prosím o kontrolu
Napsal: 05 led 2014 21:21
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-01-2014
Ran by Michal (administrator) on MICHAELL on 05-01-2014 21:14:21
Running from C:\Documents and Settings\Michal\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
(Hewlett-Packard Company) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\WINDOWS\system32\snmp.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\loggingserver.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4297136 2012-10-30] (AVAST Software)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2009-01-05] (Apple Inc.)
HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [77824 2005-11-28] (Intel Corporation)
HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2005-11-28] (Intel Corporation)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)
HKLM\...\Run: [HP Component Manager] - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe -update activex [697272 2012-12-11] (Adobe Systems Incorporated)
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
MountPoints2: {3ca692ea-f0be-11df-ad68-004063c47f62} - G:\USBAutoRun.exe
MountPoints2: {85bdf920-d201-11e2-b018-004063c47f62} - F:\Startme.exe
AppInit_DLLs: c:\progra~1\wi9130~1\datamngr\datamngr.dll [ ] ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKLM - {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKCU - firmy.cz-181836 URL = http://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKCU - mapy.cz-181836 URL = http://www.mapy.cz/?sourceid=quicksearc ... earchTerms}
SearchScopes: HKCU - seznam.cz-181836 URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - videa.seznam.cz-181837 URL = http://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKCU - zbozi.cz-181836 URL = http://www.zbozi.cz/?sourceid=quicksear ... earchTerms}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKCU - {FF6BA700-C21C-4610-B851-7DE3D292EFB5} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
BHO: No Name - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: No Name - {0e6d7a5d-b560-4d1c-9713-18dd1ade6011} - No File
BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll (Radiocom CJSC)
BHO: No Name - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
BHO: Rich Media Player - {FEB703F7-E7B2-4AB0-9566-87658AC70095} - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\IE\PluginRichmediaplayer.dll ()
Toolbar: HKLM - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} http://192.168.200.44/VatDec.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll
DPF: {3234504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... pg4dmo.CAB
DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... p43dmo.CAB
DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9dmo.cab
DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} http://192.168.200.43/RtspVaPgDec.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 9409096453
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab
DPF: {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
Handler: rebinfo - {AF808758-C780-404C-A4EE-4526323FD9B6} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.3\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll (AVG Technologies)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer - C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
FF Extension: Rich Media Player extension - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
========================== Services (Whitelisted) =================
R2 6to4; C:\Windows\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [44808 2012-10-30] (AVAST Software)
S3 LPDSVC; C:\Windows\system32\tcpsvcs.exe [19456 2004-08-18] (Microsoft Corporation)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-18] (Microsoft Corporation)
R2 vToolbarUpdater17.1.3; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe [1643696 2013-11-21] (AVG Secure Search)
S2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [x]
==================== Drivers (Whitelisted) ====================
R1 Aavmker4; C:\Windows\System32\Drivers\Aavmker4.sys [25256 2012-10-30] (AVAST Software)
R0 abp480n5; C:\Windows\System32\DRIVERS\ABP480N5.SYS [23552 2004-08-18] (Microsoft Corporation)
S3 ASNDIS5; C:\WINDOWS\system32\ASNDIS5.SYS [16269 2002-09-09] (Printing Communications Assoc., Inc. (PCAUSA))
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-10-30] (AVAST Software)
R2 aswMon2; C:\Windows\System32\Drivers\aswMon2.sys [97608 2012-10-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35928 2012-10-30] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [738504 2012-10-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [361032 2012-10-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-10-30] (AVAST Software)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-11-21] (AVG Technologies)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [60928 2005-11-17] (ENE Technology Inc.)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [37888 2005-11-17] (ENE Technology Inc.)
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [74624 2005-11-17] (ENE Technology Inc.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-06-22] (HP)
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [218496 2005-10-24] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [998656 2005-10-18] (Conexant Systems, Inc.)
R2 MDC8021X; C:\Windows\System32\DRIVERS\mdc8021x.sys [15781 2007-04-14] (Meetinghouse Data Communications)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 nm; C:\Windows\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-18] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-18] (Microsoft Corporation)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RT2500; C:\Windows\System32\DRIVERS\RT2500.sys [211072 2004-07-29] (Ralink Technology Inc.)
S3 se58bus; C:\Windows\System32\DRIVERS\se58bus.sys [61536 2006-09-05] (MCCI)
S3 se58mdfl; C:\Windows\System32\DRIVERS\se58mdfl.sys [9360 2006-09-05] (MCCI)
S3 se58mdm; C:\Windows\System32\DRIVERS\se58mdm.sys [97088 2006-09-05] (MCCI)
S3 se58mgmt; C:\Windows\System32\DRIVERS\se58mgmt.sys [88624 2006-09-05] (MCCI)
S3 se58nd5; C:\Windows\System32\DRIVERS\se58nd5.sys [18704 2006-09-05] (MCCI)
S3 se58obex; C:\Windows\System32\DRIVERS\se58obex.sys [86432 2006-09-05] (MCCI)
S3 se58unic; C:\Windows\System32\DRIVERS\se58unic.sys [90800 2006-09-05] (MCCI)
S3 SMCIRDA; C:\Windows\System32\DRIVERS\smcirda.sys [46080 2005-10-31] (SMSC)
R1 Tcpip6; C:\Windows\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S3 w200bus; C:\Windows\System32\DRIVERS\w200bus.sys [61504 2006-11-07] (MCCI)
S3 w39n51; C:\Windows\System32\DRIVERS\w39n51.sys [1427968 2005-11-27] (Intel® Corporation)
S3 btaudio; system32\drivers\btaudio.sys [x]
S3 BTWUSB; System32\Drivers\btwusb.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SNP325; system32\DRIVERS\snp325.sys [x]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x]
S0 VClone; system32\DRIVERS\VClone.sys [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 21:14 - 2014-01-05 21:14 - 00015553 _____ C:\Documents and Settings\Michal\Plocha\FRST.txt
2014-01-05 21:14 - 2014-01-05 21:14 - 00000000 ____D C:\FRST
2014-01-05 21:13 - 2014-01-05 21:13 - 01064761 _____ (Farbar) C:\Documents and Settings\Michal\Plocha\FRST.exe
2014-01-05 20:58 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix1.exe
2014-01-05 20:53 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix.exe
2013-12-27 16:07 - 2013-12-27 16:07 - 00001167 _____ C:\_Sid.txt
2013-12-27 16:07 - 2013-12-27 16:07 - 00000434 _____ C:\WINDOWS\Tasks\WebReg 20131227160705.job
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2013-12-27 15:59 - 2004-05-11 10:53 - 00626960 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvaut32.dll
2013-12-27 15:59 - 2004-05-11 10:53 - 00487424 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvcp70.dll
2013-12-27 15:59 - 2004-05-11 10:53 - 00344064 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvcr70.dll
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Plocha\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Nabídka Start\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\Michal\Nabídka Start\Programy\HP
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\HP
2013-12-27 15:57 - 2013-12-27 15:57 - 00000000 ____D C:\Program Files\Common Files\Hewlett-Packard
2013-12-27 15:54 - 2004-03-18 16:56 - 00204800 _____ (HP) C:\WINDOWS\system32\HPZipr12.dll
2013-12-27 15:54 - 2004-03-18 16:55 - 00065536 _____ (HP) C:\WINDOWS\system32\HPZipm12.exe
2013-12-27 15:54 - 2004-03-18 16:53 - 00278584 _____ (HP) C:\WINDOWS\system32\HPZidr12.dll
2013-12-27 15:54 - 2004-03-18 16:39 - 00094208 _____ (HP) C:\WINDOWS\system32\HPZipt12.dll
2013-12-27 15:54 - 2004-03-18 16:39 - 00057344 _____ (HP) C:\WINDOWS\system32\HPZisn12.dll
2013-12-27 15:54 - 2004-03-18 16:38 - 00061440 _____ (HP) C:\WINDOWS\system32\HPZinw12.exe
2013-12-27 15:50 - 2013-12-27 15:50 - 00000000 ____D C:\Program Files\HP
2013-12-27 15:49 - 2013-12-27 16:06 - 00104567 _____ C:\WINDOWS\hpoins04.dat
2013-12-27 15:49 - 2013-12-27 16:06 - 00000820 _____ C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
2013-12-27 15:49 - 2004-06-22 11:44 - 00017176 ____N C:\WINDOWS\hpomdl04.dat
2013-12-27 15:48 - 2004-06-22 11:44 - 00581632 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpotscl.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00344064 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpzcon10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00278528 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpgwiamd.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00196608 _____ (HP) C:\WINDOWS\system32\hpzcoi10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00180315 _____ (HP) C:\WINDOWS\system32\hpzsnt10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00090112 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpovst08.dll
2013-12-26 18:25 - 2005-11-28 13:56 - 00139264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxres.dll
2013-12-26 18:16 - 2013-12-26 18:16 - 00001721 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-12-26 18:16 - 2013-12-26 18:16 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
2013-12-26 18:15 - 2014-01-05 20:31 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-26 18:15 - 2014-01-05 19:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-26 18:14 - 2013-12-26 18:15 - 00045048 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-26 13:54 - 2013-12-27 15:55 - 00043020 _____ C:\WINDOWS\setupapi.log
2013-12-26 13:52 - 2013-12-26 13:53 - 00208104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 12:52 - 2013-12-26 12:52 - 00000000 __SHD C:\FOUND.009
2013-12-26 12:27 - 2013-12-27 21:16 - 00065801 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-23 21:37 - 2013-12-23 21:38 - 00000000 ____D C:\Program Files\Google
2013-12-19 21:21 - 2013-12-19 21:21 - 17013088 _____ (Microsoft Corporation) C:\Documents and Settings\Michal\Dokumenty\IE8-WindowsXP-x86-CSY.exe
==================== One Month Modified Files and Folders =======
2014-01-05 21:14 - 2014-01-05 21:14 - 00015553 _____ C:\Documents and Settings\Michal\Plocha\FRST.txt
2014-01-05 21:14 - 2014-01-05 21:14 - 00000000 ____D C:\FRST
2014-01-05 21:13 - 2014-01-05 21:13 - 01064761 _____ (Farbar) C:\Documents and Settings\Michal\Plocha\FRST.exe
2014-01-05 20:53 - 2014-01-05 20:58 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix1.exe
2014-01-05 20:53 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix.exe
2014-01-05 20:31 - 2013-12-26 18:15 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-05 19:41 - 2013-03-27 19:23 - 00000318 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-01-05 19:40 - 2013-12-26 18:15 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 19:40 - 2011-07-10 21:02 - 00000159 _____ C:\WINDOWS\wiadebug.log
2014-01-05 19:40 - 2009-09-02 12:14 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-05 19:40 - 2006-06-29 05:11 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-27 21:16 - 2013-12-26 12:27 - 00065801 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-27 16:07 - 2013-12-27 16:07 - 00001167 _____ C:\_Sid.txt
2013-12-27 16:07 - 2013-12-27 16:07 - 00000434 _____ C:\WINDOWS\Tasks\WebReg 20131227160705.job
2013-12-27 16:06 - 2013-12-27 15:49 - 00104567 _____ C:\WINDOWS\hpoins04.dat
2013-12-27 16:06 - 2013-12-27 15:49 - 00000820 _____ C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
2013-12-27 16:01 - 2005-02-15 06:48 - 00000749 _____ C:\WINDOWS\win.ini
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Plocha\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Nabídka Start\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\Michal\Nabídka Start\Programy\HP
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\HP
2013-12-27 15:57 - 2013-12-27 15:57 - 00000000 ____D C:\Program Files\Common Files\Hewlett-Packard
2013-12-27 15:55 - 2013-12-26 13:54 - 00043020 _____ C:\WINDOWS\setupapi.log
2013-12-27 15:50 - 2013-12-27 15:50 - 00000000 ____D C:\Program Files\HP
2013-12-26 20:21 - 2011-07-18 17:20 - 00000012 _____ C:\WINDOWS\bthservsdp.dat
2013-12-26 20:21 - 2011-07-10 21:02 - 00000048 _____ C:\WINDOWS\wiaservc.log
2013-12-26 20:21 - 2011-07-10 12:56 - 00032552 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-26 20:21 - 2006-10-11 18:29 - 00000178 ___SH C:\Documents and Settings\Michal\ntuser.ini
2013-12-26 18:16 - 2013-12-26 18:16 - 00001721 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-12-26 18:16 - 2013-12-26 18:16 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
2013-12-26 18:15 - 2013-12-26 18:14 - 00045048 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-26 13:53 - 2013-12-26 13:52 - 00208104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 12:52 - 2013-12-26 12:52 - 00000000 __SHD C:\FOUND.009
2013-12-23 21:51 - 2006-10-11 18:29 - 00000711 _____ C:\Documents and Settings\Michal\Plocha\Internet Explorer.lnk
2013-12-23 21:42 - 2005-02-19 10:34 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-12-23 21:38 - 2013-12-23 21:37 - 00000000 ____D C:\Program Files\Google
2013-12-22 18:34 - 2012-08-29 20:22 - 00571904 ___SH C:\Documents and Settings\Michal\Plocha\Thumbs.db
2013-12-19 21:21 - 2013-12-19 21:21 - 17013088 _____ (Microsoft Corporation) C:\Documents and Settings\Michal\Dokumenty\IE8-WindowsXP-x86-CSY.exe
2013-12-19 16:15 - 2006-11-18 22:40 - 00217088 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-06 17:22 - 2005-02-15 06:54 - 00000042 ___SH C:\Documents and Settings\LocalService\ntuser.ini
Some content of TEMP:
====================
C:\Documents and Settings\Michal\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Administrator.MICHAEL\Local Settings\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2004-08-18 20:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2004-08-18 20:00] - [2008-04-14 05:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\rpcss.dll
[2004-08-18 20:00] - [2009-02-09 12:56] - 0401408 ____A (Microsoft Corporation) be27674d1cbc3214aec84b4336a38bbf
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 20:00] - [2008-04-14 04:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
Ran by Michal (administrator) on MICHAELL on 05-01-2014 21:14:21
Running from C:\Documents and Settings\Michal\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
(Hewlett-Packard Company) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\WINDOWS\system32\snmp.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\loggingserver.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4297136 2012-10-30] (AVAST Software)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2009-01-05] (Apple Inc.)
HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [77824 2005-11-28] (Intel Corporation)
HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2005-11-28] (Intel Corporation)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)
HKLM\...\Run: [HP Component Manager] - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe -update activex [697272 2012-12-11] (Adobe Systems Incorporated)
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
MountPoints2: {3ca692ea-f0be-11df-ad68-004063c47f62} - G:\USBAutoRun.exe
MountPoints2: {85bdf920-d201-11e2-b018-004063c47f62} - F:\Startme.exe
AppInit_DLLs: c:\progra~1\wi9130~1\datamngr\datamngr.dll [ ] ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKLM - {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKCU - firmy.cz-181836 URL = http://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKCU - mapy.cz-181836 URL = http://www.mapy.cz/?sourceid=quicksearc ... earchTerms}
SearchScopes: HKCU - seznam.cz-181836 URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - videa.seznam.cz-181837 URL = http://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKCU - zbozi.cz-181836 URL = http://www.zbozi.cz/?sourceid=quicksear ... earchTerms}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {8A96AF9E-4074-43b7-BEA3-87217BDA74C8} URL = http://www.searchqu.com/web?src=ieb&sys ... earchTerms}
SearchScopes: HKCU - {FF6BA700-C21C-4610-B851-7DE3D292EFB5} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
BHO: No Name - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: No Name - {0e6d7a5d-b560-4d1c-9713-18dd1ade6011} - No File
BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll (Radiocom CJSC)
BHO: No Name - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
BHO: Rich Media Player - {FEB703F7-E7B2-4AB0-9566-87658AC70095} - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\IE\PluginRichmediaplayer.dll ()
Toolbar: HKLM - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} http://192.168.200.44/VatDec.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll
DPF: {3234504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... pg4dmo.CAB
DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... p43dmo.CAB
DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9dmo.cab
DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} http://192.168.200.43/RtspVaPgDec.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 9409096453
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab
DPF: {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
Handler: rebinfo - {AF808758-C780-404C-A4EE-4526323FD9B6} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.3\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll (AVG Technologies)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer - C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
FF Extension: Rich Media Player extension - C:\Documents and Settings\Michal\Local Settings\Data aplikací\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
========================== Services (Whitelisted) =================
R2 6to4; C:\Windows\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [44808 2012-10-30] (AVAST Software)
S3 LPDSVC; C:\Windows\system32\tcpsvcs.exe [19456 2004-08-18] (Microsoft Corporation)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-18] (Microsoft Corporation)
R2 vToolbarUpdater17.1.3; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe [1643696 2013-11-21] (AVG Secure Search)
S2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [x]
==================== Drivers (Whitelisted) ====================
R1 Aavmker4; C:\Windows\System32\Drivers\Aavmker4.sys [25256 2012-10-30] (AVAST Software)
R0 abp480n5; C:\Windows\System32\DRIVERS\ABP480N5.SYS [23552 2004-08-18] (Microsoft Corporation)
S3 ASNDIS5; C:\WINDOWS\system32\ASNDIS5.SYS [16269 2002-09-09] (Printing Communications Assoc., Inc. (PCAUSA))
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-10-30] (AVAST Software)
R2 aswMon2; C:\Windows\System32\Drivers\aswMon2.sys [97608 2012-10-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35928 2012-10-30] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [738504 2012-10-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [361032 2012-10-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-10-30] (AVAST Software)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-11-21] (AVG Technologies)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [60928 2005-11-17] (ENE Technology Inc.)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [37888 2005-11-17] (ENE Technology Inc.)
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [74624 2005-11-17] (ENE Technology Inc.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-06-22] (HP)
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [218496 2005-10-24] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [998656 2005-10-18] (Conexant Systems, Inc.)
R2 MDC8021X; C:\Windows\System32\DRIVERS\mdc8021x.sys [15781 2007-04-14] (Meetinghouse Data Communications)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 nm; C:\Windows\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-18] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-18] (Microsoft Corporation)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RT2500; C:\Windows\System32\DRIVERS\RT2500.sys [211072 2004-07-29] (Ralink Technology Inc.)
S3 se58bus; C:\Windows\System32\DRIVERS\se58bus.sys [61536 2006-09-05] (MCCI)
S3 se58mdfl; C:\Windows\System32\DRIVERS\se58mdfl.sys [9360 2006-09-05] (MCCI)
S3 se58mdm; C:\Windows\System32\DRIVERS\se58mdm.sys [97088 2006-09-05] (MCCI)
S3 se58mgmt; C:\Windows\System32\DRIVERS\se58mgmt.sys [88624 2006-09-05] (MCCI)
S3 se58nd5; C:\Windows\System32\DRIVERS\se58nd5.sys [18704 2006-09-05] (MCCI)
S3 se58obex; C:\Windows\System32\DRIVERS\se58obex.sys [86432 2006-09-05] (MCCI)
S3 se58unic; C:\Windows\System32\DRIVERS\se58unic.sys [90800 2006-09-05] (MCCI)
S3 SMCIRDA; C:\Windows\System32\DRIVERS\smcirda.sys [46080 2005-10-31] (SMSC)
R1 Tcpip6; C:\Windows\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S3 w200bus; C:\Windows\System32\DRIVERS\w200bus.sys [61504 2006-11-07] (MCCI)
S3 w39n51; C:\Windows\System32\DRIVERS\w39n51.sys [1427968 2005-11-27] (Intel® Corporation)
S3 btaudio; system32\drivers\btaudio.sys [x]
S3 BTWUSB; System32\Drivers\btwusb.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SNP325; system32\DRIVERS\snp325.sys [x]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x]
S0 VClone; system32\DRIVERS\VClone.sys [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 21:14 - 2014-01-05 21:14 - 00015553 _____ C:\Documents and Settings\Michal\Plocha\FRST.txt
2014-01-05 21:14 - 2014-01-05 21:14 - 00000000 ____D C:\FRST
2014-01-05 21:13 - 2014-01-05 21:13 - 01064761 _____ (Farbar) C:\Documents and Settings\Michal\Plocha\FRST.exe
2014-01-05 20:58 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix1.exe
2014-01-05 20:53 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix.exe
2013-12-27 16:07 - 2013-12-27 16:07 - 00001167 _____ C:\_Sid.txt
2013-12-27 16:07 - 2013-12-27 16:07 - 00000434 _____ C:\WINDOWS\Tasks\WebReg 20131227160705.job
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2013-12-27 15:59 - 2004-05-11 10:53 - 00626960 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvaut32.dll
2013-12-27 15:59 - 2004-05-11 10:53 - 00487424 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvcp70.dll
2013-12-27 15:59 - 2004-05-11 10:53 - 00344064 ____R (Microsoft Corporation) C:\WINDOWS\system32\hpvcr70.dll
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Plocha\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Nabídka Start\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\Michal\Nabídka Start\Programy\HP
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\HP
2013-12-27 15:57 - 2013-12-27 15:57 - 00000000 ____D C:\Program Files\Common Files\Hewlett-Packard
2013-12-27 15:54 - 2004-03-18 16:56 - 00204800 _____ (HP) C:\WINDOWS\system32\HPZipr12.dll
2013-12-27 15:54 - 2004-03-18 16:55 - 00065536 _____ (HP) C:\WINDOWS\system32\HPZipm12.exe
2013-12-27 15:54 - 2004-03-18 16:53 - 00278584 _____ (HP) C:\WINDOWS\system32\HPZidr12.dll
2013-12-27 15:54 - 2004-03-18 16:39 - 00094208 _____ (HP) C:\WINDOWS\system32\HPZipt12.dll
2013-12-27 15:54 - 2004-03-18 16:39 - 00057344 _____ (HP) C:\WINDOWS\system32\HPZisn12.dll
2013-12-27 15:54 - 2004-03-18 16:38 - 00061440 _____ (HP) C:\WINDOWS\system32\HPZinw12.exe
2013-12-27 15:50 - 2013-12-27 15:50 - 00000000 ____D C:\Program Files\HP
2013-12-27 15:49 - 2013-12-27 16:06 - 00104567 _____ C:\WINDOWS\hpoins04.dat
2013-12-27 15:49 - 2013-12-27 16:06 - 00000820 _____ C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
2013-12-27 15:49 - 2004-06-22 11:44 - 00017176 ____N C:\WINDOWS\hpomdl04.dat
2013-12-27 15:48 - 2004-06-22 11:44 - 00581632 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpotscl.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00344064 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpzcon10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00278528 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpgwiamd.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00196608 _____ (HP) C:\WINDOWS\system32\hpzcoi10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00180315 _____ (HP) C:\WINDOWS\system32\hpzsnt10.dll
2013-12-27 15:48 - 2004-06-22 11:44 - 00090112 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpovst08.dll
2013-12-26 18:25 - 2005-11-28 13:56 - 00139264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxres.dll
2013-12-26 18:16 - 2013-12-26 18:16 - 00001721 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-12-26 18:16 - 2013-12-26 18:16 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
2013-12-26 18:15 - 2014-01-05 20:31 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-26 18:15 - 2014-01-05 19:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-26 18:14 - 2013-12-26 18:15 - 00045048 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-26 13:54 - 2013-12-27 15:55 - 00043020 _____ C:\WINDOWS\setupapi.log
2013-12-26 13:52 - 2013-12-26 13:53 - 00208104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 12:52 - 2013-12-26 12:52 - 00000000 __SHD C:\FOUND.009
2013-12-26 12:27 - 2013-12-27 21:16 - 00065801 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-23 21:37 - 2013-12-23 21:38 - 00000000 ____D C:\Program Files\Google
2013-12-19 21:21 - 2013-12-19 21:21 - 17013088 _____ (Microsoft Corporation) C:\Documents and Settings\Michal\Dokumenty\IE8-WindowsXP-x86-CSY.exe
==================== One Month Modified Files and Folders =======
2014-01-05 21:14 - 2014-01-05 21:14 - 00015553 _____ C:\Documents and Settings\Michal\Plocha\FRST.txt
2014-01-05 21:14 - 2014-01-05 21:14 - 00000000 ____D C:\FRST
2014-01-05 21:13 - 2014-01-05 21:13 - 01064761 _____ (Farbar) C:\Documents and Settings\Michal\Plocha\FRST.exe
2014-01-05 20:53 - 2014-01-05 20:58 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix1.exe
2014-01-05 20:53 - 2014-01-05 20:53 - 00258048 _____ (Swearware) C:\Documents and Settings\Michal\Plocha\ComboFix.exe
2014-01-05 20:31 - 2013-12-26 18:15 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-05 19:41 - 2013-03-27 19:23 - 00000318 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-01-05 19:40 - 2013-12-26 18:15 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 19:40 - 2011-07-10 21:02 - 00000159 _____ C:\WINDOWS\wiadebug.log
2014-01-05 19:40 - 2009-09-02 12:14 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-05 19:40 - 2006-06-29 05:11 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-27 21:16 - 2013-12-26 12:27 - 00065801 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-27 16:07 - 2013-12-27 16:07 - 00001167 _____ C:\_Sid.txt
2013-12-27 16:07 - 2013-12-27 16:07 - 00000434 _____ C:\WINDOWS\Tasks\WebReg 20131227160705.job
2013-12-27 16:06 - 2013-12-27 15:49 - 00104567 _____ C:\WINDOWS\hpoins04.dat
2013-12-27 16:06 - 2013-12-27 15:49 - 00000820 _____ C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
2013-12-27 16:01 - 2005-02-15 06:48 - 00000749 _____ C:\WINDOWS\win.ini
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-12-27 15:59 - 2013-12-27 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Plocha\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000688 _____ C:\Documents and Settings\All Users\Nabídka Start\Správce HP.lnk
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\Michal\Nabídka Start\Programy\HP
2013-12-27 15:58 - 2013-12-27 15:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\HP
2013-12-27 15:57 - 2013-12-27 15:57 - 00000000 ____D C:\Program Files\Common Files\Hewlett-Packard
2013-12-27 15:55 - 2013-12-26 13:54 - 00043020 _____ C:\WINDOWS\setupapi.log
2013-12-27 15:50 - 2013-12-27 15:50 - 00000000 ____D C:\Program Files\HP
2013-12-26 20:21 - 2011-07-18 17:20 - 00000012 _____ C:\WINDOWS\bthservsdp.dat
2013-12-26 20:21 - 2011-07-10 21:02 - 00000048 _____ C:\WINDOWS\wiaservc.log
2013-12-26 20:21 - 2011-07-10 12:56 - 00032552 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-26 20:21 - 2006-10-11 18:29 - 00000178 ___SH C:\Documents and Settings\Michal\ntuser.ini
2013-12-26 18:16 - 2013-12-26 18:16 - 00001721 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2013-12-26 18:16 - 2013-12-26 18:16 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
2013-12-26 18:15 - 2013-12-26 18:14 - 00045048 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-26 18:09 - 2013-12-26 18:09 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-26 13:53 - 2013-12-26 13:52 - 00208104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 12:52 - 2013-12-26 12:52 - 00000000 __SHD C:\FOUND.009
2013-12-23 21:51 - 2006-10-11 18:29 - 00000711 _____ C:\Documents and Settings\Michal\Plocha\Internet Explorer.lnk
2013-12-23 21:42 - 2005-02-19 10:34 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-12-23 21:38 - 2013-12-23 21:37 - 00000000 ____D C:\Program Files\Google
2013-12-22 18:34 - 2012-08-29 20:22 - 00571904 ___SH C:\Documents and Settings\Michal\Plocha\Thumbs.db
2013-12-19 21:21 - 2013-12-19 21:21 - 17013088 _____ (Microsoft Corporation) C:\Documents and Settings\Michal\Dokumenty\IE8-WindowsXP-x86-CSY.exe
2013-12-19 16:15 - 2006-11-18 22:40 - 00217088 _____ C:\Documents and Settings\Michal\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-06 17:22 - 2005-02-15 06:54 - 00000042 ___SH C:\Documents and Settings\LocalService\ntuser.ini
Some content of TEMP:
====================
C:\Documents and Settings\Michal\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Administrator.MICHAEL\Local Settings\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2004-08-18 20:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2004-08-18 20:00] - [2008-04-14 05:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2004-08-18 20:00] - [2008-04-14 05:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\rpcss.dll
[2004-08-18 20:00] - [2009-02-09 12:56] - 0401408 ____A (Microsoft Corporation) be27674d1cbc3214aec84b4336a38bbf
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 20:00] - [2008-04-14 04:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================