Prosím Vyoska o kontrolu zaneřáděného počítače
Napsal: 18 dub 2014 13:48
Ahoj. Dostal se mi do ruky počítač v dost bídném stavu. Potřeboval bych ho dát do použitelného stavu
přikládám log
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-04-2014 01
Ran by Děda (ATTENTION: The logged in user is not administrator) on HANKA-HP on 18-04-2014 14:43:57
Running from C:\Users\Děda\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Guard-ICQ\GuardICQ.exe
(Apple Inc.) C:\iTunes\iTunesHelper.exe
(SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Messenger\SweetIM.exe
(SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
() C:\Users\Děda\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
() C:\Windows\System32\jmdp\stij.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [NeroFilterCheck] => C:\windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [Guard.Mail.ru.gui] => C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-03-26] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\iTunes\iTunesHelper.exe [421736 2012-03-27] (Apple Inc.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [296056 2012-05-15] (RealNetworks, Inc.)
HKLM\...\Run: [SiteRanker] => C:\Program Files\SiteRanker\SiteRankTray.exe [320000 2012-05-15] (Crawler, LLC)
HKLM\...\Run: [SweetIM] => C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] => C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1061960 2013-03-21] ()
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-05-13] (BlueStack Systems, Inc.)
HKLM\...\Run: [SearchProtection] => C:\ProgramData\Search Protection\_run.bat
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3764024 2013-12-28] (AVAST Software)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Děda\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Děda\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll => c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll File Not Found
Startup: C:\Users\Děda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicyUsers\S-1-5-21-3787819946-3620248423-3096216792-1005\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=1
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
URLSearchHook: HKLM - flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
URLSearchHook: HKCU - (No Name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = http://search.mywebsearch.com/mywebsear ... earchTerms}
SearchScopes: HKCU - DefaultScope {25098803-09df-430e-9c00-a3c6c71725ca} URL = http://search.seznam.cz/?q={searchTerms ... ckSearch_1
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKCU - {25098803-09df-430e-9c00-a3c6c71725ca} URL = http://search.seznam.cz/?q={searchTerms ... ckSearch_1
SearchScopes: HKCU - {4b3d0329-08b8-4b4f-9381-8802ba01cc69} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... ckSearch_1
SearchScopes: HKCU - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = http://search.mywebsearch.com/mywebsear ... earchTerms}
SearchScopes: HKCU - {66FE4E8E-8073-4CE1-8E3C-5861B3601541} URL = http://www.novinky.cz/hledej?w={searchT ... ckSearch_1
SearchScopes: HKCU - {7BDCA69E-0AA3-4D80-BF0A-1A5D94A0FE00} URL = http://encyklopedie.seznam.cz/search?q= ... ckSearch_1
SearchScopes: HKCU - {9AC21ED8-ACBA-4D29-8B01-297637746516} URL = http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_1
SearchScopes: HKCU - {A587A0CD-15D0-4CDC-80C8-5CCB09821773} URL = http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_1
SearchScopes: HKCU - {c367865b-65cb-4f7c-b3cc-0f263d9dd1a1} URL = http://www.mapy.cz/?query={searchTerms} ... ckSearch_1
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/?a=6R95yc ... erms}&i=26
SearchScopes: HKCU - {E0FAE10B-FCDB-4D2E-B699-E0605B3B30F6} URL = http://tv.seznam.cz/hledej?w={searchTer ... ckSearch_1
SearchScopes: HKCU - {f53685d1-cad0-4bac-a9fe-7449bf76e36a} URL = http://www.firmy.cz/?q={searchTerms}&so ... ckSearch_1
BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Hanka\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
BHO: flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
BHO: IMPI - {17E113E6-CD0E-4045-B154-65F0E57959EF} - C:\Program Files\IMPI\Extension32.dll ()
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\Program Files\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - No File
Toolbar: HKCU - No Name - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\searchplugins\MyStart.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Centrum doménový pomocník - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\centrumpomocnik@centrum.cz [2012-01-23]
FF Extension: Lavasoft Search Plugin - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2013-06-25]
FF Extension: Seznam lištička - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-04-09]
FF Extension: Centrum.cz nastavení - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2012-01-23]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-03]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-05-15]
FF HKLM\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files\SiteRanker\firefox\
FF Extension: SiteRanker - C:\Program Files\SiteRanker\firefox\ []
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-05-19]
FF HKLM\...\Firefox\Extensions: [{17E113E6-CD0E-4045-B154-65F0E57959EF}] - C:\Program Files\IMPI\Firefox
FF Extension: IMPI - C:\Program Files\IMPI\Firefox [2013-03-12]
========================== Services (Whitelisted) =================
R2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43072 2012-03-19] (ArcSoft, Inc.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-07-27] (LSI Corporation)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2013-12-28] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-05-13] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-05-13] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 Guard.Mail.ru; C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-03-26] ()
R2 IBUpdaterService; C:\windows\system32\dmwu.exe [1527600 2014-02-04] ()
R2 IMPI Updater; C:\Program Files\IMPI\ExtensionUpdaterService.exe [185856 2013-02-05] ()
R2 lmhosts; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 5U876UVC; C:\windows\System32\DRIVERS\5U876.sys [118656 2009-06-30] (Ricoh co.,Ltd.)
R1 aswKbd; C:\windows\system32\Drivers\aswKbd.sys [21576 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2013-12-28] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [79720 2013-10-21] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2013-10-21] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [775952 2013-12-28] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [410528 2013-12-28] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [64168 2013-12-28] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180248 2013-12-28] ()
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-05-13] (BlueStack Systems)
R1 dtsoftbus01; C:\windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-05-16] (DT Soft Ltd)
S3 MfeAVFK; C:\windows\System32\drivers\MfeAVFK.sys [79816 2009-05-16] (McAfee, Inc.)
S3 MfeBOPK; C:\windows\System32\drivers\MfeBOPK.sys [35272 2009-05-16] (McAfee, Inc.)
R1 mfehidk; C:\windows\System32\drivers\mfehidk.sys [214024 2009-05-16] (McAfee, Inc.)
S3 MfeRKDK; C:\windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
R1 mfetdik; C:\windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S0 sfvfs02; C:\windows\System32\drivers\sfvfs02.sys [63488 2005-11-03] (Protection Technology)
R3 yukonw7; C:\windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S1 SBRE; \??\C:\windows\system32\drivers\SBREdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 14:43 - 2014-04-18 14:44 - 00023470 _____ () C:\Users\Děda\Desktop\FRST.txt
2014-04-18 14:43 - 2014-04-18 14:43 - 00000000 ____D () C:\FRST
2014-04-18 14:42 - 2014-04-18 14:42 - 00112640 _____ (forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
2014-04-18 14:39 - 2014-04-18 14:40 - 01146880 _____ (Farbar) C:\Users\Děda\Desktop\FRST.exe
2014-04-14 19:11 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-14 19:11 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-14 19:11 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-04-14 19:11 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-04-14 19:11 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-14 19:11 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-04-14 19:11 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-14 19:11 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-14 19:11 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-14 19:11 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-14 19:11 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-14 19:11 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-04-14 19:11 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-04-14 19:11 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-04-14 19:11 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-04-14 19:11 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-04-14 19:11 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-14 19:11 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-04-14 19:11 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-14 19:11 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-04-14 19:11 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-14 19:11 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-04-14 19:11 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-14 19:11 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-04-14 19:11 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-14 19:11 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-09 21:48 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 21:48 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 21:48 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 21:48 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 21:48 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 21:48 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-01 13:50 - 2014-04-01 13:50 - 00000000 ____D () C:\Program Files\GUMA228.tmp
2014-03-31 18:00 - 2014-03-31 18:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-19 13:31 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-19 13:30 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-19 13:30 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-19 13:30 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-19 13:30 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
==================== One Month Modified Files and Folders =======
2014-04-18 14:44 - 2014-04-18 14:43 - 00023470 _____ () C:\Users\Děda\Desktop\FRST.txt
2014-04-18 14:44 - 2010-07-31 05:57 - 01596558 _____ () C:\windows\WindowsUpdate.log
2014-04-18 14:43 - 2014-04-18 14:43 - 00000000 ____D () C:\FRST
2014-04-18 14:43 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 14:43 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 14:42 - 2014-04-18 14:42 - 00112640 _____ (forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
2014-04-18 14:40 - 2014-04-18 14:39 - 01146880 _____ (Farbar) C:\Users\Děda\Desktop\FRST.exe
2014-04-18 14:40 - 2013-06-06 11:51 - 00000000 ____D () C:\Users\Děda\AppData\Roaming\Seznam.cz
2014-04-18 14:36 - 2013-05-23 13:05 - 00000938 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 14:35 - 2012-06-13 15:01 - 00000430 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-04-18 14:34 - 2013-05-23 13:05 - 00000934 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 14:34 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-18 14:34 - 2009-07-14 06:39 - 00335479 _____ () C:\windows\setupact.log
2014-04-16 21:21 - 2013-11-05 18:51 - 00000000 ____D () C:\fotoknihyMCL
2014-04-16 21:21 - 2013-06-17 17:25 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004UA.job
2014-04-16 21:12 - 2011-11-28 16:59 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job
2014-04-16 21:12 - 2010-01-20 02:01 - 01584626 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-16 21:03 - 2013-10-07 17:35 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-16 17:21 - 2013-06-17 17:25 - 00000910 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004Core.job
2014-04-16 16:20 - 2012-04-12 06:45 - 00000982 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job
2014-04-15 20:58 - 2011-12-14 17:38 - 00000000 ____D () C:\ProgramData\GameXN
2014-04-15 19:11 - 2011-11-28 16:59 - 00000910 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job
2014-04-15 14:02 - 2012-01-18 07:42 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-15 14:02 - 2010-08-06 12:44 - 00000052 _____ () C:\windows\system32\DOErrors.log
2014-04-15 13:56 - 2012-09-18 14:21 - 00000320 _____ () C:\windows\Tasks\HPCeeScheduleForHanka.job
2014-04-09 22:33 - 2010-01-20 02:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 22:31 - 2013-08-06 14:47 - 00000000 ____D () C:\windows\system32\MRT
2014-04-09 22:26 - 2010-07-31 00:49 - 88028728 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-07 17:13 - 2014-01-10 14:51 - 00002479 _____ () C:\Users\Public\Desktop\Safari.lnk
2014-04-07 16:19 - 2010-07-30 20:14 - 00000000 ___RD () C:\Program Files\Skype
2014-04-03 14:07 - 2013-09-13 13:16 - 00000000 ____D () C:\Program Files\Opera
2014-04-01 13:50 - 2014-04-01 13:50 - 00000000 ____D () C:\Program Files\GUMA228.tmp
2014-04-01 13:39 - 2012-06-28 12:31 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-31 19:00 - 2009-07-14 06:33 - 00483216 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-31 18:58 - 2012-09-04 15:57 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-31 18:00 - 2014-03-31 18:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-31 09:35 - 2010-07-31 00:48 - 00231584 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Users\Děda\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job => ?
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004Core.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004UA.job => ?
Task: C:\windows\Tasks\HPCeeScheduleForHanka.job => ?
Task: C:\windows\Tasks\Norton Security Scan for Hanka.job => ?
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\D�da\Desktop" je 27 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
==================== End Of Log ==============================
přikládám log
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-04-2014 01
Ran by Děda (ATTENTION: The logged in user is not administrator) on HANKA-HP on 18-04-2014 14:43:57
Running from C:\Users\Děda\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Guard-ICQ\GuardICQ.exe
(Apple Inc.) C:\iTunes\iTunesHelper.exe
(SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Messenger\SweetIM.exe
(SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
() C:\Users\Děda\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
() C:\Windows\System32\jmdp\stij.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [NeroFilterCheck] => C:\windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [Guard.Mail.ru.gui] => C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-03-26] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\iTunes\iTunesHelper.exe [421736 2012-03-27] (Apple Inc.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [296056 2012-05-15] (RealNetworks, Inc.)
HKLM\...\Run: [SiteRanker] => C:\Program Files\SiteRanker\SiteRankTray.exe [320000 2012-05-15] (Crawler, LLC)
HKLM\...\Run: [SweetIM] => C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] => C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1061960 2013-03-21] ()
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-05-13] (BlueStack Systems, Inc.)
HKLM\...\Run: [SearchProtection] => C:\ProgramData\Search Protection\_run.bat
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3764024 2013-12-28] (AVAST Software)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Děda\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Děda\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3787819946-3620248423-3096216792-1005\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll => c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll File Not Found
Startup: C:\Users\Děda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicyUsers\S-1-5-21-3787819946-3620248423-3096216792-1005\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=1
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
URLSearchHook: HKLM - flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
URLSearchHook: HKCU - (No Name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = http://search.mywebsearch.com/mywebsear ... earchTerms}
SearchScopes: HKCU - DefaultScope {25098803-09df-430e-9c00-a3c6c71725ca} URL = http://search.seznam.cz/?q={searchTerms ... ckSearch_1
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKCU - {25098803-09df-430e-9c00-a3c6c71725ca} URL = http://search.seznam.cz/?q={searchTerms ... ckSearch_1
SearchScopes: HKCU - {4b3d0329-08b8-4b4f-9381-8802ba01cc69} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... ckSearch_1
SearchScopes: HKCU - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = http://search.mywebsearch.com/mywebsear ... earchTerms}
SearchScopes: HKCU - {66FE4E8E-8073-4CE1-8E3C-5861B3601541} URL = http://www.novinky.cz/hledej?w={searchT ... ckSearch_1
SearchScopes: HKCU - {7BDCA69E-0AA3-4D80-BF0A-1A5D94A0FE00} URL = http://encyklopedie.seznam.cz/search?q= ... ckSearch_1
SearchScopes: HKCU - {9AC21ED8-ACBA-4D29-8B01-297637746516} URL = http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_1
SearchScopes: HKCU - {A587A0CD-15D0-4CDC-80C8-5CCB09821773} URL = http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_1
SearchScopes: HKCU - {c367865b-65cb-4f7c-b3cc-0f263d9dd1a1} URL = http://www.mapy.cz/?query={searchTerms} ... ckSearch_1
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/?a=6R95yc ... erms}&i=26
SearchScopes: HKCU - {E0FAE10B-FCDB-4D2E-B699-E0605B3B30F6} URL = http://tv.seznam.cz/hledej?w={searchTer ... ckSearch_1
SearchScopes: HKCU - {f53685d1-cad0-4bac-a9fe-7449bf76e36a} URL = http://www.firmy.cz/?q={searchTerms}&so ... ckSearch_1
BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Hanka\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
BHO: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
BHO: flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
BHO: IMPI - {17E113E6-CD0E-4045-B154-65F0E57959EF} - C:\Program Files\IMPI\Extension32.dll ()
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\Program Files\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - flvto.com Freecorder Toolbar - {1283e7d0-b598-4b2d-a20f-59a9dde270a8} - C:\Program Files\flvto.com_Freecorder\prxtbflvt.dll (Conduit Ltd.)
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - No File
Toolbar: HKCU - No Name - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\searchplugins\MyStart.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Centrum doménový pomocník - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\centrumpomocnik@centrum.cz [2012-01-23]
FF Extension: Lavasoft Search Plugin - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2013-06-25]
FF Extension: Seznam lištička - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-04-09]
FF Extension: Centrum.cz nastavení - C:\Users\Děda\AppData\Roaming\Mozilla\Firefox\Profiles\bspj4arb.default\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2012-01-23]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-03]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-05-15]
FF HKLM\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files\SiteRanker\firefox\
FF Extension: SiteRanker - C:\Program Files\SiteRanker\firefox\ []
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-05-19]
FF HKLM\...\Firefox\Extensions: [{17E113E6-CD0E-4045-B154-65F0E57959EF}] - C:\Program Files\IMPI\Firefox
FF Extension: IMPI - C:\Program Files\IMPI\Firefox [2013-03-12]
========================== Services (Whitelisted) =================
R2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43072 2012-03-19] (ArcSoft, Inc.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-07-27] (LSI Corporation)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2013-12-28] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-05-13] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-05-13] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 Guard.Mail.ru; C:\Program Files\Guard-ICQ\GuardICQ.exe [1564368 2012-03-26] ()
R2 IBUpdaterService; C:\windows\system32\dmwu.exe [1527600 2014-02-04] ()
R2 IMPI Updater; C:\Program Files\IMPI\ExtensionUpdaterService.exe [185856 2013-02-05] ()
R2 lmhosts; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 5U876UVC; C:\windows\System32\DRIVERS\5U876.sys [118656 2009-06-30] (Ricoh co.,Ltd.)
R1 aswKbd; C:\windows\system32\Drivers\aswKbd.sys [21576 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2013-12-28] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [79720 2013-10-21] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2013-10-21] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [775952 2013-12-28] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [410528 2013-12-28] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [64168 2013-12-28] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180248 2013-12-28] ()
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-05-13] (BlueStack Systems)
R1 dtsoftbus01; C:\windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-05-16] (DT Soft Ltd)
S3 MfeAVFK; C:\windows\System32\drivers\MfeAVFK.sys [79816 2009-05-16] (McAfee, Inc.)
S3 MfeBOPK; C:\windows\System32\drivers\MfeBOPK.sys [35272 2009-05-16] (McAfee, Inc.)
R1 mfehidk; C:\windows\System32\drivers\mfehidk.sys [214024 2009-05-16] (McAfee, Inc.)
S3 MfeRKDK; C:\windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
R1 mfetdik; C:\windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S0 sfvfs02; C:\windows\System32\drivers\sfvfs02.sys [63488 2005-11-03] (Protection Technology)
R3 yukonw7; C:\windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S1 SBRE; \??\C:\windows\system32\drivers\SBREdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 14:43 - 2014-04-18 14:44 - 00023470 _____ () C:\Users\Děda\Desktop\FRST.txt
2014-04-18 14:43 - 2014-04-18 14:43 - 00000000 ____D () C:\FRST
2014-04-18 14:42 - 2014-04-18 14:42 - 00112640 _____ (forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
2014-04-18 14:39 - 2014-04-18 14:40 - 01146880 _____ (Farbar) C:\Users\Děda\Desktop\FRST.exe
2014-04-14 19:11 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-14 19:11 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-14 19:11 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-04-14 19:11 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-04-14 19:11 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-14 19:11 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-04-14 19:11 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-14 19:11 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-14 19:11 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-14 19:11 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-14 19:11 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-14 19:11 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-04-14 19:11 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-04-14 19:11 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-04-14 19:11 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-04-14 19:11 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-04-14 19:11 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-14 19:11 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-04-14 19:11 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-14 19:11 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-04-14 19:11 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-14 19:11 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-04-14 19:11 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-14 19:11 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-04-14 19:11 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-14 19:11 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-09 21:48 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 21:48 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 21:48 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 21:48 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 21:48 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 21:48 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-01 13:50 - 2014-04-01 13:50 - 00000000 ____D () C:\Program Files\GUMA228.tmp
2014-03-31 18:00 - 2014-03-31 18:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-19 13:31 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-19 13:30 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-19 13:30 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-19 13:30 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-19 13:30 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
==================== One Month Modified Files and Folders =======
2014-04-18 14:44 - 2014-04-18 14:43 - 00023470 _____ () C:\Users\Děda\Desktop\FRST.txt
2014-04-18 14:44 - 2010-07-31 05:57 - 01596558 _____ () C:\windows\WindowsUpdate.log
2014-04-18 14:43 - 2014-04-18 14:43 - 00000000 ____D () C:\FRST
2014-04-18 14:43 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 14:43 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 14:42 - 2014-04-18 14:42 - 00112640 _____ (forum.viry.cz) C:\Users\Děda\Desktop\FRSTLauncher.exe
2014-04-18 14:40 - 2014-04-18 14:39 - 01146880 _____ (Farbar) C:\Users\Děda\Desktop\FRST.exe
2014-04-18 14:40 - 2013-06-06 11:51 - 00000000 ____D () C:\Users\Děda\AppData\Roaming\Seznam.cz
2014-04-18 14:36 - 2013-05-23 13:05 - 00000938 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 14:35 - 2012-06-13 15:01 - 00000430 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-04-18 14:34 - 2013-05-23 13:05 - 00000934 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 14:34 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-18 14:34 - 2009-07-14 06:39 - 00335479 _____ () C:\windows\setupact.log
2014-04-16 21:21 - 2013-11-05 18:51 - 00000000 ____D () C:\fotoknihyMCL
2014-04-16 21:21 - 2013-06-17 17:25 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004UA.job
2014-04-16 21:12 - 2011-11-28 16:59 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job
2014-04-16 21:12 - 2010-01-20 02:01 - 01584626 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-16 21:03 - 2013-10-07 17:35 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-16 17:21 - 2013-06-17 17:25 - 00000910 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004Core.job
2014-04-16 16:20 - 2012-04-12 06:45 - 00000982 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job
2014-04-15 20:58 - 2011-12-14 17:38 - 00000000 ____D () C:\ProgramData\GameXN
2014-04-15 19:11 - 2011-11-28 16:59 - 00000910 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job
2014-04-15 14:02 - 2012-01-18 07:42 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-15 14:02 - 2010-08-06 12:44 - 00000052 _____ () C:\windows\system32\DOErrors.log
2014-04-15 13:56 - 2012-09-18 14:21 - 00000320 _____ () C:\windows\Tasks\HPCeeScheduleForHanka.job
2014-04-09 22:33 - 2010-01-20 02:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 22:31 - 2013-08-06 14:47 - 00000000 ____D () C:\windows\system32\MRT
2014-04-09 22:26 - 2010-07-31 00:49 - 88028728 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-07 17:13 - 2014-01-10 14:51 - 00002479 _____ () C:\Users\Public\Desktop\Safari.lnk
2014-04-07 16:19 - 2010-07-30 20:14 - 00000000 ___RD () C:\Program Files\Skype
2014-04-03 14:07 - 2013-09-13 13:16 - 00000000 ____D () C:\Program Files\Opera
2014-04-01 13:50 - 2014-04-01 13:50 - 00000000 ____D () C:\Program Files\GUMA228.tmp
2014-04-01 13:39 - 2012-06-28 12:31 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-31 19:00 - 2009-07-14 06:33 - 00483216 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-31 18:58 - 2012-09-04 15:57 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-31 18:00 - 2014-03-31 18:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-31 09:35 - 2010-07-31 00:48 - 00231584 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Users\Děda\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job => ?
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001Core.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1001UA.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004Core.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3787819946-3620248423-3096216792-1004UA.job => ?
Task: C:\windows\Tasks\HPCeeScheduleForHanka.job => ?
Task: C:\windows\Tasks\Norton Security Scan for Hanka.job => ?
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\D�da\Desktop" je 27 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
==================== End Of Log ==============================