kvalitně zpomalený počítač
Napsal: 20 pro 2014 13:54
Zdravím, jedná se o starší počítač, u kterého jsem odinstaloval antivir Comodo, protože prý je náročný na hardware. Také jsem zkusil odblešení pomocí Spyware hunter, ale počítač se o mnoho nezrychlil...
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2014
Ran by WarezBos (administrator) on WAREZ on 20-12-2014 13:44:11
Running from C:\Documents and Settings\WarezBos\Plocha
Loaded Profile: WarezBos (Available profiles: WarezBos)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
() C:\Program Files\ICQ6Toolbar\ICQ Service.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(forum.viry.cz) C:\Documents and Settings\WarezBos\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [19552872 2010-06-08] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [WinampAgent] => "C:\Program Files\Winamp\winampa.exe"
HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.)
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [mswnfceSrv] => "C:\WINDOWS\system32\mswnfce.vbe" msqrhaw msmjqdfw
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-19\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-19\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
HKU\S-1-5-20\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-20\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {138e984c-7712-11e0-9bfc-001583be5316} - L:\Launcher.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {153b7b3d-b3b9-11e0-9cb2-001583be5316} - L:\Launcher.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {7b97e57e-95a3-11e0-9c5d-001583be5316} - N:\PMBP_Win.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {ac9d7a44-4426-11e0-b4dc-806d6172696f} - E:\setup.exe
HKU\S-1-5-18\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-18\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1801674531-1220945662-725345543-500\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKU\S-1-5-21-1801674531-1220945662-725345543-500\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKU\S-1-5-21-1801674531-1220945662-725345543-500 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKU\S-1-5-21-1801674531-1220945662-725345543-500 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... vc1dmo.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: DVDIdleShell Class - {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll [49152 2004-10-09] (Fengtao Software Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default
FF DefaultSearchEngine: BS Player ControlBar Customized Web Search
FF SelectedSearchEngine: BS Player ControlBar Customized Web Search
FF Homepage: hxxp://search.conduit.com/?UM=4&ctid=CT1750559&SearchSource=13&CUI=UN80739689029148664
FF Keyword.URL: hxxp://trovi.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN80739689029148664&UM=4&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @protectdisc.com/NPMPDRM -> C:\Program Files\Common Files\mpDRM\Binaries\NPMPDRM.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\bs-player-controlbar-customized-web-search.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icq-search.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icqplugin.xml
FF Extension: BS Player ControlBar - C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2014-12-04]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-02]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-01]
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync [2012-09-12]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll No File
CHR Profile: C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-02]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-02]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-29]
CHR Extension: (Gmail) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-02]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2009-07-02] () [File not signed]
R2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [247096 2010-09-06] ()
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [170912 2013-03-11] (Oracle Corporation)
R2 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2014-01-09] (Enigma Software Group USA, LLC.)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [52224 2003-02-01] (Microsoft Corporation) [File not signed]
S3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
S3 ASNDIS5; C:\WINDOWS\system32\ASNDIS5.SYS [16269 2002-09-09] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [12288 2014-01-07] ()
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
R3 WmBEnum; C:\WINDOWS\System32\drivers\WmBEnum.sys [10144 2004-04-14] (Logitech Inc.)
S3 WmFilter; C:\WINDOWS\System32\drivers\WmFilter.sys [21280 2004-04-14] (Logitech Inc.)
S3 WmHidLo; C:\WINDOWS\System32\drivers\WmHidLo.sys [14432 2004-04-14] (Logitech Inc.)
S3 WmVirHid; C:\WINDOWS\System32\drivers\WmVirHid.sys [5600 2004-04-14] (Logitech Inc.)
R3 WmXlCore; C:\WINDOWS\System32\drivers\WmXlCore.sys [44064 2004-04-14] (Logitech Inc.)
S4 IntelIde; No ImagePath
S3 MSICDSetup; \??\E:\CDriver.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S0 sptd; System32\Drivers\sptd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-20 13:44 - 2014-12-20 13:44 - 00016905 _____ () C:\Documents and Settings\WarezBos\Plocha\FRST.txt
2014-12-20 13:31 - 2014-12-20 13:44 - 00000000 ____D () C:\FRST
2014-12-20 13:25 - 2014-12-20 13:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\WarezBos\Plocha\FRSTLauncher.exe
2014-12-20 13:23 - 2014-12-20 13:22 - 01114112 _____ (Farbar) C:\Documents and Settings\WarezBos\Plocha\FRST.exe
2014-12-14 21:49 - 2014-12-14 21:49 - 00001973 _____ () C:\Documents and Settings\WarezBos\Plocha\SpyHunter.lnk
2014-12-14 21:49 - 2014-12-14 21:49 - 00000000 ____D () C:\Documents and Settings\WarezBos\Nabídka Start\Programy\SpyHunter
2014-12-14 21:48 - 2014-12-14 21:49 - 00000000 ____D () C:\sh4ldr
2014-12-14 21:48 - 2014-12-14 21:48 - 00040835 _____ () C:\Documents and Settings\WarezBos\Dokumenty\pinfect.zip
2014-12-14 21:48 - 2014-12-14 21:48 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-12-14 21:46 - 2014-12-14 21:49 - 00000000 ____D () C:\WINDOWS\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\VDLL.DLL
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\system32\runouce.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\rundll16.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\RUNDL132.EXE
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\logo1_.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\logo_1.exe
2014-12-14 19:36 - 2014-12-14 19:36 - 00000028 _____ () C:\WINDOWS\Lic.xxx
2014-12-14 19:34 - 2014-12-14 19:34 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2014-12-14 19:34 - 2014-12-14 19:34 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2014-12-14 19:34 - 2014-12-14 19:34 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2014-12-14 19:34 - 2014-12-14 19:34 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2014-12-14 19:34 - 2008-04-14 08:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\REGEDIT.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\R.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TASKMGR.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\T.COM
2014-12-14 19:34 - 2005-09-22 23:22 - 00000522 _____ () C:\WINDOWS\system32\Microsoft.VC80.CRT.manifest
2014-12-14 19:33 - 2014-12-14 19:34 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2014-12-14 19:06 - 2014-12-14 21:44 - 00000000 ____D () C:\aaa
2014-12-14 18:10 - 2014-12-14 21:49 - 00010422 _____ () C:\WINDOWS\setupapi.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00006726 _____ () C:\WINDOWS\iis6.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00006183 _____ () C:\WINDOWS\FaxSetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002956 _____ () C:\WINDOWS\ocgen.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002821 _____ () C:\WINDOWS\tsoc.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002090 _____ () C:\WINDOWS\comsetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001948 _____ () C:\WINDOWS\msmqinst.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001265 _____ () C:\WINDOWS\ntdtcsetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001083 _____ () C:\WINDOWS\netfxocm.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000517 _____ () C:\WINDOWS\updspapi.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000425 _____ () C:\WINDOWS\MedCtrOC.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000386 _____ () C:\WINDOWS\ocmsn.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000309 _____ () C:\WINDOWS\msgsocm.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-12-06 11:08 - 2014-12-06 11:23 - 00005764 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-12-06 09:44 - 2014-12-06 10:20 - 00000000 ____D () C:\d694ea3129ded3d01311f5f1ec10e6
2014-12-02 15:20 - 2014-12-06 09:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-30 11:33 - 2014-12-16 16:24 - 01474832 _____ () C:\WINDOWS\system32\Drivers\sfi.dat
2014-11-30 11:28 - 2014-12-17 08:56 - 00000000 ____D () C:\Program Files\COMODO
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-20 13:44 - 2013-09-26 08:02 - 00000624 ____H () C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
2014-12-20 13:44 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos\Plocha
2014-12-20 13:44 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos\Local Settings\Temp
2014-12-20 13:43 - 2011-03-01 19:57 - 00000000 ___HD () C:\Documents and Settings\WarezBos\Local Settings\Data aplikací
2014-12-20 13:42 - 2012-01-18 23:04 - 01237707 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-20 13:42 - 2011-03-01 00:51 - 00262144 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-12-20 13:41 - 2014-03-23 15:05 - 00000228 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-12-20 13:41 - 2013-12-12 17:43 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef3fa402a6c7e.job
2014-12-20 13:41 - 2013-02-02 11:07 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-20 13:41 - 2011-03-01 18:33 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-12-20 13:41 - 2011-03-01 18:33 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-12-20 13:40 - 2011-03-01 19:57 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-20 13:39 - 2011-03-01 19:58 - 00000178 ___SH () C:\Documents and Settings\WarezBos\ntuser.ini
2014-12-20 13:39 - 2011-03-01 19:57 - 00032564 _____ () C:\WINDOWS\SchedLgU.Txt
2014-12-20 13:31 - 2013-02-02 11:07 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-20 13:21 - 2011-03-01 20:46 - 00002613 _____ () C:\WINDOWS\wincmd.ini
2014-12-20 13:02 - 2001-10-25 17:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-12-17 12:02 - 2012-03-15 16:39 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\BS_Player
2014-12-17 09:16 - 2013-08-17 17:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-12-17 08:56 - 2011-03-01 18:30 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-12-17 08:25 - 2011-03-01 18:23 - 00000000 ____D () C:\Program Files\ESET
2014-12-17 08:22 - 2012-01-20 11:38 - 109818608 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-12-16 16:23 - 2011-03-01 18:30 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-12-16 16:23 - 2011-03-01 18:30 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-12-16 10:27 - 2013-02-02 11:07 - 00001813 _____ () C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-12-16 10:21 - 2011-03-01 19:57 - 00001599 _____ () C:\Documents and Settings\WarezBos\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-12-16 09:42 - 2011-03-01 17:38 - 00001599 _____ () C:\Documents and Settings\Default User\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-12-16 09:41 - 2011-03-01 17:38 - 00001507 _____ () C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2014-12-14 21:49 - 2011-03-01 19:57 - 00000000 ___RD () C:\Documents and Settings\WarezBos\Nabídka Start\Programy
2014-12-14 21:48 - 2011-03-01 19:57 - 00000000 ___RD () C:\Documents and Settings\WarezBos\Dokumenty
2014-12-14 21:45 - 2013-06-03 18:01 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-12-14 18:43 - 2011-03-01 19:57 - 00000178 ___SH () C:\Documents and Settings\NetworkService\ntuser.ini
2014-12-07 20:21 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos
2014-12-07 08:48 - 2011-03-01 18:30 - 01022040 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-04 16:39 - 2011-03-11 22:17 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-12-02 17:34 - 2011-03-01 18:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-12-02 14:57 - 2011-03-14 09:23 - 00000000 ____D () C:\Documents and Settings\WarezBos\Data aplikací\Skype
2014-12-02 14:56 - 2013-01-28 16:59 - 00002283 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-11-30 10:19 - 2014-04-23 16:59 - 00524288 _____ () C:\WINDOWS\system32\config\COMODO I.evt
2014-11-30 08:51 - 2012-04-14 06:01 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-30 08:51 - 2011-07-13 07:34 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Documents and Settings\WarezBos\Local Settings\Temp\avxdisk.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdc.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdcore.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdfltlib.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdfltlib2k.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdupdateservice.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\DEVCON.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\download.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\eEmpty.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\encdec.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\esupdate.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\FSSync.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\Getvlist.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\ikave.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\ipc.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\kave.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\kavvlg.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\KK.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvclnt.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvcp80.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvcr80.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvl64.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvlclnt.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\MWAVL.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\MWAVReg.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\mwunzip.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\prLoader.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\red32.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\reload.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\scan.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\ScanningProcess.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\setpriv.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\test2.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\unregx.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\viewtcp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:78.83 GB) (Free:43.4 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:102.54 GB) (Free:29.24 GB) NTFS
Drive f: (USB) (Removable) (Total:3.74 GB) (Free:3.62 GB) FAT32
Available physical RAM: 666.5 MB
Total physical RAM: 1023.17 MB
Percentage of memory in use: 34%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 181.4 GB) (Disk ID: 958F958F)
Partition 1: (Active) - (Size=78.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=102.5 GB) - (Type=07 NTFS)
Disk: 5 (Size: 3.8 GB) (Disk ID: 6164662E)
Partition 1: (Not Active) - (Size=3.7 GB) - (Type=0B)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef3fa402a6c7e.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Norton Product InstallerIdle.job => C:\WINDOWS\system32\Adobe\Shockwave 12\SymInstallStub.exe
Task: C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\WarezBos\Plocha" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\ICQ7.4\\ICQ.exe"="C:\\Program Files\\ICQ7.4\\ICQ.exe:*:Enabled:ICQ7.4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"="C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\\Program Files\\ICQ7.4\\ICQ.exe"="C:\\Program Files\\ICQ7.4\\ICQ.exe:*:Enabled:ICQ7.4"
"C:\\Program Files\\MotoGP2\\motogp2.exe"="C:\\Program Files\\MotoGP2\\motogp2.exe:*:Enabled:motogp2"
"C:\\Program Files\\ABC\\Race\\Race.exe"="C:\\Program Files\\ABC\\Race\\Race.exe:*:Enabled:Race"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Games\\World_of_Tanks\\WoTLauncher.exe"="C:\\Games\\World_of_Tanks\\WoTLauncher.exe:*:Enabled:World of Tanks Launcher"
"C:\\Games\\World_of_Tanks\\WorldOfTanks.exe"="C:\\Games\\World_of_Tanks\\WorldOfTanks.exe:*:Enabled:World of Tanks"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"="C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\\Program Files\\Java\\jre7\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre7\\bin\\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\\Documents and Settings\\WarezBos\\Data aplikac\\uTorrent\\uTorrent.exe"="C:\\Documents and Settings\\WarezBos\\Data aplikac\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"="C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe:*:Enabled:Google Chrome"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2014
Ran by WarezBos (administrator) on WAREZ on 20-12-2014 13:44:11
Running from C:\Documents and Settings\WarezBos\Plocha
Loaded Profile: WarezBos (Available profiles: WarezBos)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
() C:\Program Files\ICQ6Toolbar\ICQ Service.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(forum.viry.cz) C:\Documents and Settings\WarezBos\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [19552872 2010-06-08] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [WinampAgent] => "C:\Program Files\Winamp\winampa.exe"
HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.)
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [mswnfceSrv] => "C:\WINDOWS\system32\mswnfce.vbe" msqrhaw msmjqdfw
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-19\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-19\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
HKU\S-1-5-20\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-20\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {138e984c-7712-11e0-9bfc-001583be5316} - L:\Launcher.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {153b7b3d-b3b9-11e0-9cb2-001583be5316} - L:\Launcher.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {7b97e57e-95a3-11e0-9c5d-001583be5316} - N:\PMBP_Win.exe
HKU\S-1-5-21-1801674531-1220945662-725345543-500\...\MountPoints2: {ac9d7a44-4426-11e0-b4dc-806d6172696f} - E:\setup.exe
HKU\S-1-5-18\...\RunOnce: [PackNoVs] => C:\WINDOWS\Packs\Crystal XP\PackSys.exe [81920 2004-11-21] (Home)
HKU\S-1-5-18\...\Policies\system: [SetVisualStyle] %SystemRoot%\Resources\Themes\Crystal dlb 2\Crystal dlb 2.msstyles
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1801674531-1220945662-725345543-500\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKU\S-1-5-21-1801674531-1220945662-725345543-500\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKU\S-1-5-21-1801674531-1220945662-725345543-500 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKU\S-1-5-21-1801674531-1220945662-725345543-500 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... vc1dmo.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: DVDIdleShell Class - {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll [49152 2004-10-09] (Fengtao Software Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default
FF DefaultSearchEngine: BS Player ControlBar Customized Web Search
FF SelectedSearchEngine: BS Player ControlBar Customized Web Search
FF Homepage: hxxp://search.conduit.com/?UM=4&ctid=CT1750559&SearchSource=13&CUI=UN80739689029148664
FF Keyword.URL: hxxp://trovi.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN80739689029148664&UM=4&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @protectdisc.com/NPMPDRM -> C:\Program Files\Common Files\mpDRM\Binaries\NPMPDRM.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\bs-player-controlbar-customized-web-search.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icq-search.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\searchplugins\icqplugin.xml
FF Extension: BS Player ControlBar - C:\Documents and Settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\4n0vuair.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2014-12-04]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-02]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-01]
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync [2012-09-12]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll No File
CHR Profile: C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-02]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-02]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-29]
CHR Extension: (Gmail) - C:\Documents and Settings\WarezBos\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-02]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2009-07-02] () [File not signed]
R2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [247096 2010-09-06] ()
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [170912 2013-03-11] (Oracle Corporation)
R2 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2014-01-09] (Enigma Software Group USA, LLC.)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [52224 2003-02-01] (Microsoft Corporation) [File not signed]
S3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
S3 ASNDIS5; C:\WINDOWS\system32\ASNDIS5.SYS [16269 2002-09-09] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [12288 2014-01-07] ()
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
R3 WmBEnum; C:\WINDOWS\System32\drivers\WmBEnum.sys [10144 2004-04-14] (Logitech Inc.)
S3 WmFilter; C:\WINDOWS\System32\drivers\WmFilter.sys [21280 2004-04-14] (Logitech Inc.)
S3 WmHidLo; C:\WINDOWS\System32\drivers\WmHidLo.sys [14432 2004-04-14] (Logitech Inc.)
S3 WmVirHid; C:\WINDOWS\System32\drivers\WmVirHid.sys [5600 2004-04-14] (Logitech Inc.)
R3 WmXlCore; C:\WINDOWS\System32\drivers\WmXlCore.sys [44064 2004-04-14] (Logitech Inc.)
S4 IntelIde; No ImagePath
S3 MSICDSetup; \??\E:\CDriver.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S0 sptd; System32\Drivers\sptd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-20 13:44 - 2014-12-20 13:44 - 00016905 _____ () C:\Documents and Settings\WarezBos\Plocha\FRST.txt
2014-12-20 13:31 - 2014-12-20 13:44 - 00000000 ____D () C:\FRST
2014-12-20 13:25 - 2014-12-20 13:25 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\WarezBos\Plocha\FRSTLauncher.exe
2014-12-20 13:23 - 2014-12-20 13:22 - 01114112 _____ (Farbar) C:\Documents and Settings\WarezBos\Plocha\FRST.exe
2014-12-14 21:49 - 2014-12-14 21:49 - 00001973 _____ () C:\Documents and Settings\WarezBos\Plocha\SpyHunter.lnk
2014-12-14 21:49 - 2014-12-14 21:49 - 00000000 ____D () C:\Documents and Settings\WarezBos\Nabídka Start\Programy\SpyHunter
2014-12-14 21:48 - 2014-12-14 21:49 - 00000000 ____D () C:\sh4ldr
2014-12-14 21:48 - 2014-12-14 21:48 - 00040835 _____ () C:\Documents and Settings\WarezBos\Dokumenty\pinfect.zip
2014-12-14 21:48 - 2014-12-14 21:48 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-12-14 21:46 - 2014-12-14 21:49 - 00000000 ____D () C:\WINDOWS\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\VDLL.DLL
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\system32\runouce.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\rundll16.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\RUNDL132.EXE
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\logo1_.exe
2014-12-14 19:41 - 2014-12-14 19:41 - 00000000 ____D () C:\WINDOWS\logo_1.exe
2014-12-14 19:36 - 2014-12-14 19:36 - 00000028 _____ () C:\WINDOWS\Lic.xxx
2014-12-14 19:34 - 2014-12-14 19:34 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2014-12-14 19:34 - 2014-12-14 19:34 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2014-12-14 19:34 - 2014-12-14 19:34 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2014-12-14 19:34 - 2014-12-14 19:34 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2014-12-14 19:34 - 2008-04-14 08:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\REGEDIT.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\R.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TASKMGR.COM
2014-12-14 19:34 - 2008-04-14 08:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\T.COM
2014-12-14 19:34 - 2005-09-22 23:22 - 00000522 _____ () C:\WINDOWS\system32\Microsoft.VC80.CRT.manifest
2014-12-14 19:33 - 2014-12-14 19:34 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2014-12-14 19:06 - 2014-12-14 21:44 - 00000000 ____D () C:\aaa
2014-12-14 18:10 - 2014-12-14 21:49 - 00010422 _____ () C:\WINDOWS\setupapi.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00006726 _____ () C:\WINDOWS\iis6.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00006183 _____ () C:\WINDOWS\FaxSetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002956 _____ () C:\WINDOWS\ocgen.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002821 _____ () C:\WINDOWS\tsoc.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00002090 _____ () C:\WINDOWS\comsetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001948 _____ () C:\WINDOWS\msmqinst.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001374 _____ () C:\WINDOWS\imsins.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001265 _____ () C:\WINDOWS\ntdtcsetup.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00001083 _____ () C:\WINDOWS\netfxocm.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000517 _____ () C:\WINDOWS\updspapi.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000425 _____ () C:\WINDOWS\MedCtrOC.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000386 _____ () C:\WINDOWS\ocmsn.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000309 _____ () C:\WINDOWS\msgsocm.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-12-06 11:23 - 2014-12-06 11:23 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-12-06 11:08 - 2014-12-06 11:23 - 00005764 _____ () C:\WINDOWS\KB2964358-IE8.log
2014-12-06 09:44 - 2014-12-06 10:20 - 00000000 ____D () C:\d694ea3129ded3d01311f5f1ec10e6
2014-12-02 15:20 - 2014-12-06 09:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-30 11:33 - 2014-12-16 16:24 - 01474832 _____ () C:\WINDOWS\system32\Drivers\sfi.dat
2014-11-30 11:28 - 2014-12-17 08:56 - 00000000 ____D () C:\Program Files\COMODO
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-20 13:44 - 2013-09-26 08:02 - 00000624 ____H () C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
2014-12-20 13:44 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos\Plocha
2014-12-20 13:44 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos\Local Settings\Temp
2014-12-20 13:43 - 2011-03-01 19:57 - 00000000 ___HD () C:\Documents and Settings\WarezBos\Local Settings\Data aplikací
2014-12-20 13:42 - 2012-01-18 23:04 - 01237707 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-20 13:42 - 2011-03-01 00:51 - 00262144 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-12-20 13:41 - 2014-03-23 15:05 - 00000228 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-12-20 13:41 - 2013-12-12 17:43 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef3fa402a6c7e.job
2014-12-20 13:41 - 2013-02-02 11:07 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-20 13:41 - 2011-03-01 18:33 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-12-20 13:41 - 2011-03-01 18:33 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-12-20 13:40 - 2011-03-01 19:57 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-20 13:39 - 2011-03-01 19:58 - 00000178 ___SH () C:\Documents and Settings\WarezBos\ntuser.ini
2014-12-20 13:39 - 2011-03-01 19:57 - 00032564 _____ () C:\WINDOWS\SchedLgU.Txt
2014-12-20 13:31 - 2013-02-02 11:07 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-20 13:21 - 2011-03-01 20:46 - 00002613 _____ () C:\WINDOWS\wincmd.ini
2014-12-20 13:02 - 2001-10-25 17:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-12-17 12:02 - 2012-03-15 16:39 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\BS_Player
2014-12-17 09:16 - 2013-08-17 17:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-12-17 08:56 - 2011-03-01 18:30 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-12-17 08:25 - 2011-03-01 18:23 - 00000000 ____D () C:\Program Files\ESET
2014-12-17 08:22 - 2012-01-20 11:38 - 109818608 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-12-16 16:23 - 2011-03-01 18:30 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-12-16 16:23 - 2011-03-01 18:30 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-12-16 10:27 - 2013-02-02 11:07 - 00001813 _____ () C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-12-16 10:21 - 2011-03-01 19:57 - 00001599 _____ () C:\Documents and Settings\WarezBos\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-12-16 09:42 - 2011-03-01 17:38 - 00001599 _____ () C:\Documents and Settings\Default User\Nabídka Start\Programy\Vzdálená pomoc.lnk
2014-12-16 09:41 - 2011-03-01 17:38 - 00001507 _____ () C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2014-12-14 21:49 - 2011-03-01 19:57 - 00000000 ___RD () C:\Documents and Settings\WarezBos\Nabídka Start\Programy
2014-12-14 21:48 - 2011-03-01 19:57 - 00000000 ___RD () C:\Documents and Settings\WarezBos\Dokumenty
2014-12-14 21:45 - 2013-06-03 18:01 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-12-14 18:43 - 2011-03-01 19:57 - 00000178 ___SH () C:\Documents and Settings\NetworkService\ntuser.ini
2014-12-07 20:21 - 2011-03-01 19:57 - 00000000 ____D () C:\Documents and Settings\WarezBos
2014-12-07 08:48 - 2011-03-01 18:30 - 01022040 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-04 16:39 - 2011-03-11 22:17 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-12-02 17:34 - 2011-03-01 18:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-12-02 14:57 - 2011-03-14 09:23 - 00000000 ____D () C:\Documents and Settings\WarezBos\Data aplikací\Skype
2014-12-02 14:56 - 2013-01-28 16:59 - 00002283 _____ () C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-11-30 10:19 - 2014-04-23 16:59 - 00524288 _____ () C:\WINDOWS\system32\config\COMODO I.evt
2014-11-30 08:51 - 2012-04-14 06:01 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-30 08:51 - 2011-07-13 07:34 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Documents and Settings\WarezBos\Local Settings\Temp\avxdisk.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdc.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdcore.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdfltlib.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdfltlib2k.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\bdupdateservice.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\DEVCON.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\download.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\eEmpty.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\encdec.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\esupdate.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\FSSync.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\Getvlist.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\ikave.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\ipc.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\kave.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\kavvlg.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\KK.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvclnt.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvcp80.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvcr80.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvl64.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\msvlclnt.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\MWAVL.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\MWAVReg.EXE
C:\Documents and Settings\WarezBos\Local Settings\Temp\mwunzip.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\prLoader.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\red32.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\reload.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\scan.dll
C:\Documents and Settings\WarezBos\Local Settings\Temp\ScanningProcess.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\setpriv.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\test2.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\unregx.exe
C:\Documents and Settings\WarezBos\Local Settings\Temp\viewtcp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:78.83 GB) (Free:43.4 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:102.54 GB) (Free:29.24 GB) NTFS
Drive f: (USB) (Removable) (Total:3.74 GB) (Free:3.62 GB) FAT32
Available physical RAM: 666.5 MB
Total physical RAM: 1023.17 MB
Percentage of memory in use: 34%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 181.4 GB) (Disk ID: 958F958F)
Partition 1: (Active) - (Size=78.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=102.5 GB) - (Type=07 NTFS)
Disk: 5 (Size: 3.8 GB) (Disk ID: 6164662E)
Partition 1: (Not Active) - (Size=3.7 GB) - (Type=0B)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef3fa402a6c7e.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Norton Product InstallerIdle.job => C:\WINDOWS\system32\Adobe\Shockwave 12\SymInstallStub.exe
Task: C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => C:\WINDOWS\system32\xp_eos.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\WarezBos\Plocha" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\ICQ7.4\\ICQ.exe"="C:\\Program Files\\ICQ7.4\\ICQ.exe:*:Enabled:ICQ7.4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"="C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\\Program Files\\ICQ7.4\\ICQ.exe"="C:\\Program Files\\ICQ7.4\\ICQ.exe:*:Enabled:ICQ7.4"
"C:\\Program Files\\MotoGP2\\motogp2.exe"="C:\\Program Files\\MotoGP2\\motogp2.exe:*:Enabled:motogp2"
"C:\\Program Files\\ABC\\Race\\Race.exe"="C:\\Program Files\\ABC\\Race\\Race.exe:*:Enabled:Race"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Games\\World_of_Tanks\\WoTLauncher.exe"="C:\\Games\\World_of_Tanks\\WoTLauncher.exe:*:Enabled:World of Tanks Launcher"
"C:\\Games\\World_of_Tanks\\WorldOfTanks.exe"="C:\\Games\\World_of_Tanks\\WorldOfTanks.exe:*:Enabled:World of Tanks"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"="C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\\Program Files\\Java\\jre7\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre7\\bin\\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\\Documents and Settings\\WarezBos\\Data aplikac\\uTorrent\\uTorrent.exe"="C:\\Documents and Settings\\WarezBos\\Data aplikac\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"="C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe:*:Enabled:Google Chrome"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================