vyskakují banery na netu a černé okno s křížkem
Napsal: 27 bře 2014 18:30
Rsit mi nešel spustit, v průběhu padal. Děkuji za kontrolu
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by User (administrator) on WINDOWS-3EB2EE2 on 27-03-2014 18:28:30
Running from C:\Documents and Settings\User\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
(AVerMedia Technologies, Inc.) C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [20143688 2013-03-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2007-07-23] (AMD)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15677728 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [223008 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2586912 2013-06-21] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-12] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ZoneAlarm] - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-08-12] (Check Point Software Technologies LTD)
HKLM\...\Run: [PPort11reminder] - C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\MountPoints2: {cd9d1f70-7863-11e3-b210-00241d2e3d78} - E:\Launcher.exe
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\MountPoints2: {dde97dbb-1ebb-11e3-b186-00241d2e3d78} - E:\Launcher.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Status Monitor.lnk
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9078065390
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 10.152.40.4 10.152.40.5
FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\327dhnis.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: BringStar - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\327dhnis.default\Extensions\{3de9eb9c-a833-42cb-b66f-841b954aebef}.xpi [2014-03-27]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://seznam.cz/
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-08]
CHR Extension: (Disk Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-08]
CHR Extension: (YouTube) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-08]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-08]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-08]
CHR Extension: (Gmail) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-08]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-03-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-12] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-03-12] (Avira Operations GmbH & Co. KG)
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [348160 2010-04-27] (AVerMedia)
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] ()
R2 AVerUpdateServer; C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [168448 2011-01-06] (AVerMedia TECHNOLOGIES, Inc.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-09-11] (Oracle Corporation)
R2 SnugTV Service; C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe [571904 2011-02-14] (AVerMedia Technologies, Inc.)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-08-23] (Crawler.com)
S2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [2445304 2013-08-12] (Check Point Software Technologies LTD)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [54160 2013-06-18] (Check Point Software Technologies, Ltd.)
S4 Update BringStar; "C:\Program Files\BringStar\updateBringStar.exe" [X]
S4 Util BringStar; "C:\Program Files\BringStar\bin\utilBringStar.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices)
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [96704 2007-08-04] (SlySoft, Inc.)
R3 AVerAF35; C:\WINDOWS\System32\Drivers\AVerAF35.sys [642560 2010-04-02] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-01-08] (Disc Soft Ltd)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [26024 2009-12-17] (Elaborate Bytes AG)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [66688 2009-07-01] (NVIDIA Corporation)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128672 2013-02-25] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2009-07-01] (NVIDIA Corporation)
S3 silabenm; C:\WINDOWS\System32\DRIVERS\silabenm.sys [17920 2009-03-20] (Silicon Laboratories, Inc.)
S3 silabser; C:\WINDOWS\System32\DRIVERS\silabser.sys [62592 2009-03-20] (Silicon Laboratories)
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] ()
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-09-11] (Avira GmbH)
R1 tStLibG; C:\WINDOWS\System32\drivers\tStLibG.sys [55224 2014-03-27] (StdLib)
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [528232 2013-08-12] (Check Point Software Technologies LTD)
S4 IntelIde; No ImagePath
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-27 18:28 - 2014-03-27 18:28 - 00013519 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-03-27 18:27 - 2014-03-27 18:28 - 00000000 ____D () C:\FRST
2014-03-27 18:25 - 2014-03-27 18:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-03-27 18:24 - 2014-03-27 18:24 - 01145856 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-03-27 18:08 - 2014-03-27 18:20 - 00007919 _____ () C:\Documents and Settings\User\Plocha\hijackthis.log
2014-03-27 16:29 - 2014-03-27 16:29 - 00000000 ___RD () C:\Documents and Settings\LocalService\Oblíbené položky
2014-03-27 16:28 - 2014-03-27 16:28 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\tStLibG.sys
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Program Files\MuseTips
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MuseTips
2014-03-24 22:53 - 2014-03-24 23:31 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Power Sound Editor Free
2014-03-24 22:53 - 2014-03-24 22:53 - 00000411 _____ () C:\WINDOWS\wmsetup.log
2014-03-17 15:43 - 2014-03-17 15:48 - 00000000 ____D () C:\Documents and Settings\User\Plocha\mamka foto
2014-03-15 13:09 - 2014-03-15 13:10 - 00000000 ____D () C:\Program Files\eBLVD
2014-03-13 01:13 - 2014-03-13 01:14 - 00131578 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-12 21:04 - 2014-03-13 01:13 - 00127417 _____ () C:\WINDOWS\KB2929961.log
2014-03-12 21:03 - 2014-03-13 01:13 - 00129721 _____ () C:\WINDOWS\KB2930275.log
2014-02-27 20:24 - 2014-02-27 20:24 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-02-26 15:43 - 2014-03-21 10:31 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Biofeedback
2014-02-25 08:14 - 2014-02-25 08:14 - 00090112 _____ () C:\WINDOWS\Minidump\Mini022514-01.dmp
2014-02-25 08:14 - 2014-02-25 08:14 - 00000000 ____D () C:\WINDOWS\Minidump
==================== One Month Modified Files and Folders =======
2014-03-27 18:28 - 2014-03-27 18:28 - 00013519 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-03-27 18:28 - 2014-03-27 18:27 - 00000000 ____D () C:\FRST
2014-03-27 18:28 - 2013-09-11 17:38 - 00000000 ____D () C:\Documents and Settings\User\Plocha
2014-03-27 18:27 - 2013-09-11 17:38 - 00000000 ___HD () C:\Documents and Settings\User\Local Settings\Data aplikací
2014-03-27 18:25 - 2014-03-27 18:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-03-27 18:25 - 2013-09-11 21:23 - 00008072 _____ () C:\WINDOWS\system32\nvAppTimestamps
2014-03-27 18:25 - 2013-09-11 20:11 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Stažené soubory
2014-03-27 18:24 - 2014-03-27 18:24 - 01145856 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-03-27 18:23 - 2013-09-18 10:07 - 00000000 ____D () C:\Program Files\trend micro
2014-03-27 18:20 - 2014-03-27 18:08 - 00007919 _____ () C:\Documents and Settings\User\Plocha\hijackthis.log
2014-03-27 18:16 - 2013-09-11 17:33 - 01690536 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-27 18:15 - 2013-12-08 20:41 - 00000932 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-27 18:15 - 2013-09-11 19:28 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-27 18:15 - 2013-09-11 19:28 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-03-27 18:15 - 2013-09-11 17:36 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-27 18:14 - 2013-09-17 17:32 - 00393216 _____ () C:\WINDOWS\system32\config\AVer Med.evt
2014-03-27 18:14 - 2013-09-17 17:32 - 00131072 _____ () C:\WINDOWS\system32\config\AVer Aut.evt
2014-03-27 18:14 - 2013-09-16 22:09 - 00540214 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1292428093-1563985344-1801674531-1003-0.dat
2014-03-27 18:14 - 2013-09-16 14:41 - 00270702 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2014-03-27 18:14 - 2013-09-11 17:38 - 00000178 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-03-27 18:14 - 2013-09-11 17:36 - 00032518 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-27 18:14 - 2001-10-25 13:00 - 00000684 _____ () C:\WINDOWS\win.ini
2014-03-27 18:13 - 2013-09-17 13:13 - 00000000 ____D () C:\Program Files\utorrent
2014-03-27 18:03 - 2013-12-08 20:41 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-27 18:03 - 2013-09-11 21:26 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-03-27 16:29 - 2014-03-27 16:29 - 00000000 ___RD () C:\Documents and Settings\LocalService\Oblíbené položky
2014-03-27 16:29 - 2013-09-11 17:36 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-03-27 16:28 - 2014-03-27 16:28 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\tStLibG.sys
2014-03-27 15:35 - 2014-02-22 12:18 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\gpsPhotoTagger_Workspace
2014-03-27 10:50 - 2013-09-11 21:36 - 00000000 ____D () C:\WINDOWS\system32\LogFiles
2014-03-25 19:22 - 2001-10-25 13:00 - 00002300 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-24 23:44 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Nabídka Start\Programy
2014-03-24 23:44 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Nabídka Start
2014-03-24 23:31 - 2014-03-24 22:53 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Power Sound Editor Free
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Program Files\MuseTips
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MuseTips
2014-03-24 23:29 - 2013-09-11 19:26 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-03-24 22:53 - 2014-03-24 22:53 - 00000411 _____ () C:\WINDOWS\wmsetup.log
2014-03-24 22:53 - 2013-09-11 17:38 - 00000000 __RHD () C:\Documents and Settings\User\Data aplikací
2014-03-24 22:37 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Dokumenty\Hudba
2014-03-21 17:26 - 2013-12-12 13:01 - 00052459 _____ () C:\WINDOWS\setupapi.log
2014-03-21 15:27 - 2013-09-17 17:42 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\AVerTV
2014-03-21 10:31 - 2014-02-26 15:43 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Biofeedback
2014-03-18 19:02 - 2013-09-13 13:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-03-18 19:00 - 2013-09-13 13:12 - 87350280 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-03-17 15:48 - 2014-03-17 15:43 - 00000000 ____D () C:\Documents and Settings\User\Plocha\mamka foto
2014-03-15 17:36 - 2013-09-11 20:41 - 00000000 __SHD () C:\WINDOWS\CSC
2014-03-15 13:10 - 2014-03-15 13:09 - 00000000 ____D () C:\Program Files\eBLVD
2014-03-13 01:17 - 2013-09-11 20:15 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-13 01:17 - 2013-09-11 19:25 - 00270984 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-13 01:14 - 2014-03-13 01:13 - 00131578 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00092938 _____ () C:\WINDOWS\iis6.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00086562 _____ () C:\WINDOWS\FaxSetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00041384 _____ () C:\WINDOWS\ocgen.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00039494 _____ () C:\WINDOWS\tsoc.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00028397 _____ () C:\WINDOWS\comsetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00026894 _____ () C:\WINDOWS\msmqinst.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00017224 _____ () C:\WINDOWS\ntdtcsetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00015162 _____ () C:\WINDOWS\netfxocm.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00005950 _____ () C:\WINDOWS\MedCtrOC.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00005404 _____ () C:\WINDOWS\ocmsn.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00004354 _____ () C:\WINDOWS\tabletoc.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00004326 _____ () C:\WINDOWS\msgsocm.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-13 01:13 - 2014-03-12 21:04 - 00127417 _____ () C:\WINDOWS\KB2929961.log
2014-03-13 01:13 - 2014-03-12 21:03 - 00129721 _____ () C:\WINDOWS\KB2930275.log
2014-03-13 01:13 - 2013-12-13 19:03 - 00009636 _____ () C:\WINDOWS\updspapi.log
2014-03-13 01:13 - 2013-12-13 19:01 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-03-13 01:13 - 2013-09-13 11:58 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-03-13 01:13 - 2013-09-12 17:16 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-03-13 01:12 - 2013-09-11 20:15 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Silverlight
2014-03-12 20:03 - 2013-09-11 21:26 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-12 20:03 - 2013-09-11 21:26 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-12 16:20 - 2013-09-11 21:25 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Skype
2014-03-12 03:50 - 2013-09-12 21:02 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Mbank
2014-03-11 15:59 - 2013-09-11 22:20 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-03-11 15:58 - 2013-09-11 17:31 - 00000000 ____D () C:\WINDOWS\Registration
2014-02-27 20:24 - 2014-02-27 20:24 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Skype
2014-02-27 20:24 - 2013-09-11 21:24 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-02-27 20:23 - 2013-09-11 19:26 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-02-25 15:36 - 2014-02-23 08:52 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Flight Simulator Files
2014-02-25 08:14 - 2014-02-25 08:14 - 00090112 _____ () C:\WINDOWS\Minidump\Mini022514-01.dmp
2014-02-25 08:14 - 2014-02-25 08:14 - 00000000 ____D () C:\WINDOWS\Minidump
Some content of TEMP:
====================
C:\Documents and Settings\User\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\User\Local Settings\Temp\DTLite4481-0347.exe
C:\Documents and Settings\User\Local Settings\Temp\EBU8D.EXE
C:\Documents and Settings\User\Local Settings\Temp\EBU8E.DLL
C:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2008-04-14 07:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2008-04-14 06:42] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:465.62 GB) (Free:96.74 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive e: (DH2005) (CDROM) (Total:0.59 GB) (Free:0 GB) CDFS
Available physical RAM: 2521.49 MB
Total physical RAM: 3326.48 MB
Percentage of memory in use: 24%
==================== MBR and Partition Table ==================
na System.Windows.Media.MediaContext.Resize(System.Windows.Media.ICompositionTarget)
na System.Windows.Interop.HwndTarget.OnResize()
na System.Windows.Media.MediaContext.Resize(System.Windows.Media.ICompositionTarget)
na System.Windows.Interop.HwndTarget.OnResize()
Disk: 0 (Size: 466 GB) (Disk ID: E815E815)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall Firewall (Disabled) {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\User\Plocha" je 1609 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3
C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"C:\Documents and Settings\User\Data aplikac\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"C:\Documents and Settings\User\Data aplikac\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Documents and Settings\User\Local Settings\Data aplikac\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch
"C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload
C:\Program Files\Samsung\Kies\Kies.exe /preload [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD
"C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate
"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^AVer HID Receiver.lnk
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERHI~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^AVerQuick.lnk
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^SnugTV Quick Start.lnk
C:\WINDOWS\Installer\{198F93FD-9919-4010-8164-06BC2349959C}\NewShortcut1_46FEF19C05F1475DAA14D9007DC15270_2.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^Status Monitor.lnk
C:\PROGRA~1\Brother\Brmfcmon\BrMfcWnd.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"="C:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe:*:Enabled:SnugTV Service"
"C:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"="C:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe:*:Enabled:SnugTV Configuration Wizard"
"C:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"="C:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe:*:Enabled:Spyware Terminator 2012"
"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"="C:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe:*:Enabled:Spyware Terminator 2012"
"C:\\Games\\World_of_Tanks\\WorldOfTanks.exe"="C:\\Games\\World_of_Tanks\\WorldOfTanks.exe:*:Enabled:World of Tanks"
"C:\\Games\\World_of_Tanks\\WOTLauncher.exe"="C:\\Games\\World_of_Tanks\\WOTLauncher.exe:*:Enabled:World of Tanks Launcher"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by User (administrator) on WINDOWS-3EB2EE2 on 27-03-2014 18:28:30
Running from C:\Documents and Settings\User\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
(AVerMedia Technologies, Inc.) C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [20143688 2013-03-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2007-07-23] (AMD)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15677728 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [223008 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2586912 2013-06-21] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-12] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ZoneAlarm] - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-08-12] (Check Point Software Technologies LTD)
HKLM\...\Run: [PPort11reminder] - C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\MountPoints2: {cd9d1f70-7863-11e3-b210-00241d2e3d78} - E:\Launcher.exe
HKU\S-1-5-21-1292428093-1563985344-1801674531-1003\...\MountPoints2: {dde97dbb-1ebb-11e3-b186-00241d2e3d78} - E:\Launcher.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Status Monitor.lnk
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9078065390
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 10.152.40.4 10.152.40.5
FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\327dhnis.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: BringStar - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\327dhnis.default\Extensions\{3de9eb9c-a833-42cb-b66f-841b954aebef}.xpi [2014-03-27]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://seznam.cz/
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-08]
CHR Extension: (Disk Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-08]
CHR Extension: (YouTube) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-08]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-08]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-08]
CHR Extension: (Gmail) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-08]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-03-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-12] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-03-12] (Avira Operations GmbH & Co. KG)
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [348160 2010-04-27] (AVerMedia)
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] ()
R2 AVerUpdateServer; C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [168448 2011-01-06] (AVerMedia TECHNOLOGIES, Inc.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-09-11] (Oracle Corporation)
R2 SnugTV Service; C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe [571904 2011-02-14] (AVerMedia Technologies, Inc.)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-08-23] (Crawler.com)
S2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [2445304 2013-08-12] (Check Point Software Technologies LTD)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [54160 2013-06-18] (Check Point Software Technologies, Ltd.)
S4 Update BringStar; "C:\Program Files\BringStar\updateBringStar.exe" [X]
S4 Util BringStar; "C:\Program Files\BringStar\bin\utilBringStar.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices)
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [96704 2007-08-04] (SlySoft, Inc.)
R3 AVerAF35; C:\WINDOWS\System32\Drivers\AVerAF35.sys [642560 2010-04-02] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-01-08] (Disc Soft Ltd)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [26024 2009-12-17] (Elaborate Bytes AG)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [66688 2009-07-01] (NVIDIA Corporation)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128672 2013-02-25] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2009-07-01] (NVIDIA Corporation)
S3 silabenm; C:\WINDOWS\System32\DRIVERS\silabenm.sys [17920 2009-03-20] (Silicon Laboratories, Inc.)
S3 silabser; C:\WINDOWS\System32\DRIVERS\silabser.sys [62592 2009-03-20] (Silicon Laboratories)
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] ()
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-09-11] (Avira GmbH)
R1 tStLibG; C:\WINDOWS\System32\drivers\tStLibG.sys [55224 2014-03-27] (StdLib)
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [528232 2013-08-12] (Check Point Software Technologies LTD)
S4 IntelIde; No ImagePath
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-27 18:28 - 2014-03-27 18:28 - 00013519 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-03-27 18:27 - 2014-03-27 18:28 - 00000000 ____D () C:\FRST
2014-03-27 18:25 - 2014-03-27 18:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-03-27 18:24 - 2014-03-27 18:24 - 01145856 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-03-27 18:08 - 2014-03-27 18:20 - 00007919 _____ () C:\Documents and Settings\User\Plocha\hijackthis.log
2014-03-27 16:29 - 2014-03-27 16:29 - 00000000 ___RD () C:\Documents and Settings\LocalService\Oblíbené položky
2014-03-27 16:28 - 2014-03-27 16:28 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\tStLibG.sys
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Program Files\MuseTips
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MuseTips
2014-03-24 22:53 - 2014-03-24 23:31 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Power Sound Editor Free
2014-03-24 22:53 - 2014-03-24 22:53 - 00000411 _____ () C:\WINDOWS\wmsetup.log
2014-03-17 15:43 - 2014-03-17 15:48 - 00000000 ____D () C:\Documents and Settings\User\Plocha\mamka foto
2014-03-15 13:09 - 2014-03-15 13:10 - 00000000 ____D () C:\Program Files\eBLVD
2014-03-13 01:13 - 2014-03-13 01:14 - 00131578 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-12 21:04 - 2014-03-13 01:13 - 00127417 _____ () C:\WINDOWS\KB2929961.log
2014-03-12 21:03 - 2014-03-13 01:13 - 00129721 _____ () C:\WINDOWS\KB2930275.log
2014-02-27 20:24 - 2014-02-27 20:24 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-02-26 15:43 - 2014-03-21 10:31 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Biofeedback
2014-02-25 08:14 - 2014-02-25 08:14 - 00090112 _____ () C:\WINDOWS\Minidump\Mini022514-01.dmp
2014-02-25 08:14 - 2014-02-25 08:14 - 00000000 ____D () C:\WINDOWS\Minidump
==================== One Month Modified Files and Folders =======
2014-03-27 18:28 - 2014-03-27 18:28 - 00013519 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-03-27 18:28 - 2014-03-27 18:27 - 00000000 ____D () C:\FRST
2014-03-27 18:28 - 2013-09-11 17:38 - 00000000 ____D () C:\Documents and Settings\User\Plocha
2014-03-27 18:27 - 2013-09-11 17:38 - 00000000 ___HD () C:\Documents and Settings\User\Local Settings\Data aplikací
2014-03-27 18:25 - 2014-03-27 18:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-03-27 18:25 - 2013-09-11 21:23 - 00008072 _____ () C:\WINDOWS\system32\nvAppTimestamps
2014-03-27 18:25 - 2013-09-11 20:11 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Stažené soubory
2014-03-27 18:24 - 2014-03-27 18:24 - 01145856 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-03-27 18:23 - 2013-09-18 10:07 - 00000000 ____D () C:\Program Files\trend micro
2014-03-27 18:20 - 2014-03-27 18:08 - 00007919 _____ () C:\Documents and Settings\User\Plocha\hijackthis.log
2014-03-27 18:16 - 2013-09-11 17:33 - 01690536 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-27 18:15 - 2013-12-08 20:41 - 00000932 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-27 18:15 - 2013-09-11 19:28 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-27 18:15 - 2013-09-11 19:28 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-03-27 18:15 - 2013-09-11 17:36 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-27 18:14 - 2013-09-17 17:32 - 00393216 _____ () C:\WINDOWS\system32\config\AVer Med.evt
2014-03-27 18:14 - 2013-09-17 17:32 - 00131072 _____ () C:\WINDOWS\system32\config\AVer Aut.evt
2014-03-27 18:14 - 2013-09-16 22:09 - 00540214 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1292428093-1563985344-1801674531-1003-0.dat
2014-03-27 18:14 - 2013-09-16 14:41 - 00270702 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2014-03-27 18:14 - 2013-09-11 17:38 - 00000178 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-03-27 18:14 - 2013-09-11 17:36 - 00032518 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-27 18:14 - 2001-10-25 13:00 - 00000684 _____ () C:\WINDOWS\win.ini
2014-03-27 18:13 - 2013-09-17 13:13 - 00000000 ____D () C:\Program Files\utorrent
2014-03-27 18:03 - 2013-12-08 20:41 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-27 18:03 - 2013-09-11 21:26 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-03-27 16:29 - 2014-03-27 16:29 - 00000000 ___RD () C:\Documents and Settings\LocalService\Oblíbené položky
2014-03-27 16:29 - 2013-09-11 17:36 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-03-27 16:28 - 2014-03-27 16:28 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\tStLibG.sys
2014-03-27 15:35 - 2014-02-22 12:18 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\gpsPhotoTagger_Workspace
2014-03-27 10:50 - 2013-09-11 21:36 - 00000000 ____D () C:\WINDOWS\system32\LogFiles
2014-03-25 19:22 - 2001-10-25 13:00 - 00002300 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-24 23:44 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Nabídka Start\Programy
2014-03-24 23:44 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Nabídka Start
2014-03-24 23:31 - 2014-03-24 22:53 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Power Sound Editor Free
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Program Files\MuseTips
2014-03-24 23:29 - 2014-03-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MuseTips
2014-03-24 23:29 - 2013-09-11 19:26 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-03-24 22:53 - 2014-03-24 22:53 - 00000411 _____ () C:\WINDOWS\wmsetup.log
2014-03-24 22:53 - 2013-09-11 17:38 - 00000000 __RHD () C:\Documents and Settings\User\Data aplikací
2014-03-24 22:37 - 2013-09-11 17:38 - 00000000 ___RD () C:\Documents and Settings\User\Dokumenty\Hudba
2014-03-21 17:26 - 2013-12-12 13:01 - 00052459 _____ () C:\WINDOWS\setupapi.log
2014-03-21 15:27 - 2013-09-17 17:42 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\AVerTV
2014-03-21 10:31 - 2014-02-26 15:43 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Biofeedback
2014-03-18 19:02 - 2013-09-13 13:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-03-18 19:00 - 2013-09-13 13:12 - 87350280 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-03-17 15:48 - 2014-03-17 15:43 - 00000000 ____D () C:\Documents and Settings\User\Plocha\mamka foto
2014-03-15 17:36 - 2013-09-11 20:41 - 00000000 __SHD () C:\WINDOWS\CSC
2014-03-15 13:10 - 2014-03-15 13:09 - 00000000 ____D () C:\Program Files\eBLVD
2014-03-13 01:17 - 2013-09-11 20:15 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-13 01:17 - 2013-09-11 19:25 - 00270984 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-13 01:14 - 2014-03-13 01:13 - 00131578 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00092938 _____ () C:\WINDOWS\iis6.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00086562 _____ () C:\WINDOWS\FaxSetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00041384 _____ () C:\WINDOWS\ocgen.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00039494 _____ () C:\WINDOWS\tsoc.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00028397 _____ () C:\WINDOWS\comsetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00026894 _____ () C:\WINDOWS\msmqinst.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00017224 _____ () C:\WINDOWS\ntdtcsetup.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00015162 _____ () C:\WINDOWS\netfxocm.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00005950 _____ () C:\WINDOWS\MedCtrOC.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00005404 _____ () C:\WINDOWS\ocmsn.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00004354 _____ () C:\WINDOWS\tabletoc.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00004326 _____ () C:\WINDOWS\msgsocm.log
2014-03-13 01:14 - 2013-12-13 19:01 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-13 01:13 - 2014-03-13 01:13 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-13 01:13 - 2014-03-12 21:04 - 00127417 _____ () C:\WINDOWS\KB2929961.log
2014-03-13 01:13 - 2014-03-12 21:03 - 00129721 _____ () C:\WINDOWS\KB2930275.log
2014-03-13 01:13 - 2013-12-13 19:03 - 00009636 _____ () C:\WINDOWS\updspapi.log
2014-03-13 01:13 - 2013-12-13 19:01 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-03-13 01:13 - 2013-09-13 11:58 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-03-13 01:13 - 2013-09-12 17:16 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-03-13 01:12 - 2013-09-11 20:15 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Silverlight
2014-03-12 20:03 - 2013-09-11 21:26 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-12 20:03 - 2013-09-11 21:26 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-12 16:20 - 2013-09-11 21:25 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\Skype
2014-03-12 03:50 - 2013-09-12 21:02 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Mbank
2014-03-11 15:59 - 2013-09-11 22:20 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-03-11 15:58 - 2013-09-11 17:31 - 00000000 ____D () C:\WINDOWS\Registration
2014-02-27 20:24 - 2014-02-27 20:24 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Skype
2014-02-27 20:24 - 2013-09-11 21:24 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 20:23 - 2014-02-27 20:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-02-27 20:23 - 2013-09-11 19:26 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-02-25 15:36 - 2014-02-23 08:52 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Flight Simulator Files
2014-02-25 08:14 - 2014-02-25 08:14 - 00090112 _____ () C:\WINDOWS\Minidump\Mini022514-01.dmp
2014-02-25 08:14 - 2014-02-25 08:14 - 00000000 ____D () C:\WINDOWS\Minidump
Some content of TEMP:
====================
C:\Documents and Settings\User\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\User\Local Settings\Temp\DTLite4481-0347.exe
C:\Documents and Settings\User\Local Settings\Temp\EBU8D.EXE
C:\Documents and Settings\User\Local Settings\Temp\EBU8E.DLL
C:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2008-04-14 07:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2008-04-14 06:42] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:465.62 GB) (Free:96.74 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive e: (DH2005) (CDROM) (Total:0.59 GB) (Free:0 GB) CDFS
Available physical RAM: 2521.49 MB
Total physical RAM: 3326.48 MB
Percentage of memory in use: 24%
==================== MBR and Partition Table ==================
na System.Windows.Media.MediaContext.Resize(System.Windows.Media.ICompositionTarget)
na System.Windows.Interop.HwndTarget.OnResize()
na System.Windows.Media.MediaContext.Resize(System.Windows.Media.ICompositionTarget)
na System.Windows.Interop.HwndTarget.OnResize()
Disk: 0 (Size: 466 GB) (Disk ID: E815E815)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall Firewall (Disabled) {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\User\Plocha" je 1609 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3
C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"C:\Documents and Settings\User\Data aplikac\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"C:\Documents and Settings\User\Data aplikac\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Documents and Settings\User\Local Settings\Data aplikac\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch
"C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload
C:\Program Files\Samsung\Kies\Kies.exe /preload [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD
"C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate
"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^AVer HID Receiver.lnk
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERHI~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^AVerQuick.lnk
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^SnugTV Quick Start.lnk
C:\WINDOWS\Installer\{198F93FD-9919-4010-8164-06BC2349959C}\NewShortcut1_46FEF19C05F1475DAA14D9007DC15270_2.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabdka Start^Programy^Po sputn^Status Monitor.lnk
C:\PROGRA~1\Brother\Brmfcmon\BrMfcWnd.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"="C:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe:*:Enabled:SnugTV Service"
"C:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"="C:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe:*:Enabled:SnugTV Configuration Wizard"
"C:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"="C:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe:*:Enabled:Spyware Terminator 2012"
"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"="C:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe:*:Enabled:Spyware Terminator 2012"
"C:\\Games\\World_of_Tanks\\WorldOfTanks.exe"="C:\\Games\\World_of_Tanks\\WorldOfTanks.exe:*:Enabled:World of Tanks"
"C:\\Games\\World_of_Tanks\\WOTLauncher.exe"="C:\\Games\\World_of_Tanks\\WOTLauncher.exe:*:Enabled:World of Tanks Launcher"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================