Ordinální číslo 459 se nepodařilo v dynamicky ...
Napsal: 20 úno 2014 10:25
Dobry den, prosim o pomoc s problemem popsanym v predmetu. Zkousel jsem vytvorit log z RSIT, ale pred jeho dokoncenim na me vyskocilo nasledujici okno:
AutoIt Error
Line -1:
Error: Variable used without being declared.
Predem moc dekuji.
Tak se mi povedl vytvorit log FRST.txt a prikladam ho + do prilohy Addition.rar
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Sesr (administrator) on SESR-PC on 20-02-2014 10:15:51
Running from C:\Users\Sesr\Desktop
Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Nero AG) C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-04-03] (Nero AG)
HKLM\...\Run: [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-08-14] (Microsoft Corporation)
HKU\S-1-5-21-3899871698-3722792670-1451281827-1000\...\Run: [PC Suite Tray] - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
==================== Internet (Whitelisted) ====================
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 21 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Sesr\AppData\Roaming\Mozilla\Firefox\Profiles\sn2fhdob.default
FF user.js: detected! => C:\Users\Sesr\AppData\Roaming\Mozilla\Firefox\Profiles\sn2fhdob.default\user.js
FF Homepage: hxxp://www.seznam.cz/|hxxp://tv.sms.cz/index.p ... m/football
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-30] (Avira GmbH)
S3 TrojanKillerDriver; C:\Windows\System32\DRIVERS\gtkdrv.sys [16128 2013-08-19] (Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-20 10:15 - 2014-02-20 10:16 - 00006996 _____ () C:\Users\Sesr\Desktop\FRST.txt
2014-02-20 10:15 - 2014-02-20 10:15 - 00000000 ____D () C:\FRST
2014-02-20 10:13 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Desktop\FRST.exe
2014-02-20 10:12 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Downloads\FRST.exe
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\rsit
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\Program Files\trend micro
2014-02-20 09:30 - 2014-02-20 09:30 - 00781909 _____ () C:\Users\Sesr\Downloads\RSIT.exe
2014-02-20 09:21 - 2014-02-20 09:21 - 00001117 _____ () C:\Users\Public\Desktop\Cinema HD 2.0.lnk
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\ProgramData\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\OGG
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\HDX4
2014-02-20 09:11 - 2014-02-20 09:12 - 26735944 _____ (Engelmann Media GmbH) C:\Users\Sesr\Downloads\cinemahd-full.exe
2014-02-15 09:34 - 2014-02-15 09:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-12 21:52 - 2014-02-12 21:53 - 02152176 _____ () C:\Users\Sesr\Downloads\CodecPerformerSetup.exe
2014-02-12 21:15 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 21:14 - 2013-12-10 03:02 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 21:14 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 21:14 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 21:14 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 21:14 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-01-29 12:49 - 2013-09-13 12:16 - 417921024 _____ () C:\Users\Sesr\Downloads\5x11-Šťastí až navěky.avi
2014-01-27 10:14 - 2014-01-28 10:40 - 00000000 ____D () C:\Users\Sesr\Desktop\Ennio-Morricone-discography-1969-2007
==================== One Month Modified Files and Folders =======
2014-02-20 10:16 - 2014-02-20 10:15 - 00006996 _____ () C:\Users\Sesr\Desktop\FRST.txt
2014-02-20 10:15 - 2014-02-20 10:15 - 00000000 ____D () C:\FRST
2014-02-20 10:12 - 2014-02-20 10:13 - 01141248 _____ (Farbar) C:\Users\Sesr\Desktop\FRST.exe
2014-02-20 10:12 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Downloads\FRST.exe
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\rsit
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\Program Files\trend micro
2014-02-20 09:47 - 2013-08-12 09:46 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-20 09:47 - 2009-07-14 05:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-20 09:47 - 2009-07-14 05:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-20 09:43 - 2013-08-12 09:04 - 01241518 _____ () C:\Windows\WindowsUpdate.log
2014-02-20 09:39 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-20 09:39 - 2009-07-14 05:39 - 00045033 _____ () C:\Windows\setupact.log
2014-02-20 09:30 - 2014-02-20 09:30 - 00781909 _____ () C:\Users\Sesr\Downloads\RSIT.exe
2014-02-20 09:21 - 2014-02-20 09:21 - 00001117 _____ () C:\Users\Public\Desktop\Cinema HD 2.0.lnk
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\ProgramData\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\OGG
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\HDX4
2014-02-20 09:17 - 2013-08-12 09:42 - 00000000 ____D () C:\Users\Sesr\AppData\Local\Adobe
2014-02-20 09:12 - 2014-02-20 09:11 - 26735944 _____ (Engelmann Media GmbH) C:\Users\Sesr\Downloads\cinemahd-full.exe
2014-02-17 21:58 - 2013-08-21 06:13 - 00000000 ____D () C:\Users\Sesr\AppData\Local\PokerStars
2014-02-17 21:57 - 2013-08-21 06:12 - 00000000 ____D () C:\Program Files\PokerStars
2014-02-17 14:30 - 2013-08-12 09:10 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 08:28 - 2013-08-12 09:12 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-15 09:35 - 2014-02-15 09:34 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-13 17:39 - 2013-08-20 08:13 - 00000000 ____D () C:\Program Files\Opera
2014-02-13 09:00 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-12 21:53 - 2014-02-12 21:52 - 02152176 _____ () C:\Users\Sesr\Downloads\CodecPerformerSetup.exe
2014-02-12 21:31 - 2013-08-14 10:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-12 21:27 - 2013-08-13 15:45 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-05 08:47 - 2013-08-12 09:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-05 08:47 - 2013-08-12 09:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-02 09:29 - 2013-09-09 09:19 - 00007680 _____ () C:\Users\Sesr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-01 14:55 - 2013-08-22 13:08 - 00706048 _____ () C:\Users\Sesr\Documents\KolemDvou.cz.xls
2014-01-31 10:38 - 2013-10-17 09:07 - 00000000 ____D () C:\Users\Sesr\Documents\Osobni
2014-01-28 11:04 - 2013-08-27 08:55 - 00000000 ____D () C:\Users\Sesr\Documents\_install
2014-01-28 10:40 - 2014-01-27 10:14 - 00000000 ____D () C:\Users\Sesr\Desktop\Ennio-Morricone-discography-1969-2007
2014-01-21 08:31 - 2013-10-17 09:00 - 00000000 ____D () C:\Users\Sesr\Documents\Sazeni
Some content of TEMP:
====================
C:\Users\Sesr\AppData\Local\Temp\avgnt.exe
C:\Users\Sesr\AppData\Local\Temp\BitLord_1.01.exe
C:\Users\Sesr\AppData\Local\Temp\Checkupdate.exe
C:\Users\Sesr\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Sesr\AppData\Local\Temp\Foxit Updater.exe
C:\Users\Sesr\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Sesr\AppData\Local\Temp\gtapi_signed.dll
C:\Users\Sesr\AppData\Local\Temp\heierun.dll
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer10_chra_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_1.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_2.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_3.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_4.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32_chrd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer12x32au_mssd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer12x32au_mssd_aaa_aih_1.exe
C:\Users\Sesr\AppData\Local\Temp\ose00000.exe
C:\Users\Sesr\AppData\Local\Temp\?odec Performer803975.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-09 10:55
==================== End Of Log ============================
AutoIt Error
Line -1:
Error: Variable used without being declared.
Predem moc dekuji.
Tak se mi povedl vytvorit log FRST.txt a prikladam ho + do prilohy Addition.rar
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Sesr (administrator) on SESR-PC on 20-02-2014 10:15:51
Running from C:\Users\Sesr\Desktop
Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Nero AG) C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-04-03] (Nero AG)
HKLM\...\Run: [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-08-14] (Microsoft Corporation)
HKU\S-1-5-21-3899871698-3722792670-1451281827-1000\...\Run: [PC Suite Tray] - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
==================== Internet (Whitelisted) ====================
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 21 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Sesr\AppData\Roaming\Mozilla\Firefox\Profiles\sn2fhdob.default
FF user.js: detected! => C:\Users\Sesr\AppData\Roaming\Mozilla\Firefox\Profiles\sn2fhdob.default\user.js
FF Homepage: hxxp://www.seznam.cz/|hxxp://tv.sms.cz/index.p ... m/football
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-30] (Avira GmbH)
S3 TrojanKillerDriver; C:\Windows\System32\DRIVERS\gtkdrv.sys [16128 2013-08-19] (Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-20 10:15 - 2014-02-20 10:16 - 00006996 _____ () C:\Users\Sesr\Desktop\FRST.txt
2014-02-20 10:15 - 2014-02-20 10:15 - 00000000 ____D () C:\FRST
2014-02-20 10:13 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Desktop\FRST.exe
2014-02-20 10:12 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Downloads\FRST.exe
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\rsit
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\Program Files\trend micro
2014-02-20 09:30 - 2014-02-20 09:30 - 00781909 _____ () C:\Users\Sesr\Downloads\RSIT.exe
2014-02-20 09:21 - 2014-02-20 09:21 - 00001117 _____ () C:\Users\Public\Desktop\Cinema HD 2.0.lnk
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\ProgramData\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\OGG
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\HDX4
2014-02-20 09:11 - 2014-02-20 09:12 - 26735944 _____ (Engelmann Media GmbH) C:\Users\Sesr\Downloads\cinemahd-full.exe
2014-02-15 09:34 - 2014-02-15 09:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-12 21:52 - 2014-02-12 21:53 - 02152176 _____ () C:\Users\Sesr\Downloads\CodecPerformerSetup.exe
2014-02-12 21:15 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 21:14 - 2013-12-10 03:02 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 21:14 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 21:14 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 21:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 21:14 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 21:14 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 21:14 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-01-29 12:49 - 2013-09-13 12:16 - 417921024 _____ () C:\Users\Sesr\Downloads\5x11-Šťastí až navěky.avi
2014-01-27 10:14 - 2014-01-28 10:40 - 00000000 ____D () C:\Users\Sesr\Desktop\Ennio-Morricone-discography-1969-2007
==================== One Month Modified Files and Folders =======
2014-02-20 10:16 - 2014-02-20 10:15 - 00006996 _____ () C:\Users\Sesr\Desktop\FRST.txt
2014-02-20 10:15 - 2014-02-20 10:15 - 00000000 ____D () C:\FRST
2014-02-20 10:12 - 2014-02-20 10:13 - 01141248 _____ (Farbar) C:\Users\Sesr\Desktop\FRST.exe
2014-02-20 10:12 - 2014-02-20 10:12 - 01141248 _____ (Farbar) C:\Users\Sesr\Downloads\FRST.exe
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\rsit
2014-02-20 09:50 - 2014-02-20 09:50 - 00000000 ____D () C:\Program Files\trend micro
2014-02-20 09:47 - 2013-08-12 09:46 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-20 09:47 - 2009-07-14 05:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-20 09:47 - 2009-07-14 05:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-20 09:43 - 2013-08-12 09:04 - 01241518 _____ () C:\Windows\WindowsUpdate.log
2014-02-20 09:39 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-20 09:39 - 2009-07-14 05:39 - 00045033 _____ () C:\Windows\setupact.log
2014-02-20 09:30 - 2014-02-20 09:30 - 00781909 _____ () C:\Users\Sesr\Downloads\RSIT.exe
2014-02-20 09:21 - 2014-02-20 09:21 - 00001117 _____ () C:\Users\Public\Desktop\Cinema HD 2.0.lnk
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\ProgramData\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Engelmann Media
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\OGG
2014-02-20 09:21 - 2014-02-20 09:21 - 00000000 ____D () C:\Program Files\Common Files\HDX4
2014-02-20 09:17 - 2013-08-12 09:42 - 00000000 ____D () C:\Users\Sesr\AppData\Local\Adobe
2014-02-20 09:12 - 2014-02-20 09:11 - 26735944 _____ (Engelmann Media GmbH) C:\Users\Sesr\Downloads\cinemahd-full.exe
2014-02-17 21:58 - 2013-08-21 06:13 - 00000000 ____D () C:\Users\Sesr\AppData\Local\PokerStars
2014-02-17 21:57 - 2013-08-21 06:12 - 00000000 ____D () C:\Program Files\PokerStars
2014-02-17 14:30 - 2013-08-12 09:10 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 08:28 - 2013-08-12 09:12 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-15 09:35 - 2014-02-15 09:34 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-13 17:39 - 2013-08-20 08:13 - 00000000 ____D () C:\Program Files\Opera
2014-02-13 09:00 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-12 21:53 - 2014-02-12 21:52 - 02152176 _____ () C:\Users\Sesr\Downloads\CodecPerformerSetup.exe
2014-02-12 21:31 - 2013-08-14 10:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-12 21:27 - 2013-08-13 15:45 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-05 08:47 - 2013-08-12 09:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-05 08:47 - 2013-08-12 09:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-02 09:29 - 2013-09-09 09:19 - 00007680 _____ () C:\Users\Sesr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-01 14:55 - 2013-08-22 13:08 - 00706048 _____ () C:\Users\Sesr\Documents\KolemDvou.cz.xls
2014-01-31 10:38 - 2013-10-17 09:07 - 00000000 ____D () C:\Users\Sesr\Documents\Osobni
2014-01-28 11:04 - 2013-08-27 08:55 - 00000000 ____D () C:\Users\Sesr\Documents\_install
2014-01-28 10:40 - 2014-01-27 10:14 - 00000000 ____D () C:\Users\Sesr\Desktop\Ennio-Morricone-discography-1969-2007
2014-01-21 08:31 - 2013-10-17 09:00 - 00000000 ____D () C:\Users\Sesr\Documents\Sazeni
Some content of TEMP:
====================
C:\Users\Sesr\AppData\Local\Temp\avgnt.exe
C:\Users\Sesr\AppData\Local\Temp\BitLord_1.01.exe
C:\Users\Sesr\AppData\Local\Temp\Checkupdate.exe
C:\Users\Sesr\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Sesr\AppData\Local\Temp\Foxit Updater.exe
C:\Users\Sesr\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Sesr\AppData\Local\Temp\gtapi_signed.dll
C:\Users\Sesr\AppData\Local\Temp\heierun.dll
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer10_chra_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_1.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_2.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_3.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih_4.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer11x32_chrd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer12x32au_mssd_aaa_aih.exe
C:\Users\Sesr\AppData\Local\Temp\install_flashplayer12x32au_mssd_aaa_aih_1.exe
C:\Users\Sesr\AppData\Local\Temp\ose00000.exe
C:\Users\Sesr\AppData\Local\Temp\?odec Performer803975.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-09 10:55
==================== End Of Log ============================