zamrzá + divná myš
Napsal: 08 bře 2014 20:16
Ahoj,
poslední dobou nám tu začal zamrzat rodinnej počítač (úplně vytuhne a je potřeba reset), procesor standardně teče na 40% a víc, blbne psaní ve wordu a dneska večer se k tomu přidalo zvláštní chování myši (když chtěla mamka nastavit kurzor, aby smazala slovo, tak se celej word úplně splašil...). Teď, když jsem pustil chroma, tak se ozval, že soubor s nastavením chromu byl poškozený a proto se celý jeho profil vytváří znova...¨
Nešlo mi vytvořit FRSTL, proto dávám jenom FRST. Snažím se učit luštění logů - a soudě podle mě, tak tam není žádnej živej vir... ale přesto prosím o zkušenější očko. Díky.
(PS: soubor C:\WINDOWS\system32\Drivers\volsnap.sys jsem testoval na virustotalu a byl čistý.)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2014 01
Ran by Honza (administrator) on RODINA on 08-03-2014 20:05:07
Running from D:\Honza\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ABBYY (BIT Software)) C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
() C:\Program Files\BTH\BTNtService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(HP) C:\WINDOWS\system32\HPSIsvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
() C:\Program Files\BTH\StartSkysolSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\tv_w32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(IVT Corporation.) C:\Program Files\BTH\BlueSoleil.exe
(IVT Corporation.) C:\Program Files\BTH\BlueSoleil VoIP Plugin.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\WINDOWS\MHotkey.exe
(Chicony) C:\WINDOWS\ChiFuncExt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [16126464 2007-03-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LchDrvKey] - C:\WINDOWS\LchDrvKey.exe [36864 2007-03-28] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [] - [X]
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
ShortcutTarget: BlueSoleil.lnk -> C:\Program Files\BTH\gprs.exe (IVT Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://31.133.9.23/activex/AMC.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 89.190.94.59 89.190.64.20
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Honza\Data aplikací\Mozilla\Firefox\Profiles\zag3joi0.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-03-04]
Chrome:
=======
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Honza\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-03]
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Professional.9.0; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [660768 2009-02-15] (ABBYY (BIT Software))
S2 ArcGIS License Manager; C:\Program Files\ArcGIS\License10.0\overwrites\lmgrd.exe [1377104 2010-07-12] (Flexera Software, Inc.)
R2 BlueSoleil Hid Service; C:\Program Files\BTH\BTNtService.exe [166520 2007-12-27] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-03-04] (Oracle Corporation)
R2 Start BT in service; C:\Program Files\BTH\StartSkysolSvc.exe [51816 2007-12-27] ()
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [43008 2006-06-18] (Advanced Micro Devices)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1605056 2012-12-21] (Atheros Communications, Inc.)
R3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [34312 2007-06-24] (IVT Corporation.)
R3 BlueletSCOAudio; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [27656 2007-06-24] (IVT Corporation.)
R3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [38920 2007-06-24] (IVT Corporation.)
R0 BTHidEnum; C:\WINDOWS\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [242240 2013-03-29] (DT Soft Ltd)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-08 20:05 - 2014-03-08 20:05 - 00000000 ____D () C:\FRST
2014-03-08 20:01 - 2014-03-08 20:04 - 00029696 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-08 12:38 - 2014-03-08 12:39 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\Adobe
2014-03-08 12:29 - 2014-03-08 12:29 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-03-08 12:09 - 2014-03-08 12:09 - 00000000 ____D () C:\ATI
2014-03-08 11:38 - 2014-03-08 11:38 - 00000000 ____D () C:\Program Files\ATI
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\ESET
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\ESET
2014-03-04 14:32 - 2014-03-04 14:32 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\library_dir
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Local Settings\Data aplikací\ESET
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Program Files\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-03-04 13:58 - 2014-03-04 13:58 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-03-04 13:57 - 2014-03-04 13:57 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Program Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-02-23 16:27 - 2014-02-25 20:36 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\Skype
2014-02-19 22:36 - 2014-03-08 12:08 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\Skype
2014-02-19 18:06 - 2014-02-19 18:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 17:46 - 2014-02-19 17:46 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2014-02-19 17:44 - 2014-02-19 17:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\IVT BlueSoleil
2014-02-19 17:43 - 2014-02-19 17:43 - 00000000 ____D () C:\Program Files\BTH
2014-02-15 16:01 - 2014-02-15 16:01 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\TeamViewer
2014-02-15 16:00 - 2014-02-15 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamViewer 8
==================== One Month Modified Files and Folders =======
2014-03-08 20:05 - 2014-03-08 20:05 - 00000000 ____D () C:\FRST
2014-03-08 20:04 - 2014-03-08 20:01 - 00029696 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-08 20:04 - 2013-03-29 14:41 - 00000000 ___HD () C:\Documents and Settings\Honza\Local Settings\Data aplikací
2014-03-08 20:01 - 2013-03-29 15:31 - 00000178 ___SH () C:\Documents and Settings\Mamka\ntuser.ini
2014-03-08 20:01 - 2013-03-29 14:01 - 00363916 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-08 19:50 - 2013-03-29 14:55 - 00000211 _____ () C:\WINDOWS\wiadebug.log
2014-03-08 19:50 - 2013-03-29 14:55 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-03-08 12:39 - 2014-03-08 12:38 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\Adobe
2014-03-08 12:39 - 2013-03-29 21:57 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-08 12:39 - 2013-03-29 21:57 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-08 12:38 - 2013-03-29 15:31 - 00000000 ___HD () C:\Documents and Settings\Mamka\Local Settings\Data aplikací
2014-03-08 12:34 - 2013-03-29 21:57 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\Skype
2014-03-08 12:34 - 2013-03-29 14:41 - 00000178 ___SH () C:\Documents and Settings\Honza\ntuser.ini
2014-03-08 12:31 - 2013-03-29 14:41 - 00000000 ____D () C:\Documents and Settings\Honza
2014-03-08 12:29 - 2014-03-08 12:29 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-03-08 12:29 - 2013-03-29 14:07 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-08 12:29 - 2001-10-25 13:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-08 12:28 - 2013-04-17 17:08 - 00000000 ____D () C:\Documents and Settings\Petr
2014-03-08 12:28 - 2013-03-29 15:35 - 00000000 ____D () C:\Documents and Settings\Tatka
2014-03-08 12:28 - 2013-03-29 15:31 - 00000000 ____D () C:\Documents and Settings\Mamka
2014-03-08 12:28 - 2013-03-29 14:07 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-03-08 12:28 - 2013-03-29 14:07 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-03-08 12:28 - 2013-03-29 14:05 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-03-08 12:28 - 2013-03-29 13:58 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-08 12:26 - 2013-03-29 14:25 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-08 12:26 - 2013-03-29 14:07 - 00032544 ____N () C:\WINDOWS\SchedLgU.Txt
2014-03-08 12:25 - 2013-04-13 17:14 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-03-08 12:20 - 2013-03-29 13:59 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-03-08 12:09 - 2014-03-08 12:09 - 00000000 ____D () C:\ATI
2014-03-08 12:08 - 2014-02-19 22:36 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\Skype
2014-03-08 11:46 - 2013-03-29 14:31 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-03-08 11:38 - 2014-03-08 11:38 - 00000000 ____D () C:\Program Files\ATI
2014-03-07 21:46 - 2013-03-29 15:48 - 00131072 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2014-03-06 21:18 - 2013-03-29 15:35 - 00000178 ___SH () C:\Documents and Settings\Tatka\ntuser.ini
2014-03-06 21:09 - 2013-03-30 15:38 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\vlc
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\ESET
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\ESET
2014-03-04 19:43 - 2013-03-29 15:35 - 00074608 _____ () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 19:43 - 2013-03-29 15:35 - 00000000 __RHD () C:\Documents and Settings\Tatka\Data aplikací
2014-03-04 19:43 - 2013-03-29 15:35 - 00000000 ___HD () C:\Documents and Settings\Tatka\Local Settings\Data aplikací
2014-03-04 16:04 - 2013-03-29 15:32 - 00074608 _____ () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\ESET
2014-03-04 16:03 - 2013-03-29 15:31 - 00000000 __RHD () C:\Documents and Settings\Mamka\Data aplikací
2014-03-04 14:58 - 2013-03-29 14:41 - 00000000 __RHD () C:\Documents and Settings\Honza\Data aplikací
2014-03-04 14:58 - 2013-03-29 14:41 - 00000000 ___RD () C:\Documents and Settings\Honza\Nabídka Start\Programy
2014-03-04 14:54 - 2013-03-29 14:42 - 00074608 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 14:53 - 2013-03-29 14:51 - 00254272 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-04 14:32 - 2014-03-04 14:32 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\library_dir
2014-03-04 14:11 - 2013-03-29 16:15 - 00000000 ____D () C:\Program Files\trend micro
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Local Settings\Data aplikací\ESET
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Program Files\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-03-04 14:04 - 2013-03-29 14:52 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-03-04 14:04 - 2013-03-29 14:52 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-03-04 13:58 - 2014-03-04 13:58 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-03-04 13:57 - 2014-03-04 13:57 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Program Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-03-04 13:46 - 2013-04-17 17:08 - 00000000 ___HD () C:\Documents and Settings\Petr\Local Settings\Data aplikací
2014-03-04 13:45 - 2013-04-17 17:08 - 00000000 __RHD () C:\Documents and Settings\Petr\Data aplikací
2014-02-25 20:36 - 2014-02-23 16:27 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\Skype
2014-02-19 19:13 - 2013-03-29 16:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-19 18:06 - 2014-02-19 18:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 17:46 - 2014-02-19 17:46 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2014-02-19 17:44 - 2014-02-19 17:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\IVT BlueSoleil
2014-02-19 17:44 - 2013-03-29 14:52 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2014-02-19 17:43 - 2014-02-19 17:43 - 00000000 ____D () C:\Program Files\BTH
2014-02-15 16:01 - 2014-02-15 16:01 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\TeamViewer
2014-02-15 16:00 - 2014-02-15 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamViewer 8
2014-02-15 16:00 - 2013-03-29 21:53 - 00000815 _____ () C:\Documents and Settings\All Users\Plocha\TeamViewer 8.lnk
2014-02-15 16:00 - 2013-03-29 14:52 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
Some content of TEMP:
====================
C:\Documents and Settings\Mamka\Local Settings\Temp\AtiCimUn.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0108544 ____A (Microsoft Corporation) f0d2ae69035092bf22dad6b50fab85c2
C:\WINDOWS\system32\User32.dll
[2004-08-17 14:49] - [2008-04-14 08:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll
[2004-08-17 14:49] - [2008-04-14 08:51] - 0399360 ____A (Microsoft Corporation) c868f3ae15cf71a93f2aa3a32856d839
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-17 14:44] - [2008-04-14 07:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
poslední dobou nám tu začal zamrzat rodinnej počítač (úplně vytuhne a je potřeba reset), procesor standardně teče na 40% a víc, blbne psaní ve wordu a dneska večer se k tomu přidalo zvláštní chování myši (když chtěla mamka nastavit kurzor, aby smazala slovo, tak se celej word úplně splašil...). Teď, když jsem pustil chroma, tak se ozval, že soubor s nastavením chromu byl poškozený a proto se celý jeho profil vytváří znova...¨
Nešlo mi vytvořit FRSTL, proto dávám jenom FRST. Snažím se učit luštění logů - a soudě podle mě, tak tam není žádnej živej vir... ale přesto prosím o zkušenější očko. Díky.

(PS: soubor C:\WINDOWS\system32\Drivers\volsnap.sys jsem testoval na virustotalu a byl čistý.)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2014 01
Ran by Honza (administrator) on RODINA on 08-03-2014 20:05:07
Running from D:\Honza\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ABBYY (BIT Software)) C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
() C:\Program Files\BTH\BTNtService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(HP) C:\WINDOWS\system32\HPSIsvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
() C:\Program Files\BTH\StartSkysolSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\tv_w32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(IVT Corporation.) C:\Program Files\BTH\BlueSoleil.exe
(IVT Corporation.) C:\Program Files\BTH\BlueSoleil VoIP Plugin.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\WINDOWS\MHotkey.exe
(Chicony) C:\WINDOWS\ChiFuncExt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [16126464 2007-03-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LchDrvKey] - C:\WINDOWS\LchDrvKey.exe [36864 2007-03-28] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [] - [X]
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKU\S-1-5-21-789336058-1284227242-839522115-1003\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
ShortcutTarget: BlueSoleil.lnk -> C:\Program Files\BTH\gprs.exe (IVT Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://31.133.9.23/activex/AMC.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 89.190.94.59 89.190.64.20
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Honza\Data aplikací\Mozilla\Firefox\Profiles\zag3joi0.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-03-04]
Chrome:
=======
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Honza\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-03]
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Professional.9.0; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [660768 2009-02-15] (ABBYY (BIT Software))
S2 ArcGIS License Manager; C:\Program Files\ArcGIS\License10.0\overwrites\lmgrd.exe [1377104 2010-07-12] (Flexera Software, Inc.)
R2 BlueSoleil Hid Service; C:\Program Files\BTH\BTNtService.exe [166520 2007-12-27] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-03-04] (Oracle Corporation)
R2 Start BT in service; C:\Program Files\BTH\StartSkysolSvc.exe [51816 2007-12-27] ()
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [43008 2006-06-18] (Advanced Micro Devices)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1605056 2012-12-21] (Atheros Communications, Inc.)
R3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [34312 2007-06-24] (IVT Corporation.)
R3 BlueletSCOAudio; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [27656 2007-06-24] (IVT Corporation.)
R3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [38920 2007-06-24] (IVT Corporation.)
R0 BTHidEnum; C:\WINDOWS\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [242240 2013-03-29] (DT Soft Ltd)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-08 20:05 - 2014-03-08 20:05 - 00000000 ____D () C:\FRST
2014-03-08 20:01 - 2014-03-08 20:04 - 00029696 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-08 12:38 - 2014-03-08 12:39 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\Adobe
2014-03-08 12:29 - 2014-03-08 12:29 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-03-08 12:09 - 2014-03-08 12:09 - 00000000 ____D () C:\ATI
2014-03-08 11:38 - 2014-03-08 11:38 - 00000000 ____D () C:\Program Files\ATI
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\ESET
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\ESET
2014-03-04 14:32 - 2014-03-04 14:32 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\library_dir
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Local Settings\Data aplikací\ESET
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Program Files\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-03-04 13:58 - 2014-03-04 13:58 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-03-04 13:57 - 2014-03-04 13:57 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Program Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-02-23 16:27 - 2014-02-25 20:36 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\Skype
2014-02-19 22:36 - 2014-03-08 12:08 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\Skype
2014-02-19 18:06 - 2014-02-19 18:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 17:46 - 2014-02-19 17:46 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2014-02-19 17:44 - 2014-02-19 17:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\IVT BlueSoleil
2014-02-19 17:43 - 2014-02-19 17:43 - 00000000 ____D () C:\Program Files\BTH
2014-02-15 16:01 - 2014-02-15 16:01 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\TeamViewer
2014-02-15 16:00 - 2014-02-15 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamViewer 8
==================== One Month Modified Files and Folders =======
2014-03-08 20:05 - 2014-03-08 20:05 - 00000000 ____D () C:\FRST
2014-03-08 20:04 - 2014-03-08 20:01 - 00029696 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\MSGBOX.EXE
2014-03-08 20:04 - 2013-03-29 14:41 - 00000000 ___HD () C:\Documents and Settings\Honza\Local Settings\Data aplikací
2014-03-08 20:01 - 2013-03-29 15:31 - 00000178 ___SH () C:\Documents and Settings\Mamka\ntuser.ini
2014-03-08 20:01 - 2013-03-29 14:01 - 00363916 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-08 19:50 - 2013-03-29 14:55 - 00000211 _____ () C:\WINDOWS\wiadebug.log
2014-03-08 19:50 - 2013-03-29 14:55 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-03-08 12:39 - 2014-03-08 12:38 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\Adobe
2014-03-08 12:39 - 2013-03-29 21:57 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-08 12:39 - 2013-03-29 21:57 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-08 12:38 - 2013-03-29 15:31 - 00000000 ___HD () C:\Documents and Settings\Mamka\Local Settings\Data aplikací
2014-03-08 12:34 - 2013-03-29 21:57 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\Skype
2014-03-08 12:34 - 2013-03-29 14:41 - 00000178 ___SH () C:\Documents and Settings\Honza\ntuser.ini
2014-03-08 12:31 - 2013-03-29 14:41 - 00000000 ____D () C:\Documents and Settings\Honza
2014-03-08 12:29 - 2014-03-08 12:29 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-03-08 12:29 - 2013-03-29 14:07 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-08 12:29 - 2001-10-25 13:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-08 12:28 - 2013-04-17 17:08 - 00000000 ____D () C:\Documents and Settings\Petr
2014-03-08 12:28 - 2013-03-29 15:35 - 00000000 ____D () C:\Documents and Settings\Tatka
2014-03-08 12:28 - 2013-03-29 15:31 - 00000000 ____D () C:\Documents and Settings\Mamka
2014-03-08 12:28 - 2013-03-29 14:07 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-03-08 12:28 - 2013-03-29 14:07 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-03-08 12:28 - 2013-03-29 14:05 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-03-08 12:28 - 2013-03-29 13:58 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-08 12:26 - 2013-03-29 14:25 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-08 12:26 - 2013-03-29 14:07 - 00032544 ____N () C:\WINDOWS\SchedLgU.Txt
2014-03-08 12:25 - 2013-04-13 17:14 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-03-08 12:20 - 2013-03-29 13:59 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-03-08 12:09 - 2014-03-08 12:09 - 00000000 ____D () C:\ATI
2014-03-08 12:08 - 2014-02-19 22:36 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\Skype
2014-03-08 11:46 - 2013-03-29 14:31 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-03-08 11:38 - 2014-03-08 11:38 - 00000000 ____D () C:\Program Files\ATI
2014-03-07 21:46 - 2013-03-29 15:48 - 00131072 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2014-03-06 21:18 - 2013-03-29 15:35 - 00000178 ___SH () C:\Documents and Settings\Tatka\ntuser.ini
2014-03-06 21:09 - 2013-03-30 15:38 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\vlc
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\ESET
2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\ESET
2014-03-04 19:43 - 2013-03-29 15:35 - 00074608 _____ () C:\Documents and Settings\Tatka\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 19:43 - 2013-03-29 15:35 - 00000000 __RHD () C:\Documents and Settings\Tatka\Data aplikací
2014-03-04 19:43 - 2013-03-29 15:35 - 00000000 ___HD () C:\Documents and Settings\Tatka\Local Settings\Data aplikací
2014-03-04 16:04 - 2013-03-29 15:32 - 00074608 _____ () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Local Settings\Data aplikací\ESET
2014-03-04 16:03 - 2014-03-04 16:03 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\ESET
2014-03-04 16:03 - 2013-03-29 15:31 - 00000000 __RHD () C:\Documents and Settings\Mamka\Data aplikací
2014-03-04 14:58 - 2013-03-29 14:41 - 00000000 __RHD () C:\Documents and Settings\Honza\Data aplikací
2014-03-04 14:58 - 2013-03-29 14:41 - 00000000 ___RD () C:\Documents and Settings\Honza\Nabídka Start\Programy
2014-03-04 14:54 - 2013-03-29 14:42 - 00074608 _____ () C:\Documents and Settings\Honza\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-03-04 14:53 - 2013-03-29 14:51 - 00254272 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-04 14:32 - 2014-03-04 14:32 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\library_dir
2014-03-04 14:11 - 2013-03-29 16:15 - 00000000 ____D () C:\Program Files\trend micro
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Local Settings\Data aplikací\ESET
2014-03-04 14:06 - 2014-03-04 14:06 - 00000000 ____D () C:\Documents and Settings\Honza\Data aplikací\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Program Files\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\ESET
2014-03-04 14:04 - 2014-03-04 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\ESET
2014-03-04 14:04 - 2013-03-29 14:52 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-03-04 14:04 - 2013-03-29 14:52 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-03-04 13:58 - 2014-03-04 13:58 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-03-04 13:57 - 2014-03-04 13:57 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-03-04 13:57 - 2014-03-04 13:57 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Program Files\Java
2014-03-04 13:57 - 2014-03-04 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-03-04 13:46 - 2013-04-17 17:08 - 00000000 ___HD () C:\Documents and Settings\Petr\Local Settings\Data aplikací
2014-03-04 13:45 - 2013-04-17 17:08 - 00000000 __RHD () C:\Documents and Settings\Petr\Data aplikací
2014-02-25 20:36 - 2014-02-23 16:27 - 00000000 ____D () C:\Documents and Settings\Tatka\Data aplikací\Skype
2014-02-19 19:13 - 2013-03-29 16:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-19 18:06 - 2014-02-19 18:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 17:46 - 2014-02-19 17:46 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2014-02-19 17:44 - 2014-02-19 17:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\IVT BlueSoleil
2014-02-19 17:44 - 2013-03-29 14:52 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2014-02-19 17:43 - 2014-02-19 17:43 - 00000000 ____D () C:\Program Files\BTH
2014-02-15 16:01 - 2014-02-15 16:01 - 00000000 ____D () C:\Documents and Settings\Mamka\Data aplikací\TeamViewer
2014-02-15 16:00 - 2014-02-15 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamViewer 8
2014-02-15 16:00 - 2013-03-29 21:53 - 00000815 _____ () C:\Documents and Settings\All Users\Plocha\TeamViewer 8.lnk
2014-02-15 16:00 - 2013-03-29 14:52 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
Some content of TEMP:
====================
C:\Documents and Settings\Mamka\Local Settings\Temp\AtiCimUn.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0108544 ____A (Microsoft Corporation) f0d2ae69035092bf22dad6b50fab85c2
C:\WINDOWS\system32\User32.dll
[2004-08-17 14:49] - [2008-04-14 08:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-17 14:49] - [2008-04-14 08:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll
[2004-08-17 14:49] - [2008-04-14 08:51] - 0399360 ____A (Microsoft Corporation) c868f3ae15cf71a93f2aa3a32856d839
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-17 14:44] - [2008-04-14 07:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================