prosím o kontrolu logu - smazány některé programy
Napsal: 05 čer 2014 21:06
Dobrý večer,
prosím o pomoc a kontrolu logu. Můj PC něco provedl a smazaly se některé součásti programů, zbyl jen zástupce na ploše no ve startu. Např avast - zůstala složka ale exe aplikace nikde. Chtěl jsem ho nainstalovat znova a nejde to. Podobný problém tu měl včera kolega.
Předem uvádím, že můj operační systém by měl být legální (byl součástí kupovaného PC v obchodě, i když už to je hodně pátků nazpátek ...)
Přikládám log
Děkuji za pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014
Ran by Comfor (administrator) on TRAXLER on 05-06-2014 21:26:20
Running from C:\Users\Comfor\Desktop
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\vVX3000.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_13_0_0_214_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4317184 2006-12-29] (Realtek Semiconductor)
HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun
HKLM\...\Run: [LifeCam] => "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe [707360 2006-12-06] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\...\Run: [AvastUI.exe] => "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {b5494747-6c57-11dc-bffc-00004d2d893c} - G:\TrueCrypt\TrueCrypt.exe /q background /e /c y /m ro /m rm /v "Secret\Corsair.tc"
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {eae167b4-025d-11de-a65e-001a4d2a5c6f} - G:\WDSetup.exe
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {f352cb0f-0345-11e2-8df7-001a4d2a5c6f} - F:\unlock.exe autoplay=true
Startup: C:\Users\Comfor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (No File)
==================== Internet (Whitelisted) ====================
ProxyServer: 10.1.1.30:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/search?q={searchT ... d=ie7&rlz=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
SearchScopes: HKLM - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - DefaultScope {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {104EE3F6-6FB5-478D-9388-A3341FD5CF21} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {23AE915A-9767-420D-8D86-8985BEA15275} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
BHO: No Name - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll No File
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Toolbar: HKCU - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} http://kitchenplanner.ikea.com/CZ/Core/ ... _Win32.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 213.192.60.6 213.192.60.5
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.3088 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll No File
FF Plugin: @real.com/nprpjplug;version=6.0.11.3006 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: www.google.com
CHR StartupUrls: "www.google.com"
CHR Extension: (YouTube) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-27]
CHR Extension: (Google Search) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-29]
CHR Extension: (Skype Click to Call) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-12-14]
CHR Extension: (Google Wallet) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-14]
CHR Extension: (Gmail) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-29]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-02-29]
========================== Services (Whitelisted) =================
S3 Adobe LM Service; "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [X]
S2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [X]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [X]
S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
S2 nvUpdatusService; "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" [X]
S2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [1121536 2006-11-22] (Philips Semiconductors GmbH)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-05-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-05-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-05-15] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-05-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [777488 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411680 2014-05-15] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-05-01] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-05-01] ()
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2007-08-27] (Padus, Inc.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [685816 2007-10-27] ()
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 anothkoj; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-05 21:26 - 2014-06-05 21:27 - 00011522 _____ () C:\Users\Comfor\Desktop\FRST.txt
2014-06-05 21:25 - 2014-06-05 21:26 - 00000000 ____D () C:\FRST
2014-06-05 21:23 - 2014-06-05 21:23 - 00112640 _____ (forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
2014-06-05 21:22 - 2014-06-05 21:22 - 01059840 _____ (Farbar) C:\Users\Comfor\Desktop\FRST.exe
2014-06-03 19:59 - 2014-06-03 19:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-06-03 19:55 - 2014-06-03 20:23 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-05-29 15:50 - 2014-05-29 15:51 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-29 15:50 - 2012-10-30 23:50 - 00227648 _____ (AVAST Software) C:\Windows\system32\asw77DD.tmp
2014-05-29 14:21 - 2014-05-29 14:21 - 04796856 _____ (AVAST Software) C:\Users\Comfor\Downloads\avast_free_antivirus_setup_online.exe
2014-05-29 07:09 - 2014-05-29 07:09 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Adobe
2014-05-29 06:51 - 2014-05-29 07:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-29 06:51 - 2014-05-29 06:51 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-27 15:44 - 2014-05-27 15:44 - 00000000 ____D () C:\Program Files\MSBuild
2014-05-15 23:26 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 23:26 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 23:26 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 09:10 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
==================== One Month Modified Files and Folders =======
2014-06-05 21:27 - 2014-06-05 21:26 - 00011522 _____ () C:\Users\Comfor\Desktop\FRST.txt
2014-06-05 21:27 - 2007-08-27 13:34 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Temp
2014-06-05 21:26 - 2014-06-05 21:25 - 00000000 ____D () C:\FRST
2014-06-05 21:23 - 2014-06-05 21:23 - 00112640 _____ (forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
2014-06-05 21:22 - 2014-06-05 21:22 - 01059840 _____ (Farbar) C:\Users\Comfor\Desktop\FRST.exe
2014-06-05 21:19 - 2007-08-21 16:05 - 00000000 ____D () C:\install
2014-06-05 21:10 - 2012-04-30 20:42 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-05 21:07 - 2007-08-28 09:59 - 00002635 _____ () C:\Users\Comfor\Desktop\Microsoft Office Word 2007.lnk
2014-06-05 20:54 - 2006-11-02 14:52 - 01066875 _____ () C:\Windows\WindowsUpdate.log
2014-06-05 20:49 - 2012-02-27 19:03 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-05 20:49 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 20:49 - 2006-11-02 14:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 20:49 - 2006-11-02 14:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-05 20:49 - 2006-11-02 14:37 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-06-05 20:47 - 2014-04-08 11:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-05 20:47 - 2009-06-27 15:26 - 00000000 ___RD () C:\Program Files\Skype
2014-06-05 20:47 - 2007-08-28 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-06-05 20:47 - 2007-08-27 16:28 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-06-05 20:47 - 2007-08-27 15:47 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\GHISLER
2014-06-05 20:47 - 2007-08-21 15:33 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-05 20:47 - 2007-08-21 15:32 - 00000000 ____D () C:\Program Files\Adobe
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\spool
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\registration
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-05 20:18 - 2006-11-02 15:01 - 00032566 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-05 14:40 - 2012-02-27 19:03 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 08:40 - 2012-11-08 20:24 - 00100832 _____ () C:\Users\Comfor\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-04 08:40 - 2012-11-08 20:23 - 00372856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-04 08:39 - 2013-10-03 11:33 - 00642912 _____ () C:\Windows\PFRO.log
2014-06-03 20:23 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-06-03 19:59 - 2014-06-03 19:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-06-03 19:56 - 2007-08-28 09:57 - 00002661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Otevřít dokument sady Microsoft Office.lnk
2014-06-03 19:56 - 2007-08-28 09:57 - 00002637 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Nový dokument sady Microsoft Office.lnk
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-06-02 21:50 - 2006-11-02 12:33 - 01532822 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-02 13:53 - 2007-10-31 20:49 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\Skype
2014-06-02 11:53 - 2012-09-14 09:02 - 00002505 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-02 11:53 - 2007-10-31 20:44 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 15:51 - 2014-05-29 15:50 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-29 14:21 - 2014-05-29 14:21 - 04796856 _____ (AVAST Software) C:\Users\Comfor\Downloads\avast_free_antivirus_setup_online.exe
2014-05-29 14:13 - 2012-02-27 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-29 07:19 - 2014-05-29 06:51 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-29 07:16 - 2007-08-27 16:28 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-29 07:09 - 2014-05-29 07:09 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Adobe
2014-05-29 07:09 - 2007-08-27 14:05 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\Adobe
2014-05-29 06:51 - 2014-05-29 06:51 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-28 08:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-28 08:02 - 2010-02-24 19:33 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-05-27 15:44 - 2014-05-27 15:44 - 00000000 ____D () C:\Program Files\MSBuild
2014-05-27 10:22 - 2011-08-08 21:07 - 00000000 ____D () C:\Program Files\Common Files\Panasonic
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Movie Maker
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-05-27 10:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\System
2014-05-27 10:21 - 2007-08-27 16:04 - 00000000 ____D () C:\Program Files\Common Files\ACD Systems
2014-05-27 10:13 - 2007-08-22 09:29 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2014-05-24 09:41 - 2012-11-19 01:12 - 00000789 _____ () C:\Windows\setupact.log
2014-05-15 23:33 - 2013-07-17 15:09 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 23:29 - 2006-11-02 12:24 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-15 21:01 - 2011-06-29 13:43 - 00777488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 21:01 - 2008-04-06 20:13 - 00411680 ____N (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-15 21:01 - 2007-10-04 08:07 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-05-14 15:10 - 2012-04-30 20:42 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-14 15:10 - 2011-07-06 08:11 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-06 01:32 - 2014-05-15 23:26 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 01:14 - 2014-05-15 23:26 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 23:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
Some content of TEMP:
====================
C:\Users\Comfor\AppData\Local\Temp\mpegc.dll
C:\Users\Comfor\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Comfor\AppData\Local\Temp\nvStInst.exe
C:\Users\Comfor\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Comfor\AppData\Local\Temp\_isD5A6.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Available physical RAM: 1134.21 MB
Total physical RAM: 2046.83 MB
Percentage of memory in use: 44%
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Comfor\Desktop" je 1 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut
"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTV 310i Antenna Power
"C:\Program Files\Pinnacle\Shared Files\Drivers\Tools\PCTV 310i Antenna Power.exe" /silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toolbar_eula_launcher
C:\install\google\eula\EULALauncher.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO 6.1 HD Lite Edition.lnk
C:\PROGRA~1\COMMON~1\PANASO~1\PHOTOF~1\AUTOST~1.EXE [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
prosím o pomoc a kontrolu logu. Můj PC něco provedl a smazaly se některé součásti programů, zbyl jen zástupce na ploše no ve startu. Např avast - zůstala složka ale exe aplikace nikde. Chtěl jsem ho nainstalovat znova a nejde to. Podobný problém tu měl včera kolega.
Předem uvádím, že můj operační systém by měl být legální (byl součástí kupovaného PC v obchodě, i když už to je hodně pátků nazpátek ...)
Přikládám log
Děkuji za pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014
Ran by Comfor (administrator) on TRAXLER on 05-06-2014 21:26:20
Running from C:\Users\Comfor\Desktop
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\vVX3000.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_13_0_0_214_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4317184 2006-12-29] (Realtek Semiconductor)
HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun
HKLM\...\Run: [LifeCam] => "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe [707360 2006-12-06] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\...\Run: [AvastUI.exe] => "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {b5494747-6c57-11dc-bffc-00004d2d893c} - G:\TrueCrypt\TrueCrypt.exe /q background /e /c y /m ro /m rm /v "Secret\Corsair.tc"
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {eae167b4-025d-11de-a65e-001a4d2a5c6f} - G:\WDSetup.exe
HKU\S-1-5-21-4277153804-2581763958-2727245661-1000\...\MountPoints2: {f352cb0f-0345-11e2-8df7-001a4d2a5c6f} - F:\unlock.exe autoplay=true
Startup: C:\Users\Comfor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (No File)
==================== Internet (Whitelisted) ====================
ProxyServer: 10.1.1.30:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/search?q={searchT ... d=ie7&rlz=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
SearchScopes: HKLM - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - DefaultScope {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {104EE3F6-6FB5-478D-9388-A3341FD5CF21} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {23AE915A-9767-420D-8D86-8985BEA15275} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
BHO: No Name - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll No File
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Toolbar: HKCU - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} http://kitchenplanner.ikea.com/CZ/Core/ ... _Win32.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 213.192.60.6 213.192.60.5
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.3088 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll No File
FF Plugin: @real.com/nprpjplug;version=6.0.11.3006 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: www.google.com
CHR StartupUrls: "www.google.com"
CHR Extension: (YouTube) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-27]
CHR Extension: (Google Search) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-29]
CHR Extension: (Skype Click to Call) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-12-14]
CHR Extension: (Google Wallet) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-14]
CHR Extension: (Gmail) - C:\Users\Comfor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-29]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-02-29]
========================== Services (Whitelisted) =================
S3 Adobe LM Service; "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [X]
S2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [X]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [X]
S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
S2 nvUpdatusService; "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" [X]
S2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [1121536 2006-11-22] (Philips Semiconductors GmbH)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-05-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-05-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-05-15] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-05-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [777488 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411680 2014-05-15] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-05-01] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-05-01] ()
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2007-08-27] (Padus, Inc.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [685816 2007-10-27] ()
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 anothkoj; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-05 21:26 - 2014-06-05 21:27 - 00011522 _____ () C:\Users\Comfor\Desktop\FRST.txt
2014-06-05 21:25 - 2014-06-05 21:26 - 00000000 ____D () C:\FRST
2014-06-05 21:23 - 2014-06-05 21:23 - 00112640 _____ (forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
2014-06-05 21:22 - 2014-06-05 21:22 - 01059840 _____ (Farbar) C:\Users\Comfor\Desktop\FRST.exe
2014-06-03 19:59 - 2014-06-03 19:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-06-03 19:55 - 2014-06-03 20:23 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-05-29 15:50 - 2014-05-29 15:51 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-29 15:50 - 2012-10-30 23:50 - 00227648 _____ (AVAST Software) C:\Windows\system32\asw77DD.tmp
2014-05-29 14:21 - 2014-05-29 14:21 - 04796856 _____ (AVAST Software) C:\Users\Comfor\Downloads\avast_free_antivirus_setup_online.exe
2014-05-29 07:09 - 2014-05-29 07:09 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Adobe
2014-05-29 06:51 - 2014-05-29 07:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-29 06:51 - 2014-05-29 06:51 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-27 15:44 - 2014-05-27 15:44 - 00000000 ____D () C:\Program Files\MSBuild
2014-05-15 23:26 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 23:26 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 23:26 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 09:10 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
==================== One Month Modified Files and Folders =======
2014-06-05 21:27 - 2014-06-05 21:26 - 00011522 _____ () C:\Users\Comfor\Desktop\FRST.txt
2014-06-05 21:27 - 2007-08-27 13:34 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Temp
2014-06-05 21:26 - 2014-06-05 21:25 - 00000000 ____D () C:\FRST
2014-06-05 21:23 - 2014-06-05 21:23 - 00112640 _____ (forum.viry.cz) C:\Users\Comfor\Desktop\FRSTLauncher.exe
2014-06-05 21:22 - 2014-06-05 21:22 - 01059840 _____ (Farbar) C:\Users\Comfor\Desktop\FRST.exe
2014-06-05 21:19 - 2007-08-21 16:05 - 00000000 ____D () C:\install
2014-06-05 21:10 - 2012-04-30 20:42 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-05 21:07 - 2007-08-28 09:59 - 00002635 _____ () C:\Users\Comfor\Desktop\Microsoft Office Word 2007.lnk
2014-06-05 20:54 - 2006-11-02 14:52 - 01066875 _____ () C:\Windows\WindowsUpdate.log
2014-06-05 20:49 - 2012-02-27 19:03 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-05 20:49 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 20:49 - 2006-11-02 14:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 20:49 - 2006-11-02 14:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-05 20:49 - 2006-11-02 14:37 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-06-05 20:47 - 2014-04-08 11:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-05 20:47 - 2009-06-27 15:26 - 00000000 ___RD () C:\Program Files\Skype
2014-06-05 20:47 - 2007-08-28 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-06-05 20:47 - 2007-08-27 16:28 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-06-05 20:47 - 2007-08-27 15:47 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\GHISLER
2014-06-05 20:47 - 2007-08-21 15:33 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-05 20:47 - 2007-08-21 15:32 - 00000000 ____D () C:\Program Files\Adobe
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\spool
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\registration
2014-06-05 20:47 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-05 20:18 - 2006-11-02 15:01 - 00032566 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-05 14:40 - 2012-02-27 19:03 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 08:40 - 2012-11-08 20:24 - 00100832 _____ () C:\Users\Comfor\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-04 08:40 - 2012-11-08 20:23 - 00372856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-04 08:39 - 2013-10-03 11:33 - 00642912 _____ () C:\Windows\PFRO.log
2014-06-03 20:23 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-06-03 19:59 - 2014-06-03 19:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-06-03 19:56 - 2007-08-28 09:57 - 00002661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Otevřít dokument sady Microsoft Office.lnk
2014-06-03 19:56 - 2007-08-28 09:57 - 00002637 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Nový dokument sady Microsoft Office.lnk
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-03 19:55 - 2014-06-03 19:55 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-06-02 21:50 - 2006-11-02 12:33 - 01532822 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-02 13:53 - 2007-10-31 20:49 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\Skype
2014-06-02 11:53 - 2012-09-14 09:02 - 00002505 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-02 11:53 - 2007-10-31 20:44 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 15:51 - 2014-05-29 15:50 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-29 14:21 - 2014-05-29 14:21 - 04796856 _____ (AVAST Software) C:\Users\Comfor\Downloads\avast_free_antivirus_setup_online.exe
2014-05-29 14:13 - 2012-02-27 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-29 07:19 - 2014-05-29 06:51 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-29 07:16 - 2007-08-27 16:28 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-29 07:09 - 2014-05-29 07:09 - 00000000 ____D () C:\Users\Comfor\AppData\Local\Adobe
2014-05-29 07:09 - 2007-08-27 14:05 - 00000000 ____D () C:\Users\Comfor\AppData\Roaming\Adobe
2014-05-29 06:51 - 2014-05-29 06:51 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-28 08:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-28 08:02 - 2010-02-24 19:33 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-05-27 15:44 - 2014-05-27 15:44 - 00000000 ____D () C:\Program Files\MSBuild
2014-05-27 10:22 - 2011-08-08 21:07 - 00000000 ____D () C:\Program Files\Common Files\Panasonic
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Movie Maker
2014-05-27 10:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-05-27 10:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\System
2014-05-27 10:21 - 2007-08-27 16:04 - 00000000 ____D () C:\Program Files\Common Files\ACD Systems
2014-05-27 10:13 - 2007-08-22 09:29 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2014-05-24 09:41 - 2012-11-19 01:12 - 00000789 _____ () C:\Windows\setupact.log
2014-05-15 23:33 - 2013-07-17 15:09 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 23:29 - 2006-11-02 12:24 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-15 21:01 - 2011-06-29 13:43 - 00777488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 21:01 - 2008-04-06 20:13 - 00411680 ____N (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-15 21:01 - 2007-10-04 08:07 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-05-14 15:10 - 2012-04-30 20:42 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-14 15:10 - 2011-07-06 08:11 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-06 01:32 - 2014-05-15 23:26 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 01:14 - 2014-05-15 23:26 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 23:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
Some content of TEMP:
====================
C:\Users\Comfor\AppData\Local\Temp\mpegc.dll
C:\Users\Comfor\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Comfor\AppData\Local\Temp\nvStInst.exe
C:\Users\Comfor\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Comfor\AppData\Local\Temp\_isD5A6.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Available physical RAM: 1134.21 MB
Total physical RAM: 2046.83 MB
Percentage of memory in use: 44%
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Comfor\Desktop" je 1 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut
"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTV 310i Antenna Power
"C:\Program Files\Pinnacle\Shared Files\Drivers\Tools\PCTV 310i Antenna Power.exe" /silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toolbar_eula_launcher
C:\install\google\eula\EULALauncher.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO 6.1 HD Lite Edition.lnk
C:\PROGRA~1\COMMON~1\PANASO~1\PHOTOF~1\AUTOST~1.EXE [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================