kontrola
Napsal: 20 úno 2014 12:58
Pěkný den. Mám jakýsi problém s počítačem. Mašinka si dělá co chce. Pomalu se zapíná, sama čas od času se restartuje, je pomalá. Prosím o prohlídku logu. Děkuji za váš čas.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Karel (administrator) on DOM on 20-02-2014 12:43:16
Running from C:\Documents and Settings\Karel\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(ABBYY (BIT Software)) C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
(Intel) C:\Program Files\Intel\AMT\LMS.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
() C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
(HP) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(ABBYY Software Ltd) C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [111208 2011-02-28] (NVIDIA Corporation)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13881448 2011-02-28] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1753192 2011-01-26] ()
HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-31] (Kaspersky Lab ZAO)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe [49152 2002-12-17] ()
HKLM\...\Run: [HPDJ Taskbar Utility] - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe [172032 2003-03-26] (HP)
HKLM\...\Run: [DeviceDiscovery] - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [40960 2002-12-02] (Hewlett-Packard)
HKLM\...\Run: [Family Tree Builder Update] - C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM\...\Run: [ABBYY Screenshot Reader Retail] - C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe [959776 2008-12-09] (ABBYY Software Ltd)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
HKU\S-1-5-21-1957994488-963894560-1801674531-1004\...\Run: [ABBYY Screenshot Reader Retail] - C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe [959776 2008-12-09] (ABBYY Software Ltd)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\Karel\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\Karel\Data aplikací\LangSoft\WebIE.dll ()
BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\Karel\Data aplikací\LangSoft\WebIE.dll ()
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759072 2008-10-27] (ABBYY (BIT Software))
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-31] (Kaspersky Lab ZAO)
R2 LMS; C:\Program Files\Intel\AMT\LMS.exe [98304 2006-06-29] (Intel)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-10-14] (PDF Complete Inc)
S2 hpdj; C:\DOCUME~1\Karel\LOCALS~1\Temp\hpdj.exe -servicerunning=true -uninstall=hp deskjet 5600 series -product= [X]
==================== Drivers (Whitelisted) ====================
R1 AFS2K; C:\WINDOWS\system32\Drivers\AFS2K.sys [82380 2011-11-24] (Oak Technology Inc.)
R0 kl1; C:\WINDOWS\System32\drivers\kl1.sys [133208 2011-03-04] (Kaspersky Lab ZAO)
R1 kl2; C:\WINDOWS\System32\DRIVERS\kl2.sys [11352 2011-03-04] (Kaspersky Lab ZAO)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [565552 2011-04-20] (Kaspersky Lab)
R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [34608 2011-03-10] (Kaspersky Lab ZAO)
S3 klmouflt; C:\WINDOWS\System32\DRIVERS\klmouflt.sys [19472 2009-11-02] (Kaspersky Lab)
S3 NAL; C:\WINDOWS\system32\Drivers\iqvw32.sys [24064 2006-07-05] (Intel Corporation )
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [118248 2011-01-25] (NVIDIA Corporation)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S3 s716bus; C:\WINDOWS\System32\DRIVERS\s716bus.sys [83208 2007-06-29] (MCCI Corporation)
S3 s716mdfl; C:\WINDOWS\System32\DRIVERS\s716mdfl.sys [15112 2007-06-29] (MCCI Corporation)
S3 s716mdm; C:\WINDOWS\System32\DRIVERS\s716mdm.sys [108552 2007-06-29] (MCCI Corporation)
S3 s716mgmt; C:\WINDOWS\System32\DRIVERS\s716mgmt.sys [100360 2007-04-04] (MCCI Corporation)
S3 s716nd5; C:\WINDOWS\System32\DRIVERS\s716nd5.sys [23176 2007-04-04] (MCCI Corporation)
S3 s716obex; C:\WINDOWS\System32\DRIVERS\s716obex.sys [98568 2007-04-04] (MCCI Corporation)
S3 s716unic; C:\WINDOWS\System32\DRIVERS\s716unic.sys [98952 2007-04-04] (MCCI Corporation)
S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [11376 2014-02-11] ()
S3 sfng32; C:\WINDOWS\System32\drivers\sfng32.sys [41728 2005-12-02] (Sonic Focus, Inc)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1271032 2008-04-10] (IDT, Inc.)
S4 IntelIde; No ImagePath
S3 jfdcd; \??\C:\DOCUME~1\Karel\LOCALS~1\Temp\jfdcd.sys [X]
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-20 12:43 - 2014-02-20 12:43 - 00008105 _____ () C:\Documents and Settings\Karel\Plocha\FRST.txt
2014-02-20 12:43 - 2014-02-20 12:43 - 00000000 ____D () C:\FRST
2014-02-20 12:42 - 2014-02-20 12:42 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
2014-02-20 12:39 - 2014-02-20 12:39 - 01141248 _____ (Farbar) C:\Documents and Settings\Karel\Plocha\FRST.exe
2014-02-20 09:02 - 2014-02-20 09:02 - 00065536 _____ () C:\WINDOWS\Minidump\Mini022014-01.dmp
2014-02-17 13:06 - 2014-02-17 13:06 - 00065536 _____ () C:\WINDOWS\Minidump\Mini021714-01.dmp
2014-02-12 20:08 - 2014-02-12 20:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-12 19:47 - 2014-02-12 20:08 - 00003319 _____ () C:\WINDOWS\updspapi.log
2014-02-12 19:47 - 2014-02-12 19:48 - 00011445 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-12 19:46 - 2014-02-12 19:47 - 00004193 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-12 07:47 - 2014-02-12 20:08 - 00013540 _____ () C:\WINDOWS\KB2916036.log
2014-02-01 18:07 - 2014-02-01 18:07 - 03773629 _____ () C:\Documents and Settings\Karel\Plocha\kacky.wmv
2014-01-29 17:33 - 2014-01-29 17:33 - 00001521 _____ () C:\Documents and Settings\Karel\Plocha\Mapa znaků.lnk
==================== One Month Modified Files and Folders =======
2014-02-20 12:43 - 2014-02-20 12:43 - 00008105 _____ () C:\Documents and Settings\Karel\Plocha\FRST.txt
2014-02-20 12:43 - 2014-02-20 12:43 - 00000000 ____D () C:\FRST
2014-02-20 12:43 - 2011-10-26 16:47 - 00000000 ____D () C:\Documents and Settings\Karel\Plocha
2014-02-20 12:42 - 2014-02-20 12:42 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
2014-02-20 12:42 - 2011-10-26 16:47 - 00000000 ___HD () C:\Documents and Settings\Karel\Local Settings\Data aplikací
2014-02-20 12:39 - 2014-02-20 12:39 - 01141248 _____ (Farbar) C:\Documents and Settings\Karel\Plocha\FRST.exe
2014-02-20 12:36 - 2011-11-06 17:34 - 00000000 ____D () C:\Program Files\Opera
2014-02-20 12:35 - 2011-10-26 16:40 - 01862482 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-20 12:30 - 2012-02-03 13:33 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-20 12:15 - 2011-10-26 14:55 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2014-02-20 09:04 - 2012-02-03 13:33 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-20 09:04 - 2008-04-14 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-20 09:02 - 2014-02-20 09:02 - 00065536 _____ () C:\WINDOWS\Minidump\Mini022014-01.dmp
2014-02-20 09:02 - 2013-12-15 17:03 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-02-20 09:02 - 2013-12-15 17:03 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-20 09:02 - 2011-12-21 13:15 - 00000000 ____D () C:\WINDOWS\Minidump
2014-02-20 09:02 - 2011-10-26 18:19 - 141897728 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-20 09:02 - 2011-10-26 16:46 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-20 08:48 - 2014-01-15 10:10 - 00030932 _____ () C:\WINDOWS\setupapi.log
2014-02-20 08:34 - 2011-10-26 16:46 - 00032494 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-19 20:55 - 2011-10-26 16:47 - 00000178 ___SH () C:\Documents and Settings\Karel\ntuser.ini
2014-02-19 20:46 - 2012-07-05 06:58 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-17 20:11 - 2013-11-09 23:32 - 00053091 _____ () C:\Documents and Settings\Karel\Plocha\Farma_Rozvrzeni.pptx
2014-02-17 13:06 - 2014-02-17 13:06 - 00065536 _____ () C:\WINDOWS\Minidump\Mini021714-01.dmp
2014-02-15 16:48 - 2008-04-14 13:00 - 00000713 _____ () C:\WINDOWS\win.ini
2014-02-15 09:49 - 2011-12-13 18:16 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Data aplikací\PDFC
2014-02-13 09:40 - 2011-10-27 13:28 - 00002563 _____ () C:\Documents and Settings\Karel\Plocha\Word 2007.lnk
2014-02-12 20:46 - 2011-10-26 15:54 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-02-12 20:08 - 2014-02-12 20:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-12 20:08 - 2014-02-12 19:47 - 00003319 _____ () C:\WINDOWS\updspapi.log
2014-02-12 20:08 - 2014-02-12 07:47 - 00013540 _____ () C:\WINDOWS\KB2916036.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00024732 _____ () C:\WINDOWS\FaxSetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00011824 _____ () C:\WINDOWS\ocgen.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00009436 _____ () C:\WINDOWS\tsoc.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00008164 _____ () C:\WINDOWS\comsetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00004952 _____ () C:\WINDOWS\ntdtcsetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00003927 _____ () C:\WINDOWS\iis6.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001544 _____ () C:\WINDOWS\ocmsn.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001236 _____ () C:\WINDOWS\msgsocm.log
2014-02-12 20:03 - 2011-10-26 18:28 - 01205856 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-12 19:54 - 2013-07-22 12:09 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-12 19:52 - 2011-10-26 14:40 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-12 19:48 - 2014-02-12 19:47 - 00011445 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-12 19:48 - 2014-01-16 09:01 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-02-12 19:47 - 2014-02-12 19:46 - 00004193 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-11 14:58 - 2008-04-14 13:00 - 00011376 _____ () C:\WINDOWS\system32\Drivers\secdrv.sys
2014-02-07 14:21 - 2011-11-26 10:42 - 00000000 ____D () C:\Documents and Settings\Karel\Dokumenty\MyHeritage
2014-02-06 04:38 - 2008-04-14 13:00 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-06 04:38 - 2008-04-14 13:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 00:08 - 2012-06-14 09:51 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-06 00:08 - 2011-10-26 15:59 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-06 00:08 - 2009-03-08 03:39 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 00:08 - 2009-03-08 03:32 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 00:08 - 2009-03-08 03:32 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 00:08 - 2009-03-08 03:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 01469440 ____N (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 00:08 - 2008-04-14 13:00 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-06 00:08 - 2008-04-14 13:00 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00611840 ____N (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00206848 ____N (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00043520 ____N (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00025600 ____N (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 23:24 - 2008-04-14 13:00 - 00385024 ____N (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-02-05 23:24 - 2008-04-14 13:00 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 23:24 - 2008-04-14 13:00 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-05 18:46 - 2012-07-05 06:58 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-05 18:46 - 2011-11-06 20:47 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-03 22:51 - 2011-10-26 16:47 - 00000000 ____D () C:\Documents and Settings\Karel
2014-02-01 18:09 - 2011-12-07 20:29 - 00000098 _____ () C:\Documents and Settings\Karel\default.pls
2014-02-01 18:08 - 2011-12-07 20:29 - 00000069 _____ () C:\WINDOWS\NeroDigital.ini
2014-02-01 18:07 - 2014-02-01 18:07 - 03773629 _____ () C:\Documents and Settings\Karel\Plocha\kacky.wmv
2014-02-01 10:16 - 2011-10-26 17:30 - 00000000 ____D () C:\WINDOWS\Help
2014-01-29 17:33 - 2014-01-29 17:33 - 00001521 _____ () C:\Documents and Settings\Karel\Plocha\Mapa znaků.lnk
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2008-04-14 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2008-04-14 13:00] - [2008-04-14 13:00] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2008-04-14 13:00] - [2008-04-14 13:00] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:37.27 GB) (Free:5.88 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:74.53 GB) (Free:57.1 GB) NTFS
Drive e: (AOM_D1) (CDROM) (Total:0.48 GB) (Free:0 GB) CDFS
Available physical RAM: 656.23 MB
Total physical RAM: 2029.82 MB
Percentage of memory in use: 67%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 37 GB) (Disk ID: C092C092)
Partition 1: (Active) - (Size=37 GB) - (Type=07 NTFS)
Disk: 1 (Size: 75 GB) (Disk ID: A69FA69F)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Kaspersky Internet Security (Disabled - Up to date) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security (Disabled) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Karel\Plocha" je 109 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Karel (administrator) on DOM on 20-02-2014 12:43:16
Running from C:\Documents and Settings\Karel\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(ABBYY (BIT Software)) C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
(Intel) C:\Program Files\Intel\AMT\LMS.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
() C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
(HP) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(ABBYY Software Ltd) C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [111208 2011-02-28] (NVIDIA Corporation)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13881448 2011-02-28] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1753192 2011-01-26] ()
HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-31] (Kaspersky Lab ZAO)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe [49152 2002-12-17] ()
HKLM\...\Run: [HPDJ Taskbar Utility] - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe [172032 2003-03-26] (HP)
HKLM\...\Run: [DeviceDiscovery] - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [40960 2002-12-02] (Hewlett-Packard)
HKLM\...\Run: [Family Tree Builder Update] - C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM\...\Run: [ABBYY Screenshot Reader Retail] - C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe [959776 2008-12-09] (ABBYY Software Ltd)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
HKU\S-1-5-21-1957994488-963894560-1801674531-1004\...\Run: [ABBYY Screenshot Reader Retail] - C:\Program Files\ABBYY Screenshot Reader\ScreenShotReader.exe [959776 2008-12-09] (ABBYY Software Ltd)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\Karel\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\Karel\Data aplikací\LangSoft\WebIE.dll ()
BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\Karel\Data aplikací\LangSoft\WebIE.dll ()
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759072 2008-10-27] (ABBYY (BIT Software))
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-31] (Kaspersky Lab ZAO)
R2 LMS; C:\Program Files\Intel\AMT\LMS.exe [98304 2006-06-29] (Intel)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-10-14] (PDF Complete Inc)
S2 hpdj; C:\DOCUME~1\Karel\LOCALS~1\Temp\hpdj.exe -servicerunning=true -uninstall=hp deskjet 5600 series -product= [X]
==================== Drivers (Whitelisted) ====================
R1 AFS2K; C:\WINDOWS\system32\Drivers\AFS2K.sys [82380 2011-11-24] (Oak Technology Inc.)
R0 kl1; C:\WINDOWS\System32\drivers\kl1.sys [133208 2011-03-04] (Kaspersky Lab ZAO)
R1 kl2; C:\WINDOWS\System32\DRIVERS\kl2.sys [11352 2011-03-04] (Kaspersky Lab ZAO)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [565552 2011-04-20] (Kaspersky Lab)
R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [34608 2011-03-10] (Kaspersky Lab ZAO)
S3 klmouflt; C:\WINDOWS\System32\DRIVERS\klmouflt.sys [19472 2009-11-02] (Kaspersky Lab)
S3 NAL; C:\WINDOWS\system32\Drivers\iqvw32.sys [24064 2006-07-05] (Intel Corporation )
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [118248 2011-01-25] (NVIDIA Corporation)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S3 s716bus; C:\WINDOWS\System32\DRIVERS\s716bus.sys [83208 2007-06-29] (MCCI Corporation)
S3 s716mdfl; C:\WINDOWS\System32\DRIVERS\s716mdfl.sys [15112 2007-06-29] (MCCI Corporation)
S3 s716mdm; C:\WINDOWS\System32\DRIVERS\s716mdm.sys [108552 2007-06-29] (MCCI Corporation)
S3 s716mgmt; C:\WINDOWS\System32\DRIVERS\s716mgmt.sys [100360 2007-04-04] (MCCI Corporation)
S3 s716nd5; C:\WINDOWS\System32\DRIVERS\s716nd5.sys [23176 2007-04-04] (MCCI Corporation)
S3 s716obex; C:\WINDOWS\System32\DRIVERS\s716obex.sys [98568 2007-04-04] (MCCI Corporation)
S3 s716unic; C:\WINDOWS\System32\DRIVERS\s716unic.sys [98952 2007-04-04] (MCCI Corporation)
S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [11376 2014-02-11] ()
S3 sfng32; C:\WINDOWS\System32\drivers\sfng32.sys [41728 2005-12-02] (Sonic Focus, Inc)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1271032 2008-04-10] (IDT, Inc.)
S4 IntelIde; No ImagePath
S3 jfdcd; \??\C:\DOCUME~1\Karel\LOCALS~1\Temp\jfdcd.sys [X]
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-20 12:43 - 2014-02-20 12:43 - 00008105 _____ () C:\Documents and Settings\Karel\Plocha\FRST.txt
2014-02-20 12:43 - 2014-02-20 12:43 - 00000000 ____D () C:\FRST
2014-02-20 12:42 - 2014-02-20 12:42 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
2014-02-20 12:39 - 2014-02-20 12:39 - 01141248 _____ (Farbar) C:\Documents and Settings\Karel\Plocha\FRST.exe
2014-02-20 09:02 - 2014-02-20 09:02 - 00065536 _____ () C:\WINDOWS\Minidump\Mini022014-01.dmp
2014-02-17 13:06 - 2014-02-17 13:06 - 00065536 _____ () C:\WINDOWS\Minidump\Mini021714-01.dmp
2014-02-12 20:08 - 2014-02-12 20:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-12 19:47 - 2014-02-12 20:08 - 00003319 _____ () C:\WINDOWS\updspapi.log
2014-02-12 19:47 - 2014-02-12 19:48 - 00011445 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-12 19:46 - 2014-02-12 19:47 - 00004193 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-12 07:47 - 2014-02-12 20:08 - 00013540 _____ () C:\WINDOWS\KB2916036.log
2014-02-01 18:07 - 2014-02-01 18:07 - 03773629 _____ () C:\Documents and Settings\Karel\Plocha\kacky.wmv
2014-01-29 17:33 - 2014-01-29 17:33 - 00001521 _____ () C:\Documents and Settings\Karel\Plocha\Mapa znaků.lnk
==================== One Month Modified Files and Folders =======
2014-02-20 12:43 - 2014-02-20 12:43 - 00008105 _____ () C:\Documents and Settings\Karel\Plocha\FRST.txt
2014-02-20 12:43 - 2014-02-20 12:43 - 00000000 ____D () C:\FRST
2014-02-20 12:43 - 2011-10-26 16:47 - 00000000 ____D () C:\Documents and Settings\Karel\Plocha
2014-02-20 12:42 - 2014-02-20 12:42 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Karel\Plocha\FRSTLauncher.exe
2014-02-20 12:42 - 2011-10-26 16:47 - 00000000 ___HD () C:\Documents and Settings\Karel\Local Settings\Data aplikací
2014-02-20 12:39 - 2014-02-20 12:39 - 01141248 _____ (Farbar) C:\Documents and Settings\Karel\Plocha\FRST.exe
2014-02-20 12:36 - 2011-11-06 17:34 - 00000000 ____D () C:\Program Files\Opera
2014-02-20 12:35 - 2011-10-26 16:40 - 01862482 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-20 12:30 - 2012-02-03 13:33 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-20 12:15 - 2011-10-26 14:55 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2014-02-20 09:04 - 2012-02-03 13:33 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-20 09:04 - 2008-04-14 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-20 09:02 - 2014-02-20 09:02 - 00065536 _____ () C:\WINDOWS\Minidump\Mini022014-01.dmp
2014-02-20 09:02 - 2013-12-15 17:03 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-02-20 09:02 - 2013-12-15 17:03 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-20 09:02 - 2011-12-21 13:15 - 00000000 ____D () C:\WINDOWS\Minidump
2014-02-20 09:02 - 2011-10-26 18:19 - 141897728 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-20 09:02 - 2011-10-26 16:46 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-20 08:48 - 2014-01-15 10:10 - 00030932 _____ () C:\WINDOWS\setupapi.log
2014-02-20 08:34 - 2011-10-26 16:46 - 00032494 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-19 20:55 - 2011-10-26 16:47 - 00000178 ___SH () C:\Documents and Settings\Karel\ntuser.ini
2014-02-19 20:46 - 2012-07-05 06:58 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-17 20:11 - 2013-11-09 23:32 - 00053091 _____ () C:\Documents and Settings\Karel\Plocha\Farma_Rozvrzeni.pptx
2014-02-17 13:06 - 2014-02-17 13:06 - 00065536 _____ () C:\WINDOWS\Minidump\Mini021714-01.dmp
2014-02-15 16:48 - 2008-04-14 13:00 - 00000713 _____ () C:\WINDOWS\win.ini
2014-02-15 09:49 - 2011-12-13 18:16 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Data aplikací\PDFC
2014-02-13 09:40 - 2011-10-27 13:28 - 00002563 _____ () C:\Documents and Settings\Karel\Plocha\Word 2007.lnk
2014-02-12 20:46 - 2011-10-26 15:54 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-02-12 20:08 - 2014-02-12 20:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-12 20:08 - 2014-02-12 19:47 - 00003319 _____ () C:\WINDOWS\updspapi.log
2014-02-12 20:08 - 2014-02-12 07:47 - 00013540 _____ () C:\WINDOWS\KB2916036.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00024732 _____ () C:\WINDOWS\FaxSetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00011824 _____ () C:\WINDOWS\ocgen.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00009436 _____ () C:\WINDOWS\tsoc.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00008164 _____ () C:\WINDOWS\comsetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00004952 _____ () C:\WINDOWS\ntdtcsetup.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00003927 _____ () C:\WINDOWS\iis6.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001544 _____ () C:\WINDOWS\ocmsn.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-02-12 20:08 - 2014-01-16 09:01 - 00001236 _____ () C:\WINDOWS\msgsocm.log
2014-02-12 20:03 - 2011-10-26 18:28 - 01205856 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-12 19:54 - 2013-07-22 12:09 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-12 19:52 - 2011-10-26 14:40 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-12 19:48 - 2014-02-12 19:47 - 00011445 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-02-12 19:48 - 2014-01-16 09:01 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-02-12 19:47 - 2014-02-12 19:46 - 00004193 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-02-11 14:58 - 2008-04-14 13:00 - 00011376 _____ () C:\WINDOWS\system32\Drivers\secdrv.sys
2014-02-07 14:21 - 2011-11-26 10:42 - 00000000 ____D () C:\Documents and Settings\Karel\Dokumenty\MyHeritage
2014-02-06 04:38 - 2008-04-14 13:00 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-06 04:38 - 2008-04-14 13:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 00:08 - 2012-06-14 09:51 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-06 00:08 - 2011-10-26 15:59 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-06 00:08 - 2011-10-26 14:43 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-06 00:08 - 2009-03-08 03:39 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 00:08 - 2009-03-08 03:32 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 00:08 - 2009-03-08 03:32 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 00:08 - 2009-03-08 03:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 01469440 ____N (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 00:08 - 2008-04-14 13:00 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-06 00:08 - 2008-04-14 13:00 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00611840 ____N (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00206848 ____N (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00043520 ____N (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00025600 ____N (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-06 00:08 - 2008-04-14 13:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 23:24 - 2008-04-14 13:00 - 00385024 ____N (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-02-05 23:24 - 2008-04-14 13:00 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 23:24 - 2008-04-14 13:00 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-05 18:46 - 2012-07-05 06:58 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-05 18:46 - 2011-11-06 20:47 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-03 22:51 - 2011-10-26 16:47 - 00000000 ____D () C:\Documents and Settings\Karel
2014-02-01 18:09 - 2011-12-07 20:29 - 00000098 _____ () C:\Documents and Settings\Karel\default.pls
2014-02-01 18:08 - 2011-12-07 20:29 - 00000069 _____ () C:\WINDOWS\NeroDigital.ini
2014-02-01 18:07 - 2014-02-01 18:07 - 03773629 _____ () C:\Documents and Settings\Karel\Plocha\kacky.wmv
2014-02-01 10:16 - 2011-10-26 17:30 - 00000000 ____D () C:\WINDOWS\Help
2014-01-29 17:33 - 2014-01-29 17:33 - 00001521 _____ () C:\Documents and Settings\Karel\Plocha\Mapa znaků.lnk
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2008-04-14 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2008-04-14 13:00] - [2008-04-14 13:00] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2008-04-14 13:00] - [2008-04-14 13:00] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2008-04-14 13:00] - [2008-04-14 13:00] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:37.27 GB) (Free:5.88 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:74.53 GB) (Free:57.1 GB) NTFS
Drive e: (AOM_D1) (CDROM) (Total:0.48 GB) (Free:0 GB) CDFS
Available physical RAM: 656.23 MB
Total physical RAM: 2029.82 MB
Percentage of memory in use: 67%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 37 GB) (Disk ID: C092C092)
Partition 1: (Active) - (Size=37 GB) - (Type=07 NTFS)
Disk: 1 (Size: 75 GB) (Disk ID: A69FA69F)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Kaspersky Internet Security (Disabled - Up to date) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security (Disabled) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Karel\Plocha" je 109 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================