Policie ČR - FRST
Napsal: 07 led 2014 18:23
Dobrý den,
Ráno mi v prohlížeči vyskočil vir Policie ČR, tak jsem zkoušel projet PC ESET Online Scannerem a Norton Power Eraserem a nic to nenašlo. Od té doby už se mi Policie ČR neukázala, ale pochybuju, že to jen tak zmizelo. Někdo se s tímto virem prý nemůže dostat do safe modu, to mě jde v pohodě.
Takže tady ten log z FRSTu:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-01-2014
Ran by JL (administrator) on JL-PC on 07-01-2014 18:11:04
Running from C:\Users\JL\Desktop
Microsoft Windows 7 Professional (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Garena Plus\ggdllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-12-11] ()
HKCU\...\Run: [GarenaPlus] - C:\Program Files\Garena Plus\GarenaMessenger.exe [9890608 2013-11-21] ()
MountPoints2: {33d2785e-b154-11e2-8bb7-0015c5560449} - F:\RunGame.exe
MountPoints2: {998955ff-628b-11e3-b1f7-0015c5560449} - E:\SISetup.exe
Startup: C:\Users\JL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warcraft Config.lnk
ShortcutTarget: Warcraft Config.lnk -> C:\Program Files\Warcraft III Reign of Chaos & The Frozen Throne\support\config.exe (No File)
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{953BE56C-834D-458D-915D-A3C4E4CFCAEA}: [NameServer]77.48.100.254,78.48.100.254
FireFox:
========
FF ProfilePath: C:\Users\JL\AppData\Roaming\Mozilla\Firefox\Profiles\82jyx6m3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF Plugin: @t.garena.com/garenatalk - C:\Program Files\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\JL\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\JL\AppData\Roaming\Mozilla\Firefox\Profiles\82jyx6m3.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR RestoreOnStartup: "hxxp://www.seznam.cz/", "https://www.facebook.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\30.1_0
CHR Extension: (Google Docs) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Email) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig\1.3.13_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Slovn\u00EDk) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd\1.2.13_0
CHR Extension: (YouTube) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0
CHR Extension: (Google Play Books) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.9_0
CHR Extension: (Google Wallet) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak\1.5.14_0
CHR Extension: (Gmail) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-12-11] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-05-06] (DT Soft Ltd)
S3 NANMp50; C:\Windows\System32\Drivers\NANMp50.sys [36408 2010-03-25] (Printing Communications Assoc., Inc. (PCAUSA))
S3 NANSp50; C:\Windows\System32\Drivers\NANSp50.sys [35384 2010-03-25] (Printing Communications Assoc., Inc. (PCAUSA))
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-31] (Avira GmbH)
R1 TsLwWfF; C:\Windows\System32\DRIVERS\TsLwWfF.sys [25288 2013-07-26] (TamoSoft)
S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-07 18:09 - 2014-01-07 18:11 - 00010820 _____ C:\Users\JL\Desktop\FRST.txt
2014-01-07 18:06 - 2014-01-07 18:06 - 01064805 _____ (Farbar) C:\Users\JL\Desktop\FRST.exe
2014-01-07 18:06 - 2014-01-07 18:06 - 00112640 _____ (forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
2014-01-07 17:49 - 2014-01-07 17:49 - 00000000 ____D C:\FRST
2014-01-07 08:01 - 2014-01-07 08:01 - 02347384 _____ (ESET) C:\Users\JL\Desktop\esetsmartinstaller_csy.exe
2014-01-07 08:01 - 2014-01-07 08:01 - 00000000 ____D C:\Program Files\ESET
2014-01-07 07:41 - 2014-01-07 17:19 - 00000000 ____D C:\Users\JL\AppData\Local\NPE
2014-01-07 07:41 - 2014-01-07 07:41 - 03062248 ____N (Symantec Corporation) C:\Users\JL\Desktop\NPE.exe
2014-01-07 07:41 - 2014-01-07 07:41 - 00000000 ____D C:\ProgramData\Norton
2014-01-05 15:35 - 2014-01-05 21:29 - 00000000 ____D C:\Users\JL\Desktop\metodika
2014-01-03 19:01 - 2014-01-03 19:01 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2014-01-03 18:52 - 2012-09-27 01:30 - 00100256 _____ (HP) C:\Windows\system32\HPSIsvc.exe
2014-01-03 18:51 - 2014-01-03 18:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 18:50 - 2014-01-03 18:50 - 00000000 ____D C:\Program Files\HP
2014-01-03 18:50 - 2012-09-26 06:45 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-01-03 18:50 - 2012-09-26 06:45 - 00017408 _____ (Marvell Semiconductor, Inc.) C:\Windows\system32\Drivers\mvusbews.sys
2014-01-03 18:50 - 2012-08-31 15:01 - 01511424 _____ C:\Windows\system32\HP1100SM.EXE
2014-01-03 18:50 - 2012-08-31 15:01 - 00151552 _____ C:\Windows\system32\HP1100LM.DLL
2014-01-03 18:50 - 2012-08-31 08:10 - 00284160 _____ C:\Windows\system32\mvhlewsi.dll
2014-01-03 18:49 - 2012-09-26 06:45 - 00081920 _____ C:\Windows\system32\mvusbews.dll
2014-01-03 18:49 - 2012-09-26 06:45 - 00048128 _____ C:\Windows\system32\HP1100SMs.dll
2013-12-22 18:22 - 2013-12-22 18:22 - 00016481 _____ C:\Users\JL\Downloads\[kickass.to]dobry.will.hunting.good.will.hunting.cz.dvdrip.by.soty.torrent
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\JL\AppData\Local\Launcher
2013-12-21 18:08 - 2013-12-21 18:08 - 00000000 ____D C:\Users\JL\AppData\Local\id Software
2013-12-21 18:07 - 2013-12-21 18:07 - 00000997 _____ C:\Users\Public\Desktop\Quake Live.lnk
2013-12-21 18:07 - 2013-12-21 18:07 - 00000000 ____D C:\Program Files\Quake Live
2013-12-21 18:06 - 2013-12-21 18:06 - 06024320 _____ C:\Users\JL\Downloads\QuakeLiveSetup_841.exe
2013-12-16 20:16 - 2013-12-16 20:16 - 00000000 ____D C:\Users\JL\AppData\Roaming\Unity
2013-12-16 20:11 - 2013-12-16 20:11 - 01050264 _____ (Unity Technologies ApS) C:\Users\JL\Downloads\UnityWebPlayer.exe
2013-12-13 15:26 - 2013-12-23 19:56 - 00000000 ____D C:\Users\JL\Downloads\foto
2013-12-13 07:22 - 2013-12-13 19:11 - 00000000 ____D C:\Users\JL\Downloads\ITC
2013-12-11 20:56 - 2013-12-11 20:56 - 00049304 _____ C:\Users\JL\Downloads\The-Wolverine(0000226777).srt
2013-12-11 19:49 - 2013-12-11 19:50 - 00053958 _____ C:\Users\JL\Downloads\The-Wolverine(0000226817).srt
2013-12-11 18:49 - 2013-12-11 18:49 - 00001143 _____ C:\Users\JL\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-12-11 18:49 - 2013-12-11 18:49 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-12-11 18:21 - 2013-12-11 18:41 - 00000000 ____D C:\AdwCleaner
2013-12-11 18:21 - 2013-12-11 18:21 - 01226802 _____ C:\Users\JL\Downloads\adwcleaner.exe
2013-12-09 09:02 - 2013-12-09 09:02 - 00103780 _____ C:\Users\JL\Downloads\The-Hobbit-An-Unexpected-Journey(0000210380).srt
2013-12-08 20:12 - 2013-12-08 20:12 - 00098591 _____ C:\Users\JL\Downloads\Men-in-Black-3(0000224959).srt
2013-12-08 14:27 - 2013-12-08 14:27 - 00046751 _____ C:\Users\JL\Downloads\Riddick(0000228062).srt
2013-12-08 14:26 - 2013-12-08 14:26 - 00025441 _____ C:\Users\JL\Downloads\the.hunger.games.(2012).cze.1cd.(4633609).zip
==================== One Month Modified Files and Folders =======
2014-01-07 18:11 - 2014-01-07 18:09 - 00010820 _____ C:\Users\JL\Desktop\FRST.txt
2014-01-07 18:06 - 2014-01-07 18:06 - 01064805 _____ (Farbar) C:\Users\JL\Desktop\FRST.exe
2014-01-07 18:06 - 2014-01-07 18:06 - 00112640 _____ (forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
2014-01-07 17:50 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-07 17:50 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-07 17:49 - 2014-01-07 17:49 - 00000000 ____D C:\FRST
2014-01-07 17:46 - 2013-04-28 21:09 - 01317032 _____ C:\Windows\WindowsUpdate.log
2014-01-07 17:44 - 2013-05-05 01:57 - 00000000 ____D C:\Users\JL\AppData\Roaming\GarenaPlus
2014-01-07 17:44 - 2013-05-05 01:56 - 00000000 ____D C:\ProgramData\GarenaMessenger
2014-01-07 17:40 - 2013-04-28 21:23 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-07 17:40 - 2013-04-28 21:23 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-07 17:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 17:40 - 2009-07-14 05:39 - 00003691 _____ C:\Windows\setupact.log
2014-01-07 17:19 - 2014-01-07 07:41 - 00000000 ____D C:\Users\JL\AppData\Local\NPE
2014-01-07 08:01 - 2014-01-07 08:01 - 02347384 _____ (ESET) C:\Users\JL\Desktop\esetsmartinstaller_csy.exe
2014-01-07 08:01 - 2014-01-07 08:01 - 00000000 ____D C:\Program Files\ESET
2014-01-07 07:41 - 2014-01-07 07:41 - 03062248 ____N (Symantec Corporation) C:\Users\JL\Desktop\NPE.exe
2014-01-07 07:41 - 2014-01-07 07:41 - 00000000 ____D C:\ProgramData\Norton
2014-01-05 21:29 - 2014-01-05 15:35 - 00000000 ____D C:\Users\JL\Desktop\metodika
2014-01-04 19:49 - 2013-12-05 19:49 - 00000274 _____ C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job
2014-01-04 17:34 - 2013-04-28 22:30 - 00111920 _____ C:\Windows\PFRO.log
2014-01-04 17:13 - 2013-05-12 18:17 - 00000000 ____D C:\Users\JL\AppData\Roaming\vlc
2014-01-03 19:10 - 2013-04-28 21:17 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 19:01 - 2014-01-03 19:01 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2014-01-03 18:51 - 2014-01-03 18:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 18:50 - 2014-01-03 18:50 - 00000000 ____D C:\Program Files\HP
2014-01-03 08:21 - 2013-04-28 21:47 - 00000000 ____D C:\Users\JL\Downloads\Torrenty
2014-01-02 18:49 - 2013-04-28 21:35 - 00000000 ____D C:\Users\JL\AppData\Roaming\uTorrent
2014-01-02 17:49 - 2013-12-05 19:49 - 00000258 _____ C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job
2013-12-23 19:56 - 2013-12-13 15:26 - 00000000 ____D C:\Users\JL\Downloads\foto
2013-12-22 18:22 - 2013-12-22 18:22 - 00016481 _____ C:\Users\JL\Downloads\[kickass.to]dobry.will.hunting.good.will.hunting.cz.dvdrip.by.soty.torrent
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\JL\AppData\Local\Launcher
2013-12-21 18:08 - 2013-12-21 18:08 - 00000000 ____D C:\Users\JL\AppData\Local\id Software
2013-12-21 18:07 - 2013-12-21 18:07 - 00000997 _____ C:\Users\Public\Desktop\Quake Live.lnk
2013-12-21 18:07 - 2013-12-21 18:07 - 00000000 ____D C:\Program Files\Quake Live
2013-12-21 18:06 - 2013-12-21 18:06 - 06024320 _____ C:\Users\JL\Downloads\QuakeLiveSetup_841.exe
2013-12-19 13:44 - 2013-11-06 19:01 - 00000000 ____D C:\Users\JL\Desktop\Petanek
2013-12-18 12:07 - 2013-11-24 22:55 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-18 12:07 - 2013-11-24 22:55 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-18 12:07 - 2013-11-24 22:55 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-16 20:16 - 2013-12-16 20:16 - 00000000 ____D C:\Users\JL\AppData\Roaming\Unity
2013-12-16 20:11 - 2013-12-16 20:11 - 01050264 _____ (Unity Technologies ApS) C:\Users\JL\Downloads\UnityWebPlayer.exe
2013-12-13 19:11 - 2013-12-13 07:22 - 00000000 ____D C:\Users\JL\Downloads\ITC
2013-12-11 20:56 - 2013-12-11 20:56 - 00049304 _____ C:\Users\JL\Downloads\The-Wolverine(0000226777).srt
2013-12-11 19:50 - 2013-12-11 19:49 - 00053958 _____ C:\Users\JL\Downloads\The-Wolverine(0000226817).srt
2013-12-11 18:49 - 2013-12-11 18:49 - 00001143 _____ C:\Users\JL\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-12-11 18:49 - 2013-12-11 18:49 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-12-11 18:41 - 2013-12-11 18:21 - 00000000 ____D C:\AdwCleaner
2013-12-11 18:21 - 2013-12-11 18:21 - 01226802 _____ C:\Users\JL\Downloads\adwcleaner.exe
2013-12-09 16:26 - 2013-05-06 20:39 - 00000000 ____D C:\Users\JL\AppData\Local\Microsoft Help
2013-12-09 09:02 - 2013-12-09 09:02 - 00103780 _____ C:\Users\JL\Downloads\The-Hobbit-An-Unexpected-Journey(0000210380).srt
2013-12-08 20:12 - 2013-12-08 20:12 - 00098591 _____ C:\Users\JL\Downloads\Men-in-Black-3(0000224959).srt
2013-12-08 14:27 - 2013-12-08 14:27 - 00046751 _____ C:\Users\JL\Downloads\Riddick(0000228062).srt
2013-12-08 14:26 - 2013-12-08 14:26 - 00025441 _____ C:\Users\JL\Downloads\the.hunger.games.(2012).cze.1cd.(4633609).zip
Some content of TEMP:
====================
C:\Users\JL\AppData\Local\Temp\AdwCleaner.exe
C:\Users\JL\AppData\Local\Temp\AutoRun.exe
C:\Users\JL\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\JL\AppData\Local\Temp\avgnt.exe
C:\Users\JL\AppData\Local\Temp\bitool.dll
C:\Users\JL\AppData\Local\Temp\eauninstall.exe
C:\Users\JL\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe
C:\Users\JL\AppData\Local\Temp\Need for Speed Underground 2_uninst.exe
C:\Users\JL\AppData\Local\Temp\ose00000.exe
C:\Users\JL\AppData\Local\Temp\siinst.exe
C:\Users\JL\AppData\Local\Temp\SkypeSetup.exe
C:\Users\JL\AppData\Local\Temp\strings.dll
C:\Users\JL\AppData\Local\Temp\ubi7D48.tmp.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-03 19:33
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:74.53 GB) (Free:9.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Available physical RAM: 1083.6 MB
Total physical RAM: 2038.12 MB
Percentage of memory in use: 46%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: A39DA39D)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe
Task: C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows:38B9EA9AF583150F
AlternateDataStreams: C:\Windows:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
==================== Security Center ==================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\JL\Desktop" je 763 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Předem díky za odpověď a Váš čas.
Ráno mi v prohlížeči vyskočil vir Policie ČR, tak jsem zkoušel projet PC ESET Online Scannerem a Norton Power Eraserem a nic to nenašlo. Od té doby už se mi Policie ČR neukázala, ale pochybuju, že to jen tak zmizelo. Někdo se s tímto virem prý nemůže dostat do safe modu, to mě jde v pohodě.
Takže tady ten log z FRSTu:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-01-2014
Ran by JL (administrator) on JL-PC on 07-01-2014 18:11:04
Running from C:\Users\JL\Desktop
Microsoft Windows 7 Professional (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Garena Plus\ggdllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-12-11] ()
HKCU\...\Run: [GarenaPlus] - C:\Program Files\Garena Plus\GarenaMessenger.exe [9890608 2013-11-21] ()
MountPoints2: {33d2785e-b154-11e2-8bb7-0015c5560449} - F:\RunGame.exe
MountPoints2: {998955ff-628b-11e3-b1f7-0015c5560449} - E:\SISetup.exe
Startup: C:\Users\JL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warcraft Config.lnk
ShortcutTarget: Warcraft Config.lnk -> C:\Program Files\Warcraft III Reign of Chaos & The Frozen Throne\support\config.exe (No File)
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{953BE56C-834D-458D-915D-A3C4E4CFCAEA}: [NameServer]77.48.100.254,78.48.100.254
FireFox:
========
FF ProfilePath: C:\Users\JL\AppData\Roaming\Mozilla\Firefox\Profiles\82jyx6m3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF Plugin: @t.garena.com/garenatalk - C:\Program Files\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\JL\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\JL\AppData\Roaming\Mozilla\Firefox\Profiles\82jyx6m3.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR RestoreOnStartup: "hxxp://www.seznam.cz/", "https://www.facebook.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\30.1_0
CHR Extension: (Google Docs) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Email) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig\1.3.13_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Slovn\u00EDk) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd\1.2.13_0
CHR Extension: (YouTube) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0
CHR Extension: (Google Play Books) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.9_0
CHR Extension: (Google Wallet) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak\1.5.14_0
CHR Extension: (Gmail) - C:\Users\JL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-12-11] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-05-06] (DT Soft Ltd)
S3 NANMp50; C:\Windows\System32\Drivers\NANMp50.sys [36408 2010-03-25] (Printing Communications Assoc., Inc. (PCAUSA))
S3 NANSp50; C:\Windows\System32\Drivers\NANSp50.sys [35384 2010-03-25] (Printing Communications Assoc., Inc. (PCAUSA))
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-31] (Avira GmbH)
R1 TsLwWfF; C:\Windows\System32\DRIVERS\TsLwWfF.sys [25288 2013-07-26] (TamoSoft)
S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-07 18:09 - 2014-01-07 18:11 - 00010820 _____ C:\Users\JL\Desktop\FRST.txt
2014-01-07 18:06 - 2014-01-07 18:06 - 01064805 _____ (Farbar) C:\Users\JL\Desktop\FRST.exe
2014-01-07 18:06 - 2014-01-07 18:06 - 00112640 _____ (forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
2014-01-07 17:49 - 2014-01-07 17:49 - 00000000 ____D C:\FRST
2014-01-07 08:01 - 2014-01-07 08:01 - 02347384 _____ (ESET) C:\Users\JL\Desktop\esetsmartinstaller_csy.exe
2014-01-07 08:01 - 2014-01-07 08:01 - 00000000 ____D C:\Program Files\ESET
2014-01-07 07:41 - 2014-01-07 17:19 - 00000000 ____D C:\Users\JL\AppData\Local\NPE
2014-01-07 07:41 - 2014-01-07 07:41 - 03062248 ____N (Symantec Corporation) C:\Users\JL\Desktop\NPE.exe
2014-01-07 07:41 - 2014-01-07 07:41 - 00000000 ____D C:\ProgramData\Norton
2014-01-05 15:35 - 2014-01-05 21:29 - 00000000 ____D C:\Users\JL\Desktop\metodika
2014-01-03 19:01 - 2014-01-03 19:01 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2014-01-03 18:52 - 2012-09-27 01:30 - 00100256 _____ (HP) C:\Windows\system32\HPSIsvc.exe
2014-01-03 18:51 - 2014-01-03 18:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 18:50 - 2014-01-03 18:50 - 00000000 ____D C:\Program Files\HP
2014-01-03 18:50 - 2012-09-26 06:45 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-01-03 18:50 - 2012-09-26 06:45 - 00017408 _____ (Marvell Semiconductor, Inc.) C:\Windows\system32\Drivers\mvusbews.sys
2014-01-03 18:50 - 2012-08-31 15:01 - 01511424 _____ C:\Windows\system32\HP1100SM.EXE
2014-01-03 18:50 - 2012-08-31 15:01 - 00151552 _____ C:\Windows\system32\HP1100LM.DLL
2014-01-03 18:50 - 2012-08-31 08:10 - 00284160 _____ C:\Windows\system32\mvhlewsi.dll
2014-01-03 18:49 - 2012-09-26 06:45 - 00081920 _____ C:\Windows\system32\mvusbews.dll
2014-01-03 18:49 - 2012-09-26 06:45 - 00048128 _____ C:\Windows\system32\HP1100SMs.dll
2013-12-22 18:22 - 2013-12-22 18:22 - 00016481 _____ C:\Users\JL\Downloads\[kickass.to]dobry.will.hunting.good.will.hunting.cz.dvdrip.by.soty.torrent
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\JL\AppData\Local\Launcher
2013-12-21 18:08 - 2013-12-21 18:08 - 00000000 ____D C:\Users\JL\AppData\Local\id Software
2013-12-21 18:07 - 2013-12-21 18:07 - 00000997 _____ C:\Users\Public\Desktop\Quake Live.lnk
2013-12-21 18:07 - 2013-12-21 18:07 - 00000000 ____D C:\Program Files\Quake Live
2013-12-21 18:06 - 2013-12-21 18:06 - 06024320 _____ C:\Users\JL\Downloads\QuakeLiveSetup_841.exe
2013-12-16 20:16 - 2013-12-16 20:16 - 00000000 ____D C:\Users\JL\AppData\Roaming\Unity
2013-12-16 20:11 - 2013-12-16 20:11 - 01050264 _____ (Unity Technologies ApS) C:\Users\JL\Downloads\UnityWebPlayer.exe
2013-12-13 15:26 - 2013-12-23 19:56 - 00000000 ____D C:\Users\JL\Downloads\foto
2013-12-13 07:22 - 2013-12-13 19:11 - 00000000 ____D C:\Users\JL\Downloads\ITC
2013-12-11 20:56 - 2013-12-11 20:56 - 00049304 _____ C:\Users\JL\Downloads\The-Wolverine(0000226777).srt
2013-12-11 19:49 - 2013-12-11 19:50 - 00053958 _____ C:\Users\JL\Downloads\The-Wolverine(0000226817).srt
2013-12-11 18:49 - 2013-12-11 18:49 - 00001143 _____ C:\Users\JL\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-12-11 18:49 - 2013-12-11 18:49 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-12-11 18:21 - 2013-12-11 18:41 - 00000000 ____D C:\AdwCleaner
2013-12-11 18:21 - 2013-12-11 18:21 - 01226802 _____ C:\Users\JL\Downloads\adwcleaner.exe
2013-12-09 09:02 - 2013-12-09 09:02 - 00103780 _____ C:\Users\JL\Downloads\The-Hobbit-An-Unexpected-Journey(0000210380).srt
2013-12-08 20:12 - 2013-12-08 20:12 - 00098591 _____ C:\Users\JL\Downloads\Men-in-Black-3(0000224959).srt
2013-12-08 14:27 - 2013-12-08 14:27 - 00046751 _____ C:\Users\JL\Downloads\Riddick(0000228062).srt
2013-12-08 14:26 - 2013-12-08 14:26 - 00025441 _____ C:\Users\JL\Downloads\the.hunger.games.(2012).cze.1cd.(4633609).zip
==================== One Month Modified Files and Folders =======
2014-01-07 18:11 - 2014-01-07 18:09 - 00010820 _____ C:\Users\JL\Desktop\FRST.txt
2014-01-07 18:06 - 2014-01-07 18:06 - 01064805 _____ (Farbar) C:\Users\JL\Desktop\FRST.exe
2014-01-07 18:06 - 2014-01-07 18:06 - 00112640 _____ (forum.viry.cz) C:\Users\JL\Desktop\FRSTLauncher.exe
2014-01-07 17:50 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-07 17:50 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-07 17:49 - 2014-01-07 17:49 - 00000000 ____D C:\FRST
2014-01-07 17:46 - 2013-04-28 21:09 - 01317032 _____ C:\Windows\WindowsUpdate.log
2014-01-07 17:44 - 2013-05-05 01:57 - 00000000 ____D C:\Users\JL\AppData\Roaming\GarenaPlus
2014-01-07 17:44 - 2013-05-05 01:56 - 00000000 ____D C:\ProgramData\GarenaMessenger
2014-01-07 17:40 - 2013-04-28 21:23 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-07 17:40 - 2013-04-28 21:23 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-07 17:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 17:40 - 2009-07-14 05:39 - 00003691 _____ C:\Windows\setupact.log
2014-01-07 17:19 - 2014-01-07 07:41 - 00000000 ____D C:\Users\JL\AppData\Local\NPE
2014-01-07 08:01 - 2014-01-07 08:01 - 02347384 _____ (ESET) C:\Users\JL\Desktop\esetsmartinstaller_csy.exe
2014-01-07 08:01 - 2014-01-07 08:01 - 00000000 ____D C:\Program Files\ESET
2014-01-07 07:41 - 2014-01-07 07:41 - 03062248 ____N (Symantec Corporation) C:\Users\JL\Desktop\NPE.exe
2014-01-07 07:41 - 2014-01-07 07:41 - 00000000 ____D C:\ProgramData\Norton
2014-01-05 21:29 - 2014-01-05 15:35 - 00000000 ____D C:\Users\JL\Desktop\metodika
2014-01-04 19:49 - 2013-12-05 19:49 - 00000274 _____ C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job
2014-01-04 17:34 - 2013-04-28 22:30 - 00111920 _____ C:\Windows\PFRO.log
2014-01-04 17:13 - 2013-05-12 18:17 - 00000000 ____D C:\Users\JL\AppData\Roaming\vlc
2014-01-03 19:10 - 2013-04-28 21:17 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 19:01 - 2014-01-03 19:01 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2014-01-03 18:51 - 2014-01-03 18:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_mvusbews_01009.Wdf
2014-01-03 18:50 - 2014-01-03 18:50 - 00000000 ____D C:\Program Files\HP
2014-01-03 08:21 - 2013-04-28 21:47 - 00000000 ____D C:\Users\JL\Downloads\Torrenty
2014-01-02 18:49 - 2013-04-28 21:35 - 00000000 ____D C:\Users\JL\AppData\Roaming\uTorrent
2014-01-02 17:49 - 2013-12-05 19:49 - 00000258 _____ C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job
2013-12-23 19:56 - 2013-12-13 15:26 - 00000000 ____D C:\Users\JL\Downloads\foto
2013-12-22 18:22 - 2013-12-22 18:22 - 00016481 _____ C:\Users\JL\Downloads\[kickass.to]dobry.will.hunting.good.will.hunting.cz.dvdrip.by.soty.torrent
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\JL\AppData\Local\Launcher
2013-12-21 18:08 - 2013-12-21 18:08 - 00000000 ____D C:\Users\JL\AppData\Local\id Software
2013-12-21 18:07 - 2013-12-21 18:07 - 00000997 _____ C:\Users\Public\Desktop\Quake Live.lnk
2013-12-21 18:07 - 2013-12-21 18:07 - 00000000 ____D C:\Program Files\Quake Live
2013-12-21 18:06 - 2013-12-21 18:06 - 06024320 _____ C:\Users\JL\Downloads\QuakeLiveSetup_841.exe
2013-12-19 13:44 - 2013-11-06 19:01 - 00000000 ____D C:\Users\JL\Desktop\Petanek
2013-12-18 12:07 - 2013-11-24 22:55 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-18 12:07 - 2013-11-24 22:55 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-18 12:07 - 2013-11-24 22:55 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-16 20:16 - 2013-12-16 20:16 - 00000000 ____D C:\Users\JL\AppData\Roaming\Unity
2013-12-16 20:11 - 2013-12-16 20:11 - 01050264 _____ (Unity Technologies ApS) C:\Users\JL\Downloads\UnityWebPlayer.exe
2013-12-13 19:11 - 2013-12-13 07:22 - 00000000 ____D C:\Users\JL\Downloads\ITC
2013-12-11 20:56 - 2013-12-11 20:56 - 00049304 _____ C:\Users\JL\Downloads\The-Wolverine(0000226777).srt
2013-12-11 19:50 - 2013-12-11 19:49 - 00053958 _____ C:\Users\JL\Downloads\The-Wolverine(0000226817).srt
2013-12-11 18:49 - 2013-12-11 18:49 - 00001143 _____ C:\Users\JL\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-12-11 18:49 - 2013-12-11 18:49 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-12-11 18:41 - 2013-12-11 18:21 - 00000000 ____D C:\AdwCleaner
2013-12-11 18:21 - 2013-12-11 18:21 - 01226802 _____ C:\Users\JL\Downloads\adwcleaner.exe
2013-12-09 16:26 - 2013-05-06 20:39 - 00000000 ____D C:\Users\JL\AppData\Local\Microsoft Help
2013-12-09 09:02 - 2013-12-09 09:02 - 00103780 _____ C:\Users\JL\Downloads\The-Hobbit-An-Unexpected-Journey(0000210380).srt
2013-12-08 20:12 - 2013-12-08 20:12 - 00098591 _____ C:\Users\JL\Downloads\Men-in-Black-3(0000224959).srt
2013-12-08 14:27 - 2013-12-08 14:27 - 00046751 _____ C:\Users\JL\Downloads\Riddick(0000228062).srt
2013-12-08 14:26 - 2013-12-08 14:26 - 00025441 _____ C:\Users\JL\Downloads\the.hunger.games.(2012).cze.1cd.(4633609).zip
Some content of TEMP:
====================
C:\Users\JL\AppData\Local\Temp\AdwCleaner.exe
C:\Users\JL\AppData\Local\Temp\AutoRun.exe
C:\Users\JL\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\JL\AppData\Local\Temp\avgnt.exe
C:\Users\JL\AppData\Local\Temp\bitool.dll
C:\Users\JL\AppData\Local\Temp\eauninstall.exe
C:\Users\JL\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe
C:\Users\JL\AppData\Local\Temp\Need for Speed Underground 2_uninst.exe
C:\Users\JL\AppData\Local\Temp\ose00000.exe
C:\Users\JL\AppData\Local\Temp\siinst.exe
C:\Users\JL\AppData\Local\Temp\SkypeSetup.exe
C:\Users\JL\AppData\Local\Temp\strings.dll
C:\Users\JL\AppData\Local\Temp\ubi7D48.tmp.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-03 19:33
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:74.53 GB) (Free:9.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Available physical RAM: 1083.6 MB
Total physical RAM: 2038.12 MB
Percentage of memory in use: 46%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: A39DA39D)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe
Task: C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows:38B9EA9AF583150F
AlternateDataStreams: C:\Windows:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
==================== Security Center ==================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\JL\Desktop" je 763 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Předem díky za odpověď a Váš čas.