Nenacte se plocha, ikony
Napsal: 11 říj 2014 17:28
Dobrý den, potřebovala bych pomoct s tímto problémem. Stalo se mi to před asi měsícem poprvé, od té doby to dělá při každém spuštění PC. Po přihlaseni se mi objeví nějaké dvě chyby, že se nepodařilo nakonfigurovat nastavení uživatele a odpočítává se 30 sekund a pak se automaticky dá ok. Potom probíhá vše obvykle- zobrazí se načítaní s modrou obrazovkou, ale pak se nenačte obvyklá plocha, změní se mi tapeta(ta windows louka) a v hornim levem rohu se objevi okno, kde běží nějaké opětovné konfigurování programů. Do dneška jsem to nijak neřešila, protože se to pak vždy rozběhlo a ikony se nakonec zobrazily-akorát jsem vždycky přišla o ulozenou práci z minuleho dne, tak jsem musela zalohovat pred vypnutim treba na flashku. Dnes se mi ale stalo, že se to okno v levem hornim rohu seklo na nějakem programu a zadne ikony, ani start panel se nenacetl. Dalo se pres ctrl alt delete dostat na procesy, ale nerozumím tomu, tak jsem zašla sem. Ted jsem v nouzovem rezimu a budu moc ráda, když mi pomůžete, protože jsem absolutně bezradná!
prikladam log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-10-2014 (ATTENTION: ====> FRST version is 30 days old and could be outdated)
Ran by Kajka (administrator) on KAJA on 10-11-2014 18:02:21
Running from C:\Documents and Settings\TEMP.KAJA\Dokumenty\Downloads
Loaded Profile: Kajka (Available profiles: Kajka)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\WgaTray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-06-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16132608 2007-05-28] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [SweetIM] => C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] => C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Lexmark X1100 Series] => C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe [57344 2003-08-19] (Lexmark International, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-10] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... E63118BE13}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1F3B57AB6D}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 7930842078
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 7930876094
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 79.127.192.230 79.127.195.194
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-18]
FF HKLM\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files\BetterSurf\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha684.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ff
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta802.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ff
FF HKLM\...\Firefox\Extensions: [ext@MediaWatchV1home757.net] - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ff
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-07]
FF Extension: No Name - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ff [Not Found]
FF Extension: No Name - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ff [Not Found]
FF Extension: No Name - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ff [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "https://www.google.cz/", "hxxp://youtube.com/"
CHR Profile: C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-10]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-10]
CHR Extension: (Disk Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-10]
CHR Extension: (Seznam Lištička - Email) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-11-10]
CHR Extension: (Seznam Lištička - Slovník) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-11-10]
CHR Extension: (YouTube) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-10]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-10]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-10]
CHR Extension: (avast! SafePrice) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2014-11-10]
CHR Extension: (Tabulky Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-10]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-10]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-10]
CHR Extension: (SweetPacks Chrome Extension) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2014-11-10]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-11-10]
CHR Extension: (Gmail) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-10]
CHR HKLM\...\Chrome\Extension: [acbmobkheekoilodhgplfjjoegbgpill] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ch\WebexpEnhancedV1alpha684.crx []
CHR HKLM\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files\BetterSurf\ch\Chrome.crx []
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [hbhgilhodidclojaglkkdheamiihigcm] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ch\VideoPlayerV3beta802.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [kkfajjgblglopfefcmdlelfcfgbpfkhm] - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ch\MediaWatchV1home757.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\System32\mjcm\SweetNT.crx [2014-07-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-10] (AVAST Software)
S2 IBUpdaterService; C:\WINDOWS\system32\dmwu.exe [2387760 2014-09-17] ()
S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-08-10] (Oracle Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files\Overwolf\OverwolfUpdater.exe [998176 2014-09-21] (Overwolf LTD)
S2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-08-10] ()
S2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-08-10] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55112 2014-08-10] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-08-10] ()
S1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [779536 2014-08-10] (AVAST Software)
S1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [414520 2014-08-10] (AVAST Software)
S1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57800 2014-08-10] (AVAST Software)
S0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [192352 2014-08-10] ()
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
S0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETw4x32; C:\WINDOWS\System32\DRIVERS\NETw4x32.sys [2206976 2007-04-30] (Intel Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S2 WCMVCAM; C:\WINDOWS\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 18:01 - 2014-11-10 18:02 - 00000000 ____D () C:\FRST
2014-11-10 17:57 - 2014-11-10 17:58 - 00000000 ____D () C:\Program Files\trend micro
2014-11-10 17:57 - 2014-11-10 17:57 - 00000000 ____D () C:\rsit
2014-11-10 17:52 - 2014-11-10 17:52 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google
2014-11-10 17:51 - 2014-11-10 18:02 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Temp
2014-11-10 17:51 - 2014-11-10 17:57 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Dokumenty
2014-11-10 17:51 - 2014-11-10 17:52 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací
2014-11-10 17:51 - 2014-11-10 17:51 - 00000020 ___SH () C:\Documents and Settings\TEMP.KAJA\ntuser.ini
2014-11-10 17:51 - 2014-11-10 17:51 - 00000000 ____D () C:\WINDOWS\CSC
2014-11-10 17:51 - 2014-11-10 17:51 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA
2014-11-10 17:51 - 2013-01-13 18:51 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Microsoft Help
2014-11-10 17:51 - 2013-01-13 18:48 - 00000000 __SHD () C:\Documents and Settings\TEMP.KAJA\IETldCache
2014-11-10 17:51 - 2013-01-11 19:42 - 00001599 _____ () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-11-10 17:51 - 2013-01-11 19:42 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Příslušenství
2014-11-10 17:51 - 2013-01-11 19:42 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy
2014-11-10 17:51 - 2013-01-11 19:41 - 00000792 _____ () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Windows Media Player.lnk
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 __RHD () C:\Documents and Settings\TEMP.KAJA\Data aplikací
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Po spuštění
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Okolní tiskárny
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Okolní síť
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Plocha
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Oblíbené položky
2014-11-10 17:51 - 2013-01-11 19:37 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Šablony
2014-11-09 14:40 - 2014-11-09 14:40 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Temp
2014-11-09 14:36 - 2014-11-09 20:53 - 00000178 ___SH () C:\Documents and Settings\TEMP\ntuser.ini
2014-11-09 14:36 - 2014-11-09 14:37 - 00000738 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Outlook Express.lnk
2014-11-09 14:36 - 2014-11-09 14:36 - 00000803 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Internet Explorer.lnk
2014-11-09 14:36 - 2014-11-09 14:36 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\SWDS
2014-11-09 14:36 - 2014-11-09 14:36 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Google
2014-11-09 14:35 - 2014-11-09 20:53 - 00000000 ___HD () C:\Documents and Settings\TEMP\Local Settings\Data aplikací
2014-11-09 14:35 - 2014-11-09 20:53 - 00000000 ____D () C:\Documents and Settings\TEMP
2014-11-09 14:35 - 2014-11-09 20:51 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Temp
2014-11-09 14:35 - 2014-11-09 14:37 - 00000000 ___RD () C:\Documents and Settings\TEMP\Oblíbené položky
2014-11-09 14:35 - 2014-11-09 14:36 - 00000792 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Windows Media Player.lnk
2014-11-09 14:35 - 2014-11-09 14:36 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Příslušenství
2014-11-09 14:35 - 2014-11-09 14:36 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy
2014-11-09 14:35 - 2013-01-13 18:51 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Microsoft Help
2014-11-09 14:35 - 2013-01-11 19:42 - 00001599 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Po spuštění
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP\Okolní tiskárny
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP\Okolní síť
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP\Plocha
2014-11-09 14:35 - 2013-01-11 19:37 - 00000000 ___HD () C:\Documents and Settings\TEMP\Šablony
2014-10-28 12:32 - 2014-10-28 12:32 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ___RD () C:\Program Files\Skype
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-10-28 00:25 - 2014-11-04 14:19 - 00002287 _____ () C:\WINDOWS\setupapi.log
2014-10-17 13:54 - 2014-11-10 16:48 - 00012386 _____ () C:\WINDOWS\wmsetup.log
2014-10-16 19:19 - 2014-10-16 19:19 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-10-16 19:19 - 2014-10-16 19:19 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-16 19:19 - 2014-10-16 19:19 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 18:01 - 2014-03-29 19:50 - 00000396 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2014-11-10 17:55 - 2013-01-11 19:40 - 01030536 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-10 17:51 - 2013-01-11 19:46 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Temp
2014-11-10 17:51 - 2013-01-11 19:40 - 01833130 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-10 17:51 - 2001-10-25 13:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-10 17:49 - 2013-01-11 19:46 - 00032464 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-10 17:49 - 2013-01-11 19:46 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-10 17:49 - 2013-01-11 19:42 - 00000275 _____ () C:\WINDOWS\wiadebug.log
2014-11-10 17:28 - 2013-01-11 19:39 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-11-10 17:23 - 2013-01-12 01:22 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 17:11 - 2013-01-12 11:21 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-10 17:01 - 2013-10-07 19:46 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-10 17:01 - 2013-01-15 23:09 - 00000382 _____ () C:\WINDOWS\Tasks\AmiUpdXp.job
2014-11-10 17:01 - 2013-01-12 01:22 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 16:54 - 2013-01-11 19:42 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-11-10 16:52 - 2013-01-16 01:47 - 00000992 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-515967899-963894560-839522115-1003UA.job
2014-11-09 18:38 - 2014-09-26 17:38 - 00000388 _____ () C:\WINDOWS\Tasks\Overwolf Updater Task.job
2014-11-09 01:52 - 2013-01-16 01:47 - 00000970 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-515967899-963894560-839522115-1003Core.job
2014-11-07 16:31 - 2013-12-19 19:19 - 00000000 ____D () C:\Program Files\Lexmark X1100 Series
2014-11-07 06:14 - 2013-01-12 11:40 - 00065536 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2014-10-28 21:48 - 2013-12-27 11:22 - 00348128 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
2014-10-28 21:48 - 2013-01-11 19:46 - 00000000 ___HD () C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2014-10-28 12:32 - 2013-01-14 16:51 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Skype
2014-10-28 12:32 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-10-28 12:32 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-10-26 16:28 - 2014-06-26 13:39 - 00000000 ____D () C:\WINDOWS\system32\mjcm
2014-10-26 16:27 - 2013-06-02 17:39 - 00000000 ____D () C:\WINDOWS\system32\WNLT
2014-10-26 16:27 - 2013-06-02 17:39 - 00000000 ____D () C:\WINDOWS\system32\ARFC
2014-10-25 01:30 - 2013-01-12 01:23 - 00001813 _____ () C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-10-23 20:11 - 2013-01-12 11:21 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-10-23 20:11 - 2013-01-12 11:21 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-10-22 23:38 - 2014-09-26 17:31 - 00000000 ____D () C:\Program Files\Overwolf
2014-10-22 17:41 - 2014-09-26 17:36 - 00000000 ____D () C:\Program Files\Common Files\Overwolf
2014-10-16 19:22 - 2013-07-03 10:22 - 00000000 ____D () C:\WINDOWS\Minidump
2014-10-16 19:13 - 2014-03-13 18:33 - 00000222 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-16 19:12 - 2014-03-13 18:33 - 00000216 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-15 02:15 - 2013-01-12 11:36 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-10-15 02:14 - 2013-07-11 21:57 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-15 02:03 - 2013-01-11 21:06 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
Some content of TEMP:
====================
C:\Documents and Settings\Kajka\Local Settings\Temp\AskSLib.dll
C:\Documents and Settings\Kajka\Local Settings\Temp\bundlesweetimsetup.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\converter.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\drvinstal1.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\GenericUninstall.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\mgsqlite3.dll
C:\Documents and Settings\Kajka\Local Settings\Temp\PIPInstaller_PTV_.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\rtdrvmon.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\set-app.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\Shortcut_bundlesweetimsetup.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\SimboApp.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\SIMEEIInstaller.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\uninstaller.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\Updater.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Documents and Settings\NetworkService\Local Settings\Temp\mpam-266f1643.exe
C:\Documents and Settings\TEMP\Local Settings\Temp\rtdrvmon.exe
C:\Documents and Settings\TEMP\Local Settings\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
prikladam log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-10-2014 (ATTENTION: ====> FRST version is 30 days old and could be outdated)
Ran by Kajka (administrator) on KAJA on 10-11-2014 18:02:21
Running from C:\Documents and Settings\TEMP.KAJA\Dokumenty\Downloads
Loaded Profile: Kajka (Available profiles: Kajka)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\WgaTray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-06-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16132608 2007-05-28] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [SweetIM] => C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] => C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Lexmark X1100 Series] => C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe [57344 2003-08-19] (Lexmark International, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-10] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... E63118BE13}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1F3B57AB6D}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 7930842078
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 7930876094
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 79.127.192.230 79.127.195.194
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-18]
FF HKLM\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files\BetterSurf\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha684.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ff
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta802.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ff
FF HKLM\...\Firefox\Extensions: [ext@MediaWatchV1home757.net] - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ff
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-07]
FF Extension: No Name - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ff [Not Found]
FF Extension: No Name - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ff [Not Found]
FF Extension: No Name - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ff [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "https://www.google.cz/", "hxxp://youtube.com/"
CHR Profile: C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-10]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-10]
CHR Extension: (Disk Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-10]
CHR Extension: (Seznam Lištička - Email) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-11-10]
CHR Extension: (Seznam Lištička - Slovník) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-11-10]
CHR Extension: (YouTube) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-10]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-10]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-10]
CHR Extension: (avast! SafePrice) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2014-11-10]
CHR Extension: (Tabulky Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-10]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-10]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-10]
CHR Extension: (SweetPacks Chrome Extension) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2014-11-10]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-11-10]
CHR Extension: (Gmail) - C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-10]
CHR HKLM\...\Chrome\Extension: [acbmobkheekoilodhgplfjjoegbgpill] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha684\ch\WebexpEnhancedV1alpha684.crx []
CHR HKLM\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files\BetterSurf\ch\Chrome.crx []
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [hbhgilhodidclojaglkkdheamiihigcm] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta802\ch\VideoPlayerV3beta802.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [kkfajjgblglopfefcmdlelfcfgbpfkhm] - C:\Program Files\MediaWatchV1\MediaWatchV1home757\ch\MediaWatchV1home757.crx [2014-08-10]
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\System32\mjcm\SweetNT.crx [2014-07-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-10] (AVAST Software)
S2 IBUpdaterService; C:\WINDOWS\system32\dmwu.exe [2387760 2014-09-17] ()
S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-08-10] (Oracle Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files\Overwolf\OverwolfUpdater.exe [998176 2014-09-21] (Overwolf LTD)
S2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-08-10] ()
S2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-08-10] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55112 2014-08-10] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-08-10] ()
S1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [779536 2014-08-10] (AVAST Software)
S1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [414520 2014-08-10] (AVAST Software)
S1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57800 2014-08-10] (AVAST Software)
S0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [192352 2014-08-10] ()
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
S0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETw4x32; C:\WINDOWS\System32\DRIVERS\NETw4x32.sys [2206976 2007-04-30] (Intel Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S2 WCMVCAM; C:\WINDOWS\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 18:01 - 2014-11-10 18:02 - 00000000 ____D () C:\FRST
2014-11-10 17:57 - 2014-11-10 17:58 - 00000000 ____D () C:\Program Files\trend micro
2014-11-10 17:57 - 2014-11-10 17:57 - 00000000 ____D () C:\rsit
2014-11-10 17:52 - 2014-11-10 17:52 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Google
2014-11-10 17:51 - 2014-11-10 18:02 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Temp
2014-11-10 17:51 - 2014-11-10 17:57 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Dokumenty
2014-11-10 17:51 - 2014-11-10 17:52 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací
2014-11-10 17:51 - 2014-11-10 17:51 - 00000020 ___SH () C:\Documents and Settings\TEMP.KAJA\ntuser.ini
2014-11-10 17:51 - 2014-11-10 17:51 - 00000000 ____D () C:\WINDOWS\CSC
2014-11-10 17:51 - 2014-11-10 17:51 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA
2014-11-10 17:51 - 2013-01-13 18:51 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Local Settings\Data aplikací\Microsoft Help
2014-11-10 17:51 - 2013-01-13 18:48 - 00000000 __SHD () C:\Documents and Settings\TEMP.KAJA\IETldCache
2014-11-10 17:51 - 2013-01-11 19:42 - 00001599 _____ () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-11-10 17:51 - 2013-01-11 19:42 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Příslušenství
2014-11-10 17:51 - 2013-01-11 19:42 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy
2014-11-10 17:51 - 2013-01-11 19:41 - 00000792 _____ () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Windows Media Player.lnk
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 __RHD () C:\Documents and Settings\TEMP.KAJA\Data aplikací
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start\Programy\Po spuštění
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP.KAJA\Nabídka Start
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Okolní tiskárny
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Okolní síť
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Plocha
2014-11-10 17:51 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP.KAJA\Oblíbené položky
2014-11-10 17:51 - 2013-01-11 19:37 - 00000000 ___HD () C:\Documents and Settings\TEMP.KAJA\Šablony
2014-11-09 14:40 - 2014-11-09 14:40 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Temp
2014-11-09 14:36 - 2014-11-09 20:53 - 00000178 ___SH () C:\Documents and Settings\TEMP\ntuser.ini
2014-11-09 14:36 - 2014-11-09 14:37 - 00000738 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Outlook Express.lnk
2014-11-09 14:36 - 2014-11-09 14:36 - 00000803 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Internet Explorer.lnk
2014-11-09 14:36 - 2014-11-09 14:36 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\SWDS
2014-11-09 14:36 - 2014-11-09 14:36 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Google
2014-11-09 14:35 - 2014-11-09 20:53 - 00000000 ___HD () C:\Documents and Settings\TEMP\Local Settings\Data aplikací
2014-11-09 14:35 - 2014-11-09 20:53 - 00000000 ____D () C:\Documents and Settings\TEMP
2014-11-09 14:35 - 2014-11-09 20:51 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Temp
2014-11-09 14:35 - 2014-11-09 14:37 - 00000000 ___RD () C:\Documents and Settings\TEMP\Oblíbené položky
2014-11-09 14:35 - 2014-11-09 14:36 - 00000792 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Windows Media Player.lnk
2014-11-09 14:35 - 2014-11-09 14:36 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Příslušenství
2014-11-09 14:35 - 2014-11-09 14:36 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy
2014-11-09 14:35 - 2013-01-13 18:51 - 00000000 ____D () C:\Documents and Settings\TEMP\Local Settings\Data aplikací\Microsoft Help
2014-11-09 14:35 - 2013-01-11 19:42 - 00001599 _____ () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start\Programy\Po spuštění
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\TEMP\Nabídka Start
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP\Okolní tiskárny
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ___HD () C:\Documents and Settings\TEMP\Okolní síť
2014-11-09 14:35 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\TEMP\Plocha
2014-11-09 14:35 - 2013-01-11 19:37 - 00000000 ___HD () C:\Documents and Settings\TEMP\Šablony
2014-10-28 12:32 - 2014-10-28 12:32 - 00001896 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ___RD () C:\Program Files\Skype
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-10-28 12:32 - 2014-10-28 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2014-10-28 00:25 - 2014-11-04 14:19 - 00002287 _____ () C:\WINDOWS\setupapi.log
2014-10-17 13:54 - 2014-11-10 16:48 - 00012386 _____ () C:\WINDOWS\wmsetup.log
2014-10-16 19:19 - 2014-10-16 19:19 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-10-16 19:19 - 2014-10-16 19:19 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-16 19:19 - 2014-10-16 19:19 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 18:01 - 2014-03-29 19:50 - 00000396 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2014-11-10 17:55 - 2013-01-11 19:40 - 01030536 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-10 17:51 - 2013-01-11 19:46 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Temp
2014-11-10 17:51 - 2013-01-11 19:40 - 01833130 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-10 17:51 - 2001-10-25 13:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-10 17:49 - 2013-01-11 19:46 - 00032464 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-10 17:49 - 2013-01-11 19:46 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-10 17:49 - 2013-01-11 19:42 - 00000275 _____ () C:\WINDOWS\wiadebug.log
2014-11-10 17:28 - 2013-01-11 19:39 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-11-10 17:23 - 2013-01-12 01:22 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 17:11 - 2013-01-12 11:21 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-10 17:01 - 2013-10-07 19:46 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-10 17:01 - 2013-01-15 23:09 - 00000382 _____ () C:\WINDOWS\Tasks\AmiUpdXp.job
2014-11-10 17:01 - 2013-01-12 01:22 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 16:54 - 2013-01-11 19:42 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-11-10 16:52 - 2013-01-16 01:47 - 00000992 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-515967899-963894560-839522115-1003UA.job
2014-11-09 18:38 - 2014-09-26 17:38 - 00000388 _____ () C:\WINDOWS\Tasks\Overwolf Updater Task.job
2014-11-09 01:52 - 2013-01-16 01:47 - 00000970 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-515967899-963894560-839522115-1003Core.job
2014-11-07 16:31 - 2013-12-19 19:19 - 00000000 ____D () C:\Program Files\Lexmark X1100 Series
2014-11-07 06:14 - 2013-01-12 11:40 - 00065536 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2014-10-28 21:48 - 2013-12-27 11:22 - 00348128 _____ () C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
2014-10-28 21:48 - 2013-01-11 19:46 - 00000000 ___HD () C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2014-10-28 12:32 - 2013-01-14 16:51 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Skype
2014-10-28 12:32 - 2013-01-11 19:39 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-10-28 12:32 - 2013-01-11 19:39 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-10-26 16:28 - 2014-06-26 13:39 - 00000000 ____D () C:\WINDOWS\system32\mjcm
2014-10-26 16:27 - 2013-06-02 17:39 - 00000000 ____D () C:\WINDOWS\system32\WNLT
2014-10-26 16:27 - 2013-06-02 17:39 - 00000000 ____D () C:\WINDOWS\system32\ARFC
2014-10-25 01:30 - 2013-01-12 01:23 - 00001813 _____ () C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-10-23 20:11 - 2013-01-12 11:21 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-10-23 20:11 - 2013-01-12 11:21 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-10-22 23:38 - 2014-09-26 17:31 - 00000000 ____D () C:\Program Files\Overwolf
2014-10-22 17:41 - 2014-09-26 17:36 - 00000000 ____D () C:\Program Files\Common Files\Overwolf
2014-10-16 19:22 - 2013-07-03 10:22 - 00000000 ____D () C:\WINDOWS\Minidump
2014-10-16 19:13 - 2014-03-13 18:33 - 00000222 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-16 19:12 - 2014-03-13 18:33 - 00000216 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-15 02:15 - 2013-01-12 11:36 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-10-15 02:14 - 2013-07-11 21:57 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-15 02:03 - 2013-01-11 21:06 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
Some content of TEMP:
====================
C:\Documents and Settings\Kajka\Local Settings\Temp\AskSLib.dll
C:\Documents and Settings\Kajka\Local Settings\Temp\bundlesweetimsetup.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\converter.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\drvinstal1.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\GenericUninstall.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\mgsqlite3.dll
C:\Documents and Settings\Kajka\Local Settings\Temp\PIPInstaller_PTV_.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\rtdrvmon.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\set-app.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\Shortcut_bundlesweetimsetup.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\SimboApp.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\SIMEEIInstaller.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\uninstaller.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\Updater.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\Kajka\Local Settings\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Documents and Settings\NetworkService\Local Settings\Temp\mpam-266f1643.exe
C:\Documents and Settings\TEMP\Local Settings\Temp\rtdrvmon.exe
C:\Documents and Settings\TEMP\Local Settings\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================