Prosímo kontrolu, podezření, 1 proces pořád 50%
Napsal: 05 lis 2014 22:03
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Jan Rukavička (administrator) on 1810TZ on 10-11-2014 22:00:48
Running from C:\Documents and Settings\Jan Rukavička\Plocha
Loaded Profile: Jan Rukavička (Available profiles: Jan Rukavička)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\inetsrv\inetinfo.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(forum.viry.cz) C:\Documents and Settings\Jan Rukavička\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [17887232 2009-06-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1372160 2009-07-01] (Intel(R) Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1202448 2009-07-01] (Intel(R) Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [805384 2014-01-25] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [NPSStartup] => [X]
HKLM\...\Run: [MSStp] => C:\WINDOWS\inf\msstp.vbe [1584 2014-03-05] ()
HKLM\...\Run: [mnceopwavSrv] => C:\WINDOWS\system32\mnceopwav.vbe [7670 2014-03-05] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Winlogon: [UIHost] C:\WINDOWS\system32\logonui.exe [515072 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKU\S-1-5-19\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-19\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
HKU\S-1-5-20\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-20\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
HKU\S-1-5-18\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKCU - {010F492F-54FC-4461-8A2D-F34ABA0436C5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: PodoWeb -> {980b8a8f-ea0b-4c24-a2e9-70635e2502e9} -> C:\Program Files\PodoWeb\PodoWebbho.dll (PodoWeb)
BHO: NextCoup -> {ae711686-aca6-4629-960b-3dfd922e5d5b} -> C:\Program Files\NextCoup\Fn3ITHATu6Df2g.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Vaudixx) - C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bcnlgaejjldjaekengmfmbdgiblfdcph [2014-09-14]
CHR Extension: (NextCoup) - C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pojlppkoeidkjfhehlmdajbklflkpkef [2014-10-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-10-24] (Oracle Corporation)
R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-07-01] (Intel(R) Corporation) [File not signed]
R2 W3SVC; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [533024 2009-06-18] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37160 2008-02-04] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [991136 2009-04-15] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-24] (Broadcom Corporation.)
S3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37032 2008-02-04] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [45984 2009-06-18] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-06] (Disc Soft Ltd)
S3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [22688 2014-01-21] (REALiX(tm))
R3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [39424 2009-03-31] (Atheros Communications, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETw1x32; C:\WINDOWS\System32\DRIVERS\NETw1x32.sys [5929216 2009-06-19] (Intel Corporation)
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
R1 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
S4 IntelIde; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 22:00 - 2014-11-10 22:01 - 00010018 _____ () C:\Documents and Settings\Jan Rukavička\Plocha\FRST.txt
2014-11-10 22:00 - 2014-11-10 22:00 - 00000000 ____D () C:\FRST
2014-11-10 21:59 - 2014-11-10 21:59 - 01106432 _____ (Farbar) C:\Documents and Settings\Jan Rukavička\Plocha\FRST.exe
2014-11-10 21:59 - 2014-11-10 21:59 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Jan Rukavička\Plocha\FRSTLauncher.exe
2014-11-10 19:44 - 2014-11-10 19:44 - 00001915 _____ () C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2014-11-10 19:44 - 2014-11-10 19:44 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\Google
2014-11-10 19:44 - 2014-11-10 19:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth
2014-11-10 19:39 - 2014-11-10 21:46 - 00000950 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 19:39 - 2014-11-10 19:44 - 00000954 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 19:39 - 2014-11-10 19:44 - 00000000 ____D () C:\Program Files\Google
2014-11-08 18:04 - 2014-11-08 18:04 - 00003926 _____ () C:\WINDOWS\setupapi.log
2014-11-07 09:40 - 2014-11-07 09:40 - 00000690 _____ () C:\Documents and Settings\Jan Rukavička\Dokumenty\cc_20141107_094013.reg
2014-10-24 15:35 - 2014-10-24 15:35 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-10-24 15:35 - 2014-10-24 15:35 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Program Files\Java
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-10-24 15:32 - 2014-10-24 15:32 - 00019326 _____ () C:\Documents and Settings\Jan Rukavička\Dokumenty\cc_20141024_163233.reg
2014-10-24 15:25 - 2014-10-24 15:25 - 00000000 ____D () C:\Program Files\NextCoup
2014-10-24 15:25 - 2014-10-24 15:25 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\NextCoup
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 22:01 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Temp
2014-11-10 22:00 - 2014-01-16 22:15 - 00000000 ___HD () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací
2014-11-10 22:00 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Plocha
2014-11-10 21:48 - 2014-08-04 13:06 - 00000062 _____ () C:\Documents and Settings\Jan Rukavička\rgut
2014-11-10 21:48 - 2014-01-16 22:57 - 00000000 ____D () C:\WINDOWS\system32\inetsrv
2014-11-10 21:47 - 2014-01-16 23:05 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-11-10 21:47 - 2014-01-16 22:10 - 01929087 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-10 21:46 - 2014-01-16 23:05 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-11-10 21:46 - 2014-01-16 22:14 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-10 20:04 - 2014-01-16 22:15 - 00000178 ___SH () C:\Documents and Settings\Jan Rukavička\ntuser.ini
2014-11-10 20:04 - 2014-01-16 22:14 - 00032620 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-10 19:44 - 2014-01-16 23:00 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-10 19:44 - 2014-01-16 23:00 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-11-10 19:44 - 2014-01-16 22:15 - 00000000 __RHD () C:\Documents and Settings\Jan Rukavička\Data aplikací
2014-11-10 19:39 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google
2014-11-10 19:31 - 2014-01-17 00:00 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-07 10:42 - 2014-01-16 23:39 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-07 10:42 - 2014-01-16 23:39 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-07 10:41 - 2014-06-21 07:49 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Adobe
2014-11-07 09:56 - 2014-01-16 22:09 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt
2014-11-07 09:53 - 2014-10-03 18:23 - 00000000 ____D () C:\Program Files\Abe's Oddysee
2014-11-07 09:53 - 2014-01-16 23:00 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start
2014-11-07 09:53 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička
2014-11-07 09:52 - 2014-01-16 23:00 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-11-07 09:52 - 2014-01-16 23:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-07 09:40 - 2014-01-16 22:15 - 00000000 ___RD () C:\Documents and Settings\Jan Rukavička\Dokumenty
2014-11-07 09:37 - 2014-01-16 09:56 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-02 13:02 - 2014-01-16 23:01 - 00785792 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-24 20:06 - 2014-01-17 11:00 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\vlc
2014-10-24 16:14 - 2014-10-03 18:09 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\Seznam.cz
2014-10-24 15:26 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Vaudaix
2014-10-24 15:25 - 2014-09-14 17:21 - 00000406 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-10-24 15:25 - 2014-09-14 17:21 - 00000000 ____D () C:\Program Files\Vaudaix
2014-10-24 15:25 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\8c4d112dfd1676b4
2014-10-24 15:18 - 2014-01-16 23:18 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\GHISLER
2014-10-24 08:06 - 2014-02-14 09:35 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-24 08:04 - 2014-01-16 23:19 - 100290944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:40.01 GB) (Free:31.49 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:192.87 GB) (Free:75.71 GB) NTFS
Available physical RAM: 2528.7 MB
Total physical RAM: 2974.84 MB
Percentage of memory in use: 14%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 232.9 GB) (Disk ID: 1E06AC08)
Partition 1: (Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=192.9 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Low Battery Alarm Program.job => ?
Task: C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Jan Rukavika\Plocha" je 15 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel
C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
mnmsrvc REG_DWORD 0x3
avast! Antivirus REG_DWORD 0x2
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Jan Rukavika\\Plocha\\MyPhoneExplorer portable\\MyPhoneExplorer portable.exe"="C:\\Documents and Settings\\Jan Rukavika\\Plocha\\MyPhoneExplorer portable\\MyPhoneExplorer portable.exe:*:Enabled:MyPhoneExplorer"
"C:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer portable.exe"="C:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer portable.exe:*:Enabled:MyPhoneExplorer"
"C:\\Program Files\\Things & Stuff\\Touchpad Server\\TouchpadServer.exe"="C:\\Program Files\\Things & Stuff\\Touchpad Server\\TouchpadServer.exe:*:Enabled:Touchpad Server"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"="C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"="C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by Jan Rukavička (administrator) on 1810TZ on 10-11-2014 22:00:48
Running from C:\Documents and Settings\Jan Rukavička\Plocha
Loaded Profile: Jan Rukavička (Available profiles: Jan Rukavička)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\inetsrv\inetinfo.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(forum.viry.cz) C:\Documents and Settings\Jan Rukavička\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [17887232 2009-06-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1372160 2009-07-01] (Intel(R) Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1202448 2009-07-01] (Intel(R) Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [805384 2014-01-25] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [NPSStartup] => [X]
HKLM\...\Run: [MSStp] => C:\WINDOWS\inf\msstp.vbe [1584 2014-03-05] ()
HKLM\...\Run: [mnceopwavSrv] => C:\WINDOWS\system32\mnceopwav.vbe [7670 2014-03-05] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Winlogon: [UIHost] C:\WINDOWS\system32\logonui.exe [515072 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKU\S-1-5-19\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-19\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
HKU\S-1-5-20\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-20\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
HKU\S-1-5-18\...\RunOnce: [_nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKCU - {010F492F-54FC-4461-8A2D-F34ABA0436C5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: PodoWeb -> {980b8a8f-ea0b-4c24-a2e9-70635e2502e9} -> C:\Program Files\PodoWeb\PodoWebbho.dll (PodoWeb)
BHO: NextCoup -> {ae711686-aca6-4629-960b-3dfd922e5d5b} -> C:\Program Files\NextCoup\Fn3ITHATu6Df2g.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Vaudixx) - C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bcnlgaejjldjaekengmfmbdgiblfdcph [2014-09-14]
CHR Extension: (NextCoup) - C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pojlppkoeidkjfhehlmdajbklflkpkef [2014-10-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-10-24] (Oracle Corporation)
R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-07-01] (Intel(R) Corporation) [File not signed]
R2 W3SVC; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [533024 2009-06-18] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37160 2008-02-04] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [991136 2009-04-15] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-24] (Broadcom Corporation.)
S3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37032 2008-02-04] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [45984 2009-06-18] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-06] (Disc Soft Ltd)
S3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [22688 2014-01-21] (REALiX(tm))
R3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [39424 2009-03-31] (Atheros Communications, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETw1x32; C:\WINDOWS\System32\DRIVERS\NETw1x32.sys [5929216 2009-06-19] (Intel Corporation)
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
R1 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
S4 IntelIde; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 22:00 - 2014-11-10 22:01 - 00010018 _____ () C:\Documents and Settings\Jan Rukavička\Plocha\FRST.txt
2014-11-10 22:00 - 2014-11-10 22:00 - 00000000 ____D () C:\FRST
2014-11-10 21:59 - 2014-11-10 21:59 - 01106432 _____ (Farbar) C:\Documents and Settings\Jan Rukavička\Plocha\FRST.exe
2014-11-10 21:59 - 2014-11-10 21:59 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Jan Rukavička\Plocha\FRSTLauncher.exe
2014-11-10 19:44 - 2014-11-10 19:44 - 00001915 _____ () C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2014-11-10 19:44 - 2014-11-10 19:44 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\Google
2014-11-10 19:44 - 2014-11-10 19:44 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth
2014-11-10 19:39 - 2014-11-10 21:46 - 00000950 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 19:39 - 2014-11-10 19:44 - 00000954 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 19:39 - 2014-11-10 19:44 - 00000000 ____D () C:\Program Files\Google
2014-11-08 18:04 - 2014-11-08 18:04 - 00003926 _____ () C:\WINDOWS\setupapi.log
2014-11-07 09:40 - 2014-11-07 09:40 - 00000690 _____ () C:\Documents and Settings\Jan Rukavička\Dokumenty\cc_20141107_094013.reg
2014-10-24 15:35 - 2014-10-24 15:35 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-10-24 15:35 - 2014-10-24 15:35 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-10-24 15:35 - 2014-10-24 15:35 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Program Files\Java
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-24 15:35 - 2014-10-24 15:35 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-10-24 15:32 - 2014-10-24 15:32 - 00019326 _____ () C:\Documents and Settings\Jan Rukavička\Dokumenty\cc_20141024_163233.reg
2014-10-24 15:25 - 2014-10-24 15:25 - 00000000 ____D () C:\Program Files\NextCoup
2014-10-24 15:25 - 2014-10-24 15:25 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\NextCoup
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 22:01 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Temp
2014-11-10 22:00 - 2014-01-16 22:15 - 00000000 ___HD () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací
2014-11-10 22:00 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Plocha
2014-11-10 21:48 - 2014-08-04 13:06 - 00000062 _____ () C:\Documents and Settings\Jan Rukavička\rgut
2014-11-10 21:48 - 2014-01-16 22:57 - 00000000 ____D () C:\WINDOWS\system32\inetsrv
2014-11-10 21:47 - 2014-01-16 23:05 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-11-10 21:47 - 2014-01-16 22:10 - 01929087 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-10 21:46 - 2014-01-16 23:05 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-11-10 21:46 - 2014-01-16 22:14 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-10 20:04 - 2014-01-16 22:15 - 00000178 ___SH () C:\Documents and Settings\Jan Rukavička\ntuser.ini
2014-11-10 20:04 - 2014-01-16 22:14 - 00032620 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-10 19:44 - 2014-01-16 23:00 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-10 19:44 - 2014-01-16 23:00 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-11-10 19:44 - 2014-01-16 22:15 - 00000000 __RHD () C:\Documents and Settings\Jan Rukavička\Data aplikací
2014-11-10 19:39 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Google
2014-11-10 19:31 - 2014-01-17 00:00 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-07 10:42 - 2014-01-16 23:39 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-07 10:42 - 2014-01-16 23:39 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-07 10:41 - 2014-06-21 07:49 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\Adobe
2014-11-07 09:56 - 2014-01-16 22:09 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt
2014-11-07 09:53 - 2014-10-03 18:23 - 00000000 ____D () C:\Program Files\Abe's Oddysee
2014-11-07 09:53 - 2014-01-16 23:00 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start
2014-11-07 09:53 - 2014-01-16 22:15 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička
2014-11-07 09:52 - 2014-01-16 23:00 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-11-07 09:52 - 2014-01-16 23:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-07 09:40 - 2014-01-16 22:15 - 00000000 ___RD () C:\Documents and Settings\Jan Rukavička\Dokumenty
2014-11-07 09:37 - 2014-01-16 09:56 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-02 13:02 - 2014-01-16 23:01 - 00785792 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-24 20:06 - 2014-01-17 11:00 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\vlc
2014-10-24 16:14 - 2014-10-03 18:09 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Data aplikací\Seznam.cz
2014-10-24 15:26 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Vaudaix
2014-10-24 15:25 - 2014-09-14 17:21 - 00000406 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-10-24 15:25 - 2014-09-14 17:21 - 00000000 ____D () C:\Program Files\Vaudaix
2014-10-24 15:25 - 2014-09-14 17:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\8c4d112dfd1676b4
2014-10-24 15:18 - 2014-01-16 23:18 - 00000000 ____D () C:\Documents and Settings\Jan Rukavička\Local Settings\Data aplikací\GHISLER
2014-10-24 08:06 - 2014-02-14 09:35 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-24 08:04 - 2014-01-16 23:19 - 100290944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:40.01 GB) (Free:31.49 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:192.87 GB) (Free:75.71 GB) NTFS
Available physical RAM: 2528.7 MB
Total physical RAM: 2974.84 MB
Percentage of memory in use: 14%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 232.9 GB) (Disk ID: 1E06AC08)
Partition 1: (Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=192.9 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Low Battery Alarm Program.job => ?
Task: C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Jan Rukavika\Plocha" je 15 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel
C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
mnmsrvc REG_DWORD 0x3
avast! Antivirus REG_DWORD 0x2
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Jan Rukavika\\Plocha\\MyPhoneExplorer portable\\MyPhoneExplorer portable.exe"="C:\\Documents and Settings\\Jan Rukavika\\Plocha\\MyPhoneExplorer portable\\MyPhoneExplorer portable.exe:*:Enabled:MyPhoneExplorer"
"C:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer portable.exe"="C:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer portable.exe:*:Enabled:MyPhoneExplorer"
"C:\\Program Files\\Things & Stuff\\Touchpad Server\\TouchpadServer.exe"="C:\\Program Files\\Things & Stuff\\Touchpad Server\\TouchpadServer.exe:*:Enabled:Touchpad Server"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"="C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"="C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================