - 00000000 ____D C:\Program Files\GUM531E.tmp
2013-12-12 06:42 - 2013-12-12 06:42 - 49940480 _____ C:\Program Files\GUT537D.tmp
2013-12-12 06:42 - 2012-11-30 21:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-12 06:42 - 2012-11-30 21:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-09 14:01 - 2013-11-26 12:28 - 00000102 ____H C:\Users\NB500\Desktop\.~lock.Klima školy.doc#
2013-12-06 20:54 - 2013-12-06 20:54 - 00034964 _____ C:\Users\NB500\Desktop\Zápis13ml.xlsx
Some content of TEMP:
====================
C:\Users\NB500\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-14 10:02
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (WINDOWS) (Fixed) (Total:116.44 GB) (Free:83.98 GB) NTFS
Drive d: (Data) (Fixed) (Total:116.05 GB) (Free:100.22 GB) NTFS
Available physical RAM: 445.52 MB
Total physical RAM: 1013.42 MB
Percentage of memory in use: 56%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 5D67747B)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=116 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=116 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\NB500\Desktop" je 118 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPLTarget
C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify
"C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE3 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL
C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO
"C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation
%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC
Re�im ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk
C:\PROGRA~1\ArcSoft\TOTALM~1.5\TMMONI~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^NB500^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================