Prosímo kontrolu logu.
Napsal: 08 kvě 2014 17:00
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-05-2014
Ran by Lucka (administrator) on DOMA on 08-05-2014 17:52:01
Running from C:\Documents and Settings\Lucka\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(BitTorrent Inc.) C:\Documents and Settings\Lucka\Data aplikací\uTorrent\uTorrent.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
() C:\WINDOWS\system32\UAService7.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\PanProcess.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2003-06-27] (Agere Systems)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [UserFaultCheck] => %systemroot%\system32\dumprep 0 -u
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [uTorrent] => C:\Documents and Settings\Lucka\Data aplikací\uTorrent\uTorrent.exe [1270352 2014-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3477312 2012-01-19] (DT Soft Ltd)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20924576 2014-02-10] (Skype Technologies S.A.)
Startup: C:\Documents and Settings\Lucka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
ShortcutTarget: Xfire.lnk -> D:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dalesearch.com/?babsrc=HP_ss ... 0&tsp=5025
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTer ... 0&tsp=5025
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTer ... 0&tsp=5025
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default
FF user.js: detected! => C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\user.js
FF NewTab: hxxp://www.dalesearch.com/?babsrc=NT_ss&mntrId ... 0&tsp=5025
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WebSite Recommendation - C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\Extensions\WebSiteRecommendation@weliketheweb.com [2014-03-21]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-29]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-29]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-17]
CHR Extension: (Disk Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-17]
CHR Extension: (YouTube) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-17]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-17]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-19]
CHR Extension: (Skype Click to Call) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-11-17]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-17]
CHR Extension: (Gmail) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-17]
CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\DOCUME~1\Lucka\LOCALS~1\Temp\ccex.crx [2013-11-17]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14]
CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search\ChromeExt\13.2.0.5\avg.crx [2013-05-14]
========================== Services (Whitelisted) =================
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2549248 2008-07-17] (Aladdin Knowledge Systems Ltd.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [170408 2013-01-12] (Oracle Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [167936 2006-06-16] ()
R2 UserAccess7; C:\WINDOWS\system32\UAService7.exe [126976 2013-06-19] ()
==================== Drivers (Whitelisted) ====================
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [350720 2008-03-27] (Aladdin Knowledge Systems Ltd.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [26984 2012-11-08] (AVG Technologies)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [242240 2012-02-03] (DT Soft Ltd)
R3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [170392 2006-10-24] (Intel Corporation)
R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [693760 2006-11-22] (Aladdin Knowledge Systems Ltd.)
R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2012-08-31] (Aladdin Knowledge Systems)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 w70n51; C:\WINDOWS\System32\DRIVERS\w70n51.sys [674560 2006-07-13] (Intel® Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-08 17:52 - 2014-05-08 17:52 - 00011913 _____ () C:\Documents and Settings\Lucka\Plocha\FRST.txt
2014-05-08 17:50 - 2014-05-08 17:52 - 00000000 ____D () C:\FRST
2014-05-08 17:49 - 2014-05-08 17:49 - 01053184 _____ (Farbar) C:\Documents and Settings\Lucka\Plocha\FRST.exe
2014-05-04 21:18 - 2014-05-04 21:18 - 00005504 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-04-29 13:34 - 2014-05-01 11:34 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-04-23 21:24 - 2014-04-23 21:27 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Tisk prosim prosim
2014-04-09 21:40 - 2014-04-09 21:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-09 21:34 - 2014-04-09 21:35 - 00011471 _____ () C:\WINDOWS\KB2936068-IE8.log
2014-04-09 13:08 - 2014-04-09 21:40 - 00013804 _____ () C:\WINDOWS\KB2922229.log
2014-04-08 12:01 - 2013-10-04 14:16 - 00072960 _____ (SimilarSites) C:\Documents and Settings\Lucka\Plocha\Kopie - SimilarBundleGenericDl.exe
2014-04-08 12:01 - 2012-07-13 10:41 - 00000706 _____ () C:\Documents and Settings\Lucka\Plocha\Kopie - TapinRadio.lnk
2014-04-08 12:01 - 2012-05-26 16:37 - 155059785 _____ (HTC Corporation ) C:\Documents and Settings\Lucka\Plocha\Kopie - setup_3.0.5551.exe
==================== One Month Modified Files and Folders =======
2014-05-08 17:52 - 2014-05-08 17:52 - 00011913 _____ () C:\Documents and Settings\Lucka\Plocha\FRST.txt
2014-05-08 17:52 - 2014-05-08 17:50 - 00000000 ____D () C:\FRST
2014-05-08 17:52 - 2012-01-23 19:41 - 00000000 ____D () C:\Documents and Settings\Lucka\Data aplikací\uTorrent
2014-05-08 17:52 - 2012-01-23 11:17 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha
2014-05-08 17:49 - 2014-05-08 17:49 - 01053184 _____ (Farbar) C:\Documents and Settings\Lucka\Plocha\FRST.exe
2014-05-08 17:48 - 2012-01-23 19:48 - 00000116 _____ () C:\WINDOWS\NeroDigital.ini
2014-05-08 17:34 - 2012-12-25 23:33 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-08 17:32 - 2012-01-23 11:05 - 01528820 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-08 17:31 - 2014-03-10 09:40 - 00000222 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-05-08 17:31 - 2013-07-31 12:39 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-05-08 17:31 - 2013-07-31 12:39 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-05-08 17:31 - 2012-01-30 12:31 - 00000000 ____D () C:\Documents and Settings\Lucka\Data aplikací\Skype
2014-05-08 17:31 - 2012-01-23 11:17 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-08 17:31 - 2004-08-18 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-05-08 17:30 - 2012-01-23 11:17 - 00032350 _____ () C:\WINDOWS\SchedLgU.Txt
2014-05-08 17:30 - 2012-01-23 11:17 - 00000178 ___SH () C:\Documents and Settings\Lucka\ntuser.ini
2014-05-08 17:26 - 2014-03-10 09:40 - 00000216 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-05-08 17:26 - 2012-03-15 18:36 - 00003264 _____ () C:\WINDOWS\wincmd.ini
2014-05-05 14:36 - 2012-02-03 10:47 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Fotky
2014-05-05 14:07 - 2013-09-30 14:09 - 00024064 _____ () C:\Documents and Settings\Lucka\Plocha\Docházka Lucka.xls
2014-05-04 21:18 - 2014-05-04 21:18 - 00005504 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-05-04 21:18 - 2014-02-12 14:42 - 00009284 _____ () C:\WINDOWS\updspapi.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00073212 _____ () C:\WINDOWS\iis6.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00068011 _____ () C:\WINDOWS\FaxSetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00032516 _____ () C:\WINDOWS\ocgen.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00031020 _____ () C:\WINDOWS\tsoc.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00022592 _____ () C:\WINDOWS\comsetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00021200 _____ () C:\WINDOWS\msmqinst.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00013699 _____ () C:\WINDOWS\ntdtcsetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00011913 _____ () C:\WINDOWS\netfxocm.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00004675 _____ () C:\WINDOWS\MedCtrOC.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00004246 _____ () C:\WINDOWS\ocmsn.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00003421 _____ () C:\WINDOWS\tabletoc.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00003399 _____ () C:\WINDOWS\msgsocm.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00001355 _____ () C:\WINDOWS\imsins.log
2014-05-01 11:34 - 2014-04-29 13:34 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-05-01 11:34 - 2012-04-15 18:30 - 00692400 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-05-01 11:34 - 2012-01-23 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-04-30 10:12 - 2011-11-03 17:50 - 06022144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-04-30 10:12 - 2004-08-18 14:00 - 06022144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-24 07:20 - 2012-01-23 12:31 - 00000000 ____D () C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Adobe
2014-04-24 07:19 - 2012-01-24 23:50 - 00000000 ____D () C:\Documents and Settings\Lucka\Dokumenty\Stažené soubory
2014-04-24 07:19 - 2012-01-23 19:48 - 00166400 _____ () C:\Documents and Settings\Lucka\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-23 21:27 - 2014-04-23 21:24 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Tisk prosim prosim
2014-04-14 23:14 - 2012-01-23 13:36 - 00002563 _____ () C:\Documents and Settings\Lucka\Plocha\Microsoft Office Word 2007.lnk
2014-04-13 17:28 - 2012-01-23 11:17 - 00000000 ___RD () C:\Documents and Settings\Lucka\Dokumenty\Obrázky
2014-04-12 23:24 - 2012-01-23 11:50 - 01030536 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-09 21:41 - 2012-01-23 13:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-04-09 21:40 - 2014-04-09 21:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-09 21:40 - 2014-04-09 13:08 - 00013804 _____ () C:\WINDOWS\KB2922229.log
2014-04-09 21:40 - 2014-01-16 00:44 - 00001355 _____ () C:\WINDOWS\imsins.BAK
2014-04-09 21:39 - 2013-08-16 03:04 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-09 21:36 - 2012-02-03 07:05 - 88028728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-09 21:35 - 2014-04-09 21:34 - 00011471 _____ () C:\WINDOWS\KB2936068-IE8.log
Files to move or delete:
====================
C:\Documents and Settings\All Users\Data aplikací\MagicPlayDVD.ini
Some content of TEMP:
====================
C:\Documents and Settings\Lucka\Local Settings\Temp\comver.dll
C:\Documents and Settings\Lucka\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\Lucka\Local Settings\Temp\utt3.tmp.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-18 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2004-08-18 14:00] - [2008-04-14 09:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-18 14:00] - [2008-04-14 08:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
Ran by Lucka (administrator) on DOMA on 08-05-2014 17:52:01
Running from C:\Documents and Settings\Lucka\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(BitTorrent Inc.) C:\Documents and Settings\Lucka\Data aplikací\uTorrent\uTorrent.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
() C:\WINDOWS\system32\UAService7.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\PanProcess.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2003-06-27] (Agere Systems)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [UserFaultCheck] => %systemroot%\system32\dumprep 0 -u
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [uTorrent] => C:\Documents and Settings\Lucka\Data aplikací\uTorrent\uTorrent.exe [1270352 2014-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3477312 2012-01-19] (DT Soft Ltd)
HKU\S-1-5-21-2052111302-1060284298-839522115-1003\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20924576 2014-02-10] (Skype Technologies S.A.)
Startup: C:\Documents and Settings\Lucka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
ShortcutTarget: Xfire.lnk -> D:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dalesearch.com/?babsrc=HP_ss ... 0&tsp=5025
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTer ... 0&tsp=5025
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTer ... 0&tsp=5025
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default
FF user.js: detected! => C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\user.js
FF NewTab: hxxp://www.dalesearch.com/?babsrc=NT_ss&mntrId ... 0&tsp=5025
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WebSite Recommendation - C:\Documents and Settings\Lucka\Data aplikací\Mozilla\Firefox\Profiles\ja0o3l5a.default\Extensions\WebSiteRecommendation@weliketheweb.com [2014-03-21]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-29]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-29]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-17]
CHR Extension: (Disk Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-17]
CHR Extension: (YouTube) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-17]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-17]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-19]
CHR Extension: (Skype Click to Call) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-11-17]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-17]
CHR Extension: (Gmail) - C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-17]
CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\DOCUME~1\Lucka\LOCALS~1\Temp\ccex.crx [2013-11-17]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14]
CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search\ChromeExt\13.2.0.5\avg.crx [2013-05-14]
========================== Services (Whitelisted) =================
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2549248 2008-07-17] (Aladdin Knowledge Systems Ltd.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [170408 2013-01-12] (Oracle Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [167936 2006-06-16] ()
R2 UserAccess7; C:\WINDOWS\system32\UAService7.exe [126976 2013-06-19] ()
==================== Drivers (Whitelisted) ====================
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [350720 2008-03-27] (Aladdin Knowledge Systems Ltd.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [26984 2012-11-08] (AVG Technologies)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [242240 2012-02-03] (DT Soft Ltd)
R3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [170392 2006-10-24] (Intel Corporation)
R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [693760 2006-11-22] (Aladdin Knowledge Systems Ltd.)
R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2012-08-31] (Aladdin Knowledge Systems)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 w70n51; C:\WINDOWS\System32\DRIVERS\w70n51.sys [674560 2006-07-13] (Intel® Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-08 17:52 - 2014-05-08 17:52 - 00011913 _____ () C:\Documents and Settings\Lucka\Plocha\FRST.txt
2014-05-08 17:50 - 2014-05-08 17:52 - 00000000 ____D () C:\FRST
2014-05-08 17:49 - 2014-05-08 17:49 - 01053184 _____ (Farbar) C:\Documents and Settings\Lucka\Plocha\FRST.exe
2014-05-04 21:18 - 2014-05-04 21:18 - 00005504 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-04-29 13:34 - 2014-05-01 11:34 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-04-23 21:24 - 2014-04-23 21:27 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Tisk prosim prosim
2014-04-09 21:40 - 2014-04-09 21:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-09 21:34 - 2014-04-09 21:35 - 00011471 _____ () C:\WINDOWS\KB2936068-IE8.log
2014-04-09 13:08 - 2014-04-09 21:40 - 00013804 _____ () C:\WINDOWS\KB2922229.log
2014-04-08 12:01 - 2013-10-04 14:16 - 00072960 _____ (SimilarSites) C:\Documents and Settings\Lucka\Plocha\Kopie - SimilarBundleGenericDl.exe
2014-04-08 12:01 - 2012-07-13 10:41 - 00000706 _____ () C:\Documents and Settings\Lucka\Plocha\Kopie - TapinRadio.lnk
2014-04-08 12:01 - 2012-05-26 16:37 - 155059785 _____ (HTC Corporation ) C:\Documents and Settings\Lucka\Plocha\Kopie - setup_3.0.5551.exe
==================== One Month Modified Files and Folders =======
2014-05-08 17:52 - 2014-05-08 17:52 - 00011913 _____ () C:\Documents and Settings\Lucka\Plocha\FRST.txt
2014-05-08 17:52 - 2014-05-08 17:50 - 00000000 ____D () C:\FRST
2014-05-08 17:52 - 2012-01-23 19:41 - 00000000 ____D () C:\Documents and Settings\Lucka\Data aplikací\uTorrent
2014-05-08 17:52 - 2012-01-23 11:17 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha
2014-05-08 17:49 - 2014-05-08 17:49 - 01053184 _____ (Farbar) C:\Documents and Settings\Lucka\Plocha\FRST.exe
2014-05-08 17:48 - 2012-01-23 19:48 - 00000116 _____ () C:\WINDOWS\NeroDigital.ini
2014-05-08 17:34 - 2012-12-25 23:33 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-08 17:32 - 2012-01-23 11:05 - 01528820 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-08 17:31 - 2014-03-10 09:40 - 00000222 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-05-08 17:31 - 2013-07-31 12:39 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-05-08 17:31 - 2013-07-31 12:39 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-05-08 17:31 - 2012-01-30 12:31 - 00000000 ____D () C:\Documents and Settings\Lucka\Data aplikací\Skype
2014-05-08 17:31 - 2012-01-23 11:17 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-08 17:31 - 2004-08-18 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-05-08 17:30 - 2012-01-23 11:17 - 00032350 _____ () C:\WINDOWS\SchedLgU.Txt
2014-05-08 17:30 - 2012-01-23 11:17 - 00000178 ___SH () C:\Documents and Settings\Lucka\ntuser.ini
2014-05-08 17:26 - 2014-03-10 09:40 - 00000216 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-05-08 17:26 - 2012-03-15 18:36 - 00003264 _____ () C:\WINDOWS\wincmd.ini
2014-05-05 14:36 - 2012-02-03 10:47 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Fotky
2014-05-05 14:07 - 2013-09-30 14:09 - 00024064 _____ () C:\Documents and Settings\Lucka\Plocha\Docházka Lucka.xls
2014-05-04 21:18 - 2014-05-04 21:18 - 00005504 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-05-04 21:18 - 2014-02-12 14:42 - 00009284 _____ () C:\WINDOWS\updspapi.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00073212 _____ () C:\WINDOWS\iis6.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00068011 _____ () C:\WINDOWS\FaxSetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00032516 _____ () C:\WINDOWS\ocgen.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00031020 _____ () C:\WINDOWS\tsoc.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00022592 _____ () C:\WINDOWS\comsetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00021200 _____ () C:\WINDOWS\msmqinst.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00013699 _____ () C:\WINDOWS\ntdtcsetup.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00011913 _____ () C:\WINDOWS\netfxocm.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00004675 _____ () C:\WINDOWS\MedCtrOC.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00004246 _____ () C:\WINDOWS\ocmsn.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00003421 _____ () C:\WINDOWS\tabletoc.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00003399 _____ () C:\WINDOWS\msgsocm.log
2014-05-04 21:18 - 2014-01-16 00:44 - 00001355 _____ () C:\WINDOWS\imsins.log
2014-05-01 11:34 - 2014-04-29 13:34 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-05-01 11:34 - 2012-04-15 18:30 - 00692400 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-05-01 11:34 - 2012-01-23 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-04-30 10:12 - 2011-11-03 17:50 - 06022144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-04-30 10:12 - 2004-08-18 14:00 - 06022144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-24 07:20 - 2012-01-23 12:31 - 00000000 ____D () C:\Documents and Settings\Lucka\Local Settings\Data aplikací\Adobe
2014-04-24 07:19 - 2012-01-24 23:50 - 00000000 ____D () C:\Documents and Settings\Lucka\Dokumenty\Stažené soubory
2014-04-24 07:19 - 2012-01-23 19:48 - 00166400 _____ () C:\Documents and Settings\Lucka\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-23 21:27 - 2014-04-23 21:24 - 00000000 ____D () C:\Documents and Settings\Lucka\Plocha\Tisk prosim prosim
2014-04-14 23:14 - 2012-01-23 13:36 - 00002563 _____ () C:\Documents and Settings\Lucka\Plocha\Microsoft Office Word 2007.lnk
2014-04-13 17:28 - 2012-01-23 11:17 - 00000000 ___RD () C:\Documents and Settings\Lucka\Dokumenty\Obrázky
2014-04-12 23:24 - 2012-01-23 11:50 - 01030536 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-09 21:41 - 2012-01-23 13:04 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-04-09 21:40 - 2014-04-09 21:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-09 21:40 - 2014-04-09 13:08 - 00013804 _____ () C:\WINDOWS\KB2922229.log
2014-04-09 21:40 - 2014-01-16 00:44 - 00001355 _____ () C:\WINDOWS\imsins.BAK
2014-04-09 21:39 - 2013-08-16 03:04 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-09 21:36 - 2012-02-03 07:05 - 88028728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-09 21:35 - 2014-04-09 21:34 - 00011471 _____ () C:\WINDOWS\KB2936068-IE8.log
Files to move or delete:
====================
C:\Documents and Settings\All Users\Data aplikací\MagicPlayDVD.ini
Some content of TEMP:
====================
C:\Documents and Settings\Lucka\Local Settings\Temp\comver.dll
C:\Documents and Settings\Lucka\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\Lucka\Local Settings\Temp\utt3.tmp.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\WINDOWS\system32\winlogon.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\WINDOWS\system32\svchost.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\WINDOWS\system32\services.exe
[2004-08-18 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\WINDOWS\system32\User32.dll
[2004-08-18 14:00] - [2008-04-14 09:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\WINDOWS\system32\userinit.exe
[2004-08-18 14:00] - [2008-04-14 09:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2004-08-18 14:00] - [2008-04-14 08:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================