
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Nejde nainstalovat Malwarebytes
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Nejde nainstalovat Malwarebytes
Dobrý den. Mám problém s intalací MBAM. Při instalaci vyhazuje hlášku, je v souboru.
Přikládám log z RSIT. Díky ralcar.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Radim at 2015-01-01 23:52:58
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 8 GB (7%) free of 114 GB
Total RAM: 2558 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:53:15, on 1.1.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Radim\Plocha\Mozilla Optimizer-extrémní zrychlení Firefoxu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Radim\Plocha\mbam-setup-2.0.4.1028.exe
C:\DOCUME~1\Radim\LOCALS~1\Temp\is-OPMJ2.tmp\mbam-setup-2.0.4.1028.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mspaint.exe
C:\Program Files\Microsoft Office\Office12\OIS.EXE
C:\PROGRA~1\MICROS~3\Office12\OIS.EXE
C:\PROGRA~1\MICROS~3\Office12\OIS.EXE
C:\Documents and Settings\Radim\Plocha\RSIT.exe
C:\Program Files\trend micro\Radim.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4879006000
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Serviio - Unknown owner - C:\Program Files\Serviio\bin\ServiioService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
--
End of file - 4723 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 951576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2012-11-27 393728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-23 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Aplikace\Balicky2013\jre\bin\java.exe"="C:\Aplikace\Balicky2013\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Serviio\bin\ServiioService.exe"="C:\Program Files\Serviio\bin\ServiioService.exe:*:Enabled:Serviio"
"C:\Program Files\Serviio\bin\ServiioConsole.exe"="C:\Program Files\Serviio\bin\ServiioConsole.exe:*:Enabled:Serviio"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Enabled:Logiciel de transfert de fichiers"
"C:\Program Files\yWorks\yEd\yEd.exe"="C:\Program Files\yWorks\yEd\yEd.exe:*:Disabled:yEd Graph Editor"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
======File associations======
.js - edit -
.js - open - "C:\Program Files\URUSoft\Subtitle Workshop\SubtitleWorkshop.exe" /OPEN("%1")
======List of files/folders created in the last 1 month======
2015-01-01 23:52:58 ----D---- C:\rsit
2015-01-01 23:10:50 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2015-01-01 23:10:50 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-01-01 23:10:50 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-12-30 18:28:03 ----D---- C:\Program Files\Zlodeji dusi
2014-12-19 17:42:05 ----D---- C:\Documents and Settings\Radim\Data aplikací\URSE Games
2014-12-19 17:39:22 ----D---- C:\Program Files\Profesor Gustav - Zlovestna trojice
2014-12-12 14:08:17 ----D---- C:\Program Files\Common Files\Java
2014-12-12 14:08:09 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-12-12 14:07:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Oracle
2014-12-09 23:50:27 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2014-12-09 10:58:29 ----D---- C:\Program Files\Mozilla Firefox
2014-12-08 12:59:53 ----A---- C:\AdwCleanerDebug.txt
2014-12-06 20:16:15 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
======List of files/folders modified in the last 1 month======
2015-01-01 23:53:15 ----D---- C:\Program Files\trend micro
2015-01-01 23:53:06 ----D---- C:\Documents and Settings\Radim\Data aplikací\uTorrent
2015-01-01 23:53:05 ----D---- C:\WINDOWS\Prefetch
2015-01-01 23:13:34 ----D---- C:\WINDOWS
2015-01-01 23:10:50 ----RD---- C:\Program Files
2015-01-01 23:10:50 ----D---- C:\WINDOWS\system32\drivers
2015-01-01 23:07:51 ----D---- C:\Filmy
2015-01-01 20:35:00 ----AD---- C:\Moje filmy
2015-01-01 20:30:58 ----D---- C:\Install
2015-01-01 13:42:03 ----D---- C:\WINDOWS\temp
2015-01-01 04:46:57 ----D---- C:\WINDOWS\system32\config
2014-12-30 18:29:40 ----D---- C:\Documents and Settings\Radim\Data aplikací\Specialbit
2014-12-29 00:11:49 ----D---- C:\Documents and Settings\Radim\Data aplikací\vlc
2014-12-28 18:56:53 ----SD---- C:\WINDOWS\Tasks
2014-12-25 02:48:50 ----D---- C:\Program Files\CCleaner
2014-12-25 02:43:10 ----D---- C:\Program Files\Glary Utilities 5
2014-12-21 14:17:52 ----D---- C:\WINDOWS\system32
2014-12-21 14:17:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-21 14:17:45 ----D---- C:\WINDOWS\system32\CatRoot2
2014-12-13 21:36:04 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-12 14:09:28 ----SHD---- C:\WINDOWS\Installer
2014-12-12 14:09:22 ----D---- C:\Program Files\Java
2014-12-12 14:08:17 ----D---- C:\Program Files\Common Files
2014-12-12 14:07:43 ----A---- C:\WINDOWS\system32\javaws.exe
2014-12-12 14:07:43 ----A---- C:\WINDOWS\system32\javaw.exe
2014-12-12 14:07:42 ----A---- C:\WINDOWS\system32\java.exe
2014-12-10 02:58:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-12-09 23:12:11 ----D---- C:\WINDOWS\system32\wbem
2014-12-09 23:12:11 ----D---- C:\WINDOWS\Registration
2014-12-08 13:40:29 ----SHD---- C:\System Volume Information
2014-12-08 13:40:29 ----D---- C:\WINDOWS\system32\Restore
2014-12-06 20:33:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\VSO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2011-07-18 432664]
R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2014-01-25 231960]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 GUBootStartup;GUBootStartup; \??\C:\WINDOWS\System32\drivers\GUBootStartup.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-23 1578496]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-08-30 6435432]
R3 NETw3x32;Ovladač adaptéru Intel(R) PRO/Wireless 3945ABG pro Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw3x32.sys [2006-09-27 1709696]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2005-09-30 78720]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-09-16 846792]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 MpKsl247733c8;MpKsl247733c8; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKsl247733c8.sys []
S1 MpKslb7b84e2a;MpKslb7b84e2a; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslb7b84e2a.sys []
S1 MpKslefaba5f7;MpKslefaba5f7; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslefaba5f7.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\WINDOWS\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\WINDOWS\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\WINDOWS\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-13 267440]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 22216]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Serviio;Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [2013-03-22 323584]
S3 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-23 409600]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
Přikládám log z RSIT. Díky ralcar.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Radim at 2015-01-01 23:52:58
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 8 GB (7%) free of 114 GB
Total RAM: 2558 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:53:15, on 1.1.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Radim\Plocha\Mozilla Optimizer-extrémní zrychlení Firefoxu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Radim\Plocha\mbam-setup-2.0.4.1028.exe
C:\DOCUME~1\Radim\LOCALS~1\Temp\is-OPMJ2.tmp\mbam-setup-2.0.4.1028.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mspaint.exe
C:\Program Files\Microsoft Office\Office12\OIS.EXE
C:\PROGRA~1\MICROS~3\Office12\OIS.EXE
C:\PROGRA~1\MICROS~3\Office12\OIS.EXE
C:\Documents and Settings\Radim\Plocha\RSIT.exe
C:\Program Files\trend micro\Radim.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4879006000
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Serviio - Unknown owner - C:\Program Files\Serviio\bin\ServiioService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
--
End of file - 4723 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 951576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2012-11-27 393728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-23 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Aplikace\Balicky2013\jre\bin\java.exe"="C:\Aplikace\Balicky2013\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Serviio\bin\ServiioService.exe"="C:\Program Files\Serviio\bin\ServiioService.exe:*:Enabled:Serviio"
"C:\Program Files\Serviio\bin\ServiioConsole.exe"="C:\Program Files\Serviio\bin\ServiioConsole.exe:*:Enabled:Serviio"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Enabled:Logiciel de transfert de fichiers"
"C:\Program Files\yWorks\yEd\yEd.exe"="C:\Program Files\yWorks\yEd\yEd.exe:*:Disabled:yEd Graph Editor"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
======File associations======
.js - edit -
.js - open - "C:\Program Files\URUSoft\Subtitle Workshop\SubtitleWorkshop.exe" /OPEN("%1")
======List of files/folders created in the last 1 month======
2015-01-01 23:52:58 ----D---- C:\rsit
2015-01-01 23:10:50 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2015-01-01 23:10:50 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-01-01 23:10:50 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-12-30 18:28:03 ----D---- C:\Program Files\Zlodeji dusi
2014-12-19 17:42:05 ----D---- C:\Documents and Settings\Radim\Data aplikací\URSE Games
2014-12-19 17:39:22 ----D---- C:\Program Files\Profesor Gustav - Zlovestna trojice
2014-12-12 14:08:17 ----D---- C:\Program Files\Common Files\Java
2014-12-12 14:08:09 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-12-12 14:07:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Oracle
2014-12-09 23:50:27 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2014-12-09 10:58:29 ----D---- C:\Program Files\Mozilla Firefox
2014-12-08 12:59:53 ----A---- C:\AdwCleanerDebug.txt
2014-12-06 20:16:15 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
======List of files/folders modified in the last 1 month======
2015-01-01 23:53:15 ----D---- C:\Program Files\trend micro
2015-01-01 23:53:06 ----D---- C:\Documents and Settings\Radim\Data aplikací\uTorrent
2015-01-01 23:53:05 ----D---- C:\WINDOWS\Prefetch
2015-01-01 23:13:34 ----D---- C:\WINDOWS
2015-01-01 23:10:50 ----RD---- C:\Program Files
2015-01-01 23:10:50 ----D---- C:\WINDOWS\system32\drivers
2015-01-01 23:07:51 ----D---- C:\Filmy
2015-01-01 20:35:00 ----AD---- C:\Moje filmy
2015-01-01 20:30:58 ----D---- C:\Install
2015-01-01 13:42:03 ----D---- C:\WINDOWS\temp
2015-01-01 04:46:57 ----D---- C:\WINDOWS\system32\config
2014-12-30 18:29:40 ----D---- C:\Documents and Settings\Radim\Data aplikací\Specialbit
2014-12-29 00:11:49 ----D---- C:\Documents and Settings\Radim\Data aplikací\vlc
2014-12-28 18:56:53 ----SD---- C:\WINDOWS\Tasks
2014-12-25 02:48:50 ----D---- C:\Program Files\CCleaner
2014-12-25 02:43:10 ----D---- C:\Program Files\Glary Utilities 5
2014-12-21 14:17:52 ----D---- C:\WINDOWS\system32
2014-12-21 14:17:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-21 14:17:45 ----D---- C:\WINDOWS\system32\CatRoot2
2014-12-13 21:36:04 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-12 14:09:28 ----SHD---- C:\WINDOWS\Installer
2014-12-12 14:09:22 ----D---- C:\Program Files\Java
2014-12-12 14:08:17 ----D---- C:\Program Files\Common Files
2014-12-12 14:07:43 ----A---- C:\WINDOWS\system32\javaws.exe
2014-12-12 14:07:43 ----A---- C:\WINDOWS\system32\javaw.exe
2014-12-12 14:07:42 ----A---- C:\WINDOWS\system32\java.exe
2014-12-10 02:58:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-12-09 23:12:11 ----D---- C:\WINDOWS\system32\wbem
2014-12-09 23:12:11 ----D---- C:\WINDOWS\Registration
2014-12-08 13:40:29 ----SHD---- C:\System Volume Information
2014-12-08 13:40:29 ----D---- C:\WINDOWS\system32\Restore
2014-12-06 20:33:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\VSO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2011-07-18 432664]
R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2014-01-25 231960]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 GUBootStartup;GUBootStartup; \??\C:\WINDOWS\System32\drivers\GUBootStartup.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-23 1578496]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-08-30 6435432]
R3 NETw3x32;Ovladač adaptéru Intel(R) PRO/Wireless 3945ABG pro Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw3x32.sys [2006-09-27 1709696]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2005-09-30 78720]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-09-16 846792]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 MpKsl247733c8;MpKsl247733c8; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKsl247733c8.sys []
S1 MpKslb7b84e2a;MpKslb7b84e2a; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslb7b84e2a.sys []
S1 MpKslefaba5f7;MpKslefaba5f7; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslefaba5f7.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\WINDOWS\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\WINDOWS\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\WINDOWS\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-13 267440]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 22216]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Serviio;Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [2013-03-22 323584]
S3 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-23 409600]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
- Přílohy
-
- Registry1.JPG.jpg (66.61 KiB) Zobrazeno 2444 x
Re: Nejde nainstalovat Malwarebytes
Zdravim 
Drzte se presne navodu! Win XP neni podporovan novou verzi 2.0



- Stahnete a nainstalujte MBAM 1.75 http://www.bleepingcomputer.com/downloa ... i-malware/
- na konci instalace zruste zatrzitko u polozky Povolit bezplatnou zkusebni verzi Malwarebytes Anti-Malware PRO
- ted je dulezity krok - stahuje se aktualizace celeho programu a na konci vyskoci hlaska - zvolte Cancel, pripadne Storno
- jako dalsi se sama stahla aktualizace virove databaze a dava Vam jedinou moznost -> OK
- opet je Vam nabizena aktualizace celeho programu -> zvolte opet Cancel
- v zalozce Kontrolor vyberte moznost Kompletni kontrola a kliknete na Prohledat
- po dokonceni skenovani, ktere se muze protahnout az na nekolik hodin, na Vas vyskoci log, ktery mi zkopirujte do pristi odpovedi... pripadne jej najdete v karte Slozka protokolu
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Nejde nainstalovat Malwarebytes
Log z Malwarebytes.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.04.04.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Radim :: 84B938A95D0145B [administrátor]
2.1.2015 18:13:36
MBAM-log-2015-01-02 (20-08-34).txt
Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 289329
Uplynulý čas: 1 hodin, 30 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Install\Revo Uninstaller Pro v2.5.1\Revo Uninstaller Pro v2.5.1\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
(konec)
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.04.04.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Radim :: 84B938A95D0145B [administrátor]
2.1.2015 18:13:36
MBAM-log-2015-01-02 (20-08-34).txt
Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 289329
Uplynulý čas: 1 hodin, 30 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Install\Revo Uninstaller Pro v2.5.1\Revo Uninstaller Pro v2.5.1\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
(konec)
Re: Nejde nainstalovat Malwarebytes


Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Nejde nainstalovat Malwarebytes
Problémy nejsou, tedy si myslím já. Kromě te instalace MBAM.
Těch hlášek tam, totiž bylo více, ale zachitil jsem jeom jednu.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-01-2015
Ran by Radim (administrator) on 84B938A95D0145B on 02-01-2015 20:36:52
Running from C:\Documents and Settings\Radim\Plocha
Loaded Profile: Radim (Available profiles: Radim & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ATICCC] => C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [45056 2006-01-02] (ATI Technologies Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\Run: [uTorrent] => C:\Program Files\uTorrent\uTorrent.exe [393728 2012-11-27] (BitTorrent, Inc.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> DefaultScope {D17E06F4-8FF1-4155-A33F-259C56A80459} URL = http://www.google.cz/search?q={searchTe ... AZ_csCZ451
SearchScopes: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> {D17E06F4-8FF1-4155-A33F-259C56A80459} URL = http://www.google.cz/search?q={searchTe ... AZ_csCZ451
Toolbar: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 172.22.52.5
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1708537768-1364589140-1177238915-1004: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1708537768-1364589140-1177238915-1004: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF user.js: detected! => C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js
FF Extension: Seznam lištička - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-11-27]
FF Extension: Adblock Plus - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-21]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-10]
Chrome:
=======
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-23]
CHR Extension: (Verbatim Translatio) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bobgnmijljonenlachekpkgikohcghon [2012-07-03]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-23]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-15]
CHR Extension: (No Name) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-23]
CHR StartMenuInternet: Google Chrome - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
S4 NwSapAgent; C:\WINDOWS\System32\ipxsap.dll [66560 2008-04-14] (Microsoft Corporation)
S3 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [323584 2013-03-22] () [File not signed]
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Aspi32; C:\WINDOWS\system32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec) [File not signed]
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [17344 2014-10-18] (Glarysoft Ltd)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 NETw3x32; C:\WINDOWS\System32\DRIVERS\NETw3x32.sys [1709696 2006-09-27] (Intel® Corporation)
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2008-04-14] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2008-04-14] (Microsoft Corporation)
S3 s0016bus; C:\WINDOWS\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\WINDOWS\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\WINDOWS\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\WINDOWS\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\WINDOWS\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\WINDOWS\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\WINDOWS\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation)
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2013-02-07] (Microsoft Corporation) [File not signed]
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S1 MpKsl247733c8; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKsl247733c8.sys [X]
S1 MpKslb7b84e2a; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslb7b84e2a.sys [X]
S1 MpKslefaba5f7; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslefaba5f7.sys [X]
U3 TlntSvr; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-02 20:36 - 2015-01-02 20:37 - 00013478 _____ () C:\Documents and Settings\Radim\Plocha\FRST.txt
2015-01-02 20:36 - 2015-01-02 20:36 - 00000000 ____D () C:\FRST
2015-01-02 20:33 - 2015-01-02 20:36 - 01115136 _____ (Farbar) C:\Documents and Settings\Radim\Plocha\FRST.exe
2015-01-02 18:06 - 2015-01-02 18:06 - 00000790 _____ () C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
2015-01-02 18:06 - 2015-01-02 18:06 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
2015-01-02 18:05 - 2015-01-02 18:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2015-01-02 18:05 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-02 15:02 - 2015-01-02 15:02 - 03502326 _____ () C:\Documents and Settings\Radim\Plocha\Produktové listy.zip
2015-01-02 15:01 - 2015-01-02 15:11 - 00032793 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-02 14:01 - 2015-01-02 14:02 - 00001730 _____ () C:\WINDOWS\wmsetup.log
2015-01-01 23:52 - 2015-01-01 23:53 - 00000000 ____D () C:\rsit
2015-01-01 23:52 - 2015-01-01 23:52 - 01107968 _____ () C:\Documents and Settings\Radim\Plocha\RSIT.exe
2015-01-01 23:44 - 2015-01-01 23:47 - 00512118 _____ () C:\Documents and Settings\Radim\Plocha\Bez názvu.bmp
2015-01-01 23:13 - 2015-01-01 23:13 - 00000159 ____N () C:\WINDOWS\wiadebug.log
2015-01-01 23:13 - 2015-01-01 23:13 - 00000048 ____N () C:\WINDOWS\wiaservc.log
2015-01-01 23:13 - 2015-01-01 23:13 - 00000000 ____N () C:\WINDOWS\Sti_Trace.log
2014-12-30 18:29 - 2014-12-30 18:29 - 00000736 _____ () C:\Documents and Settings\All Users\Plocha\Zloději duší.lnk
2014-12-30 18:29 - 2014-12-30 18:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Zloději duší
2014-12-30 18:28 - 2014-12-30 18:29 - 00000000 ____D () C:\Program Files\Zlodeji dusi
2014-12-19 17:42 - 2014-12-19 17:42 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\URSE Games
2014-12-19 17:41 - 2014-12-19 17:41 - 00001012 _____ () C:\Documents and Settings\All Users\Plocha\Profesor Gustav - Zlovestna trojice.lnk
2014-12-19 17:41 - 2014-12-19 17:41 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Profesor Gustav - Zlovestna trojice
2014-12-19 17:39 - 2014-12-19 17:41 - 00000000 ____D () C:\Program Files\Profesor Gustav - Zlovestna trojice
2014-12-17 12:49 - 2014-12-17 12:51 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\SOUHRNY A PŘÍLOHY K INFORMACÍM
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\Sun
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-12-12 14:08 - 2014-12-12 14:07 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-12-12 14:07 - 2014-12-12 15:00 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Oracle
2014-12-09 23:50 - 2014-12-09 23:50 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2014-12-09 20:08 - 2015-01-02 19:42 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-09 10:58 - 2014-12-09 23:11 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-08 13:41 - 2014-12-08 13:42 - 15201368 _____ () C:\Documents and Settings\Radim\Plocha\RogueKiller.exe
2014-12-08 12:59 - 2014-12-08 12:59 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 12:56 - 2014-12-08 12:56 - 02153472 _____ () C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe
2014-12-06 20:16 - 2014-12-12 07:23 - 03540144 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-02 20:37 - 2014-05-31 13:35 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\temp
2015-01-02 20:36 - 2011-09-10 13:05 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha
2015-01-02 20:33 - 2011-09-12 02:35 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\uTorrent
2015-01-02 20:33 - 2011-09-10 19:17 - 00000000 ____D () C:\Install
2015-01-02 18:06 - 2011-09-10 14:36 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-01-02 18:06 - 2011-09-10 14:36 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2015-01-02 17:59 - 2014-05-15 10:06 - 00000000 ____D () C:\Program Files\Glary Utilities 5
2015-01-02 17:59 - 2011-09-10 13:05 - 00000000 ___HD () C:\Documents and Settings\Radim\Šablony
2015-01-02 15:06 - 2014-05-31 13:35 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp
2015-01-02 14:53 - 2011-09-12 02:02 - 00002521 _____ () C:\Documents and Settings\Radim\Plocha\Microsoft Office Outlook 2007.lnk
2015-01-02 05:08 - 2011-09-10 18:11 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt
2015-01-02 05:08 - 2011-09-10 17:34 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt
2015-01-02 05:08 - 2011-09-10 13:25 - 00065536 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2015-01-02 05:08 - 2011-09-10 13:05 - 00000000 ____D () C:\Documents and Settings\Radim
2015-01-02 02:46 - 2011-09-10 18:30 - 00000000 ____D () C:\Filmy
2015-01-01 23:53 - 2014-02-07 18:08 - 00000000 ____D () C:\Program Files\trend micro
2015-01-01 23:43 - 2011-09-10 18:23 - 00000000 ___RD () C:\Documents and Settings\Radim\Dokumenty\Obrázky
2015-01-01 23:15 - 2012-11-23 18:01 - 00002435 _____ () C:\Documents and Settings\Radim\Plocha\Microsoft Office Picture Manager.lnk
2015-01-01 20:35 - 2011-09-10 19:31 - 00000000 ____D () C:\Moje filmy
2015-01-01 13:39 - 2011-09-10 13:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-01 13:39 - 2008-04-14 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-12-31 22:21 - 2012-04-27 13:00 - 00000000 ____D () C:\Documents and Settings\Radim\Dokumenty\CSOBPSmlouvy
2014-12-31 22:21 - 2011-09-13 09:49 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\ČSOB_Pojišťovna,_a.s
2014-12-31 21:42 - 2013-07-10 16:07 - 00032312 _____ () C:\WINDOWS\Tasks\SCHEDLGU.TXT
2014-12-30 18:29 - 2013-11-11 18:16 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\Specialbit
2014-12-29 00:11 - 2014-04-27 13:08 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\vlc
2014-12-28 19:06 - 2011-09-10 13:04 - 00000178 ___SH () C:\Documents and Settings\LocalService\ntuser.ini
2014-12-28 18:14 - 2011-09-10 13:05 - 00000178 ___SH () C:\Documents and Settings\Radim\ntuser.ini
2014-12-25 02:48 - 2014-03-04 02:07 - 00000688 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-12-25 02:48 - 2014-03-04 02:07 - 00000000 ____D () C:\Program Files\CCleaner
2014-12-25 02:43 - 2014-06-24 13:09 - 00000761 _____ () C:\Documents and Settings\All Users\Plocha\Glary Utilities 5.lnk
2014-12-25 02:43 - 2014-05-15 10:07 - 00000767 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 5.lnk
2014-12-21 14:17 - 2011-09-10 14:37 - 01191610 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-19 17:42 - 2011-09-10 13:05 - 00000000 __RHD () C:\Documents and Settings\Radim\Data aplikací
2014-12-17 12:53 - 2013-11-01 14:11 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\PPR a TRUMF
2014-12-14 17:38 - 2013-07-05 16:03 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\RECEPTY
2014-12-13 21:38 - 2011-09-10 14:36 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2014-12-13 21:38 - 2011-09-10 14:35 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-12-13 21:36 - 2012-04-11 12:43 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-13 21:36 - 2011-09-10 17:44 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\Adobe
2014-12-13 21:36 - 2011-09-10 16:24 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-12-12 14:09 - 2011-09-10 17:14 - 00000000 ____D () C:\Program Files\Java
2014-12-12 14:08 - 2011-09-10 13:05 - 00000000 ___HD () C:\Documents and Settings\Radim\Local Settings\Data aplikací
2014-12-12 14:07 - 2011-09-10 17:57 - 00272296 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-12-12 14:07 - 2011-09-10 17:57 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-12-12 14:07 - 2011-09-10 17:57 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-12-12 14:07 - 2011-09-10 17:14 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-12-12 04:34 - 2013-04-26 16:50 - 00000189 _____ () C:\.dir
2014-12-11 09:34 - 2014-02-13 10:37 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\Faktury internet
2014-12-11 09:32 - 2014-07-07 07:20 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\SIPO
2014-12-10 02:58 - 2011-09-10 17:31 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-12-09 23:12 - 2013-02-13 00:35 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-12-09 23:12 - 2011-09-10 13:04 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-12-09 23:12 - 2011-09-10 13:04 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-12-09 23:12 - 2011-09-10 12:57 - 00000000 ____D () C:\WINDOWS\Registration
2014-12-08 13:40 - 2011-09-10 12:57 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-12-08 13:23 - 2014-06-01 19:38 - 00165888 _____ () C:\Documents and Settings\Radim\Plocha\T-Cleaner.exe
2014-12-06 20:33 - 2012-11-28 22:35 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\VSO
Some content of TEMP:
====================
C:\Documents and Settings\Radim\Local Settings\temp\i4jd6764946741729054765.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-01-2015
Ran by Radim at 2015-01-02 20:37:45
Running from C:\Documents and Settings\Radim\Plocha
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Disabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKLM\...\uTorrent) (Version: 2.2.1 - )
ACDSee 32 (HKLM\...\ACDSee 32) (Version: - )
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Aktualizace systému Windows Internet Explorer 8 (KB2447568) (HKLM\...\KB2447568-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace systému Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace systému Windows Internet Explorer 8 (KB2632503) (HKLM\...\KB2632503-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2510531) (HKLM\...\KB2510531-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2544521) (HKLM\...\KB2544521-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2559049) (HKLM\...\KB2559049-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2586448) (HKLM\...\KB2586448-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2618444) (HKLM\...\KB2618444-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2647516) (HKLM\...\KB2647516-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2675157) (HKLM\...\KB2675157-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2699988) (HKLM\...\KB2699988-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2722913) (HKLM\...\KB2722913-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2744842) (HKLM\...\KB2744842-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2761465) (HKLM\...\KB2761465-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2792100) (HKLM\...\KB2792100-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2797052) (HKLM\...\KB2797052-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2799329) (HKLM\...\KB2799329-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2809289) (HKLM\...\KB2809289-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2817183) (HKLM\...\KB2817183-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2829530) (HKLM\...\KB2829530-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2838727) (HKLM\...\KB2838727-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2846071) (HKLM\...\KB2846071-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2847204) (HKLM\...\KB2847204-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2862772) (HKLM\...\KB2862772-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2870699) (HKLM\...\KB2870699-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2879017) (HKLM\...\KB2879017-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2888505) (HKLM\...\KB2888505-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2898785) (HKLM\...\KB2898785-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2909210) (HKLM\...\KB2909210-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2909921) (HKLM\...\KB2909921-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2925418) (HKLM\...\KB2925418-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2936068) (HKLM\...\KB2936068-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2964358) (HKLM\...\KB2964358-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB982381) (HKLM\...\KB982381-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows XP (KB923789) (HKLM\...\KB923789) (Version: - Microsoft Corporation)
ATI - Software Uninstall Utility (HKLM\...\All ATI Software) (Version: 6.14.10.1014 - )
ATI Catalyst Control Center (HKLM\...\{386B6902-74AD-4579-B0BF-8841E886F041}) (Version: 1.2.2334.37172 - )
ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.261-060523a1-033345C - )
ATI Parental Control & Encoder (HKLM\...\{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}) (Version: 3.0 - Název společnosti:)
aTube Catcher (HKLM\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp)
aTube Catcher verze 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
ČSOBP Balíčky 2013 (HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\ČSOB Pojišťovna Balíčky_is1) (Version: - ČSOB Pojišťovna)
ČSOBP Kalkulátory 1.14.3.x (HKLM\...\Kalkulátory_is1) (Version: - )
DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version: - DVD Shrink)
EVEREST Ultimate Edition v5.50 (HKLM\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
FormatFactory 2.70 (HKLM\...\FormatFactory) (Version: 2.70 - Free Time)
Glary Utilities PRO 5.15 (HKLM\...\Glary Utilities 5) (Version: 5.15.0.28 - Glarysoft Ltd)
Google Chrome (HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
K-Lite Codec Pack 7.5.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 7.5.0 - )
KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.9.1.129 - PandoraTV)
Malwarebytes Anti-Malware verze 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY (HKLM\...\{A2C9CD1B-2551-3AED-B244-6698FB929FA6}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY (HKLM\...\{546C143E-68DC-314D-97BC-1E454E3BA429}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Motorola SM56 Data Fax Modem (HKLM\...\SMSERIAL) (Version: - )
Mozilla Firefox 34.0.5 (x86 cs) (HKLM\...\Mozilla Firefox 34.0.5 (x86 cs)) (Version: 34.0.5 - Mozilla)
Nero 7 Premium (HKLM\...\{235BBFC6-D863-4066-A01A-3BD504C31029}) (Version: 7.02.2620 - Nero AG)
Profesor Gustav - Zlovestna trojice v1.0 (HKLM\...\{Profesor Gustav - Zlovestna trojice}_is1) (Version: - Špidla Data Processing, s.r.o.)
Readon TV Movie Radio Player 7.5.0.0 (HKLM\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.6449 - Realtek Semiconductor Corp.)
Sada Compatibility Pack pro systém Office 2007 (HKLM\...\{90120000-0020-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Serviio (HKLM\...\Serviio) (Version: - )
Sestry - spojeny krví v1.0 (HKLM\...\{Sestry - spojeny krvi}_is1) (Version: - Špidla Data Processing, s.r.o.)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.10.13089 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Sony PC Companion 2.10.228 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.228 - Sony)
StreamTransport version: 1.0.2.1931 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
Subtitle Workshop 2.51 (HKLM\...\SubtitleWorkshop) (Version: - )
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.50 beta 15 - Ghisler Software GmbH)
Ulož.to File Manager verze 1.6 (HKLM\...\{8190420D-F4BA-4744-8940-A466F81AF89C}_is1) (Version: 1.6 - Nodus Technologies s.r.o.)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version: - )
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 5.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
XML Paper Specification Shared Components Language Pack 1.0 (Version: - Microsoft Corporation) Hidden
Zloději duší v1.1 (HKLM\...\{Zlodeji dusi}_is1) (Version: - Špidla Data Processing, s.r.o.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\delegate_execute.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\psuser.dll (Google Inc.)
==================== Restore Points =========================
13-12-2014 14:44:05 Software Distribution Service 3.0
13-12-2014 21:38:41 Revo Uninstaller Pro's restore point - McAfee Security Scan Plus
14-12-2014 22:18:39 Kontrolní bod systému
15-12-2014 09:05:16 Software Distribution Service 3.0
15-12-2014 18:07:43 Software Distribution Service 3.0
16-12-2014 18:51:43 Kontrolní bod systému
17-12-2014 01:31:51 Software Distribution Service 3.0
18-12-2014 08:18:26 Software Distribution Service 3.0
19-12-2014 09:31:36 Software Distribution Service 3.0
21-12-2014 08:09:56 Software Distribution Service 3.0
22-12-2014 08:46:01 Software Distribution Service 3.0
24-12-2014 08:11:05 Software Distribution Service 3.0
25-12-2014 08:19:10 Software Distribution Service 3.0
26-12-2014 14:41:09 Software Distribution Service 3.0
27-12-2014 16:31:53 Kontrolní bod systému
27-12-2014 16:55:15 Software Distribution Service 3.0
28-12-2014 17:26:10 Software Distribution Service 3.0
29-12-2014 19:31:18 Software Distribution Service 3.0
30-12-2014 20:34:54 Kontrolní bod systému
31-12-2014 09:23:09 Software Distribution Service 3.0
01-01-2015 09:37:00 Software Distribution Service 3.0
01-01-2015 22:11:58 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 2.0.4.1028
02-01-2015 15:06:17 Software Distribution Service 3.0
02-01-2015 17:54:57 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 2.0.4.1028
02-01-2015 17:55:48 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 1.75.0.1300
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2008-04-14 13:00 - 2014-05-15 23:01 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-02-15 01:16 - 2013-10-30 09:54 - 00348160 _____ () C:\Program Files\WinRAR\rarlng.dll
2014-12-09 10:58 - 2014-12-09 10:59 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1708537768-1364589140-1177238915-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1708537768-1364589140-1177238915-1005 - Limited - Enabled)
Guest (S-1-5-21-1708537768-1364589140-1177238915-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1708537768-1364589140-1177238915-1000 - Limited - Disabled)
Radim (S-1-5-21-1708537768-1364589140-1177238915-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Radim
SUPPORT_388945a0 (S-1-5-21-1708537768-1364589140-1177238915-1002 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (01/02/2015 03:06:51 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Error: (01/02/2015 03:06:50 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Error: (01/02/2015 03:01:43 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Percentage of memory in use: 35%
Total physical RAM: 2558.11 MB
Available physical RAM: 1655.09 MB
Total Pagefile: 4445.75 MB
Available Pagefile: 3703.49 MB
Total Virtual: 2047.88 MB
Available Virtual: 1936.05 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:111.78 GB) (Free:11 GB) NTFS ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 111.8 GB) (Disk ID: 45248BED)
Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Těch hlášek tam, totiž bylo více, ale zachitil jsem jeom jednu.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-01-2015
Ran by Radim (administrator) on 84B938A95D0145B on 02-01-2015 20:36:52
Running from C:\Documents and Settings\Radim\Plocha
Loaded Profile: Radim (Available profiles: Radim & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ATICCC] => C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [45056 2006-01-02] (ATI Technologies Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\Run: [uTorrent] => C:\Program Files\uTorrent\uTorrent.exe [393728 2012-11-27] (BitTorrent, Inc.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> DefaultScope {D17E06F4-8FF1-4155-A33F-259C56A80459} URL = http://www.google.cz/search?q={searchTe ... AZ_csCZ451
SearchScopes: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> {D17E06F4-8FF1-4155-A33F-259C56A80459} URL = http://www.google.cz/search?q={searchTe ... AZ_csCZ451
Toolbar: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 172.22.52.5
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1708537768-1364589140-1177238915-1004: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1708537768-1364589140-1177238915-1004: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF user.js: detected! => C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js
FF Extension: Seznam lištička - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-11-27]
FF Extension: Adblock Plus - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-21]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-10]
Chrome:
=======
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-23]
CHR Extension: (Verbatim Translatio) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bobgnmijljonenlachekpkgikohcghon [2012-07-03]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-23]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-15]
CHR Extension: (No Name) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-23]
CHR StartMenuInternet: Google Chrome - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
S4 NwSapAgent; C:\WINDOWS\System32\ipxsap.dll [66560 2008-04-14] (Microsoft Corporation)
S3 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [323584 2013-03-22] () [File not signed]
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Aspi32; C:\WINDOWS\system32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec) [File not signed]
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [17344 2014-10-18] (Glarysoft Ltd)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 NETw3x32; C:\WINDOWS\System32\DRIVERS\NETw3x32.sys [1709696 2006-09-27] (Intel® Corporation)
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2008-04-14] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2008-04-14] (Microsoft Corporation)
S3 s0016bus; C:\WINDOWS\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\WINDOWS\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\WINDOWS\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\WINDOWS\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\WINDOWS\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\WINDOWS\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\WINDOWS\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation)
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2013-02-07] (Microsoft Corporation) [File not signed]
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S1 MpKsl247733c8; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKsl247733c8.sys [X]
S1 MpKslb7b84e2a; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslb7b84e2a.sys [X]
S1 MpKslefaba5f7; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{08E9A34C-0E96-4C8E-A50B-93CBD5B3F6C6}\MpKslefaba5f7.sys [X]
U3 TlntSvr; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-02 20:36 - 2015-01-02 20:37 - 00013478 _____ () C:\Documents and Settings\Radim\Plocha\FRST.txt
2015-01-02 20:36 - 2015-01-02 20:36 - 00000000 ____D () C:\FRST
2015-01-02 20:33 - 2015-01-02 20:36 - 01115136 _____ (Farbar) C:\Documents and Settings\Radim\Plocha\FRST.exe
2015-01-02 18:06 - 2015-01-02 18:06 - 00000790 _____ () C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
2015-01-02 18:06 - 2015-01-02 18:06 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
2015-01-02 18:05 - 2015-01-02 18:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2015-01-02 18:05 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-02 15:02 - 2015-01-02 15:02 - 03502326 _____ () C:\Documents and Settings\Radim\Plocha\Produktové listy.zip
2015-01-02 15:01 - 2015-01-02 15:11 - 00032793 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-02 14:01 - 2015-01-02 14:02 - 00001730 _____ () C:\WINDOWS\wmsetup.log
2015-01-01 23:52 - 2015-01-01 23:53 - 00000000 ____D () C:\rsit
2015-01-01 23:52 - 2015-01-01 23:52 - 01107968 _____ () C:\Documents and Settings\Radim\Plocha\RSIT.exe
2015-01-01 23:44 - 2015-01-01 23:47 - 00512118 _____ () C:\Documents and Settings\Radim\Plocha\Bez názvu.bmp
2015-01-01 23:13 - 2015-01-01 23:13 - 00000159 ____N () C:\WINDOWS\wiadebug.log
2015-01-01 23:13 - 2015-01-01 23:13 - 00000048 ____N () C:\WINDOWS\wiaservc.log
2015-01-01 23:13 - 2015-01-01 23:13 - 00000000 ____N () C:\WINDOWS\Sti_Trace.log
2014-12-30 18:29 - 2014-12-30 18:29 - 00000736 _____ () C:\Documents and Settings\All Users\Plocha\Zloději duší.lnk
2014-12-30 18:29 - 2014-12-30 18:29 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Zloději duší
2014-12-30 18:28 - 2014-12-30 18:29 - 00000000 ____D () C:\Program Files\Zlodeji dusi
2014-12-19 17:42 - 2014-12-19 17:42 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\URSE Games
2014-12-19 17:41 - 2014-12-19 17:41 - 00001012 _____ () C:\Documents and Settings\All Users\Plocha\Profesor Gustav - Zlovestna trojice.lnk
2014-12-19 17:41 - 2014-12-19 17:41 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Profesor Gustav - Zlovestna trojice
2014-12-19 17:39 - 2014-12-19 17:41 - 00000000 ____D () C:\Program Files\Profesor Gustav - Zlovestna trojice
2014-12-17 12:49 - 2014-12-17 12:51 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\SOUHRNY A PŘÍLOHY K INFORMACÍM
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\Sun
2014-12-12 14:08 - 2014-12-12 14:08 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-12-12 14:08 - 2014-12-12 14:07 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-12-12 14:07 - 2014-12-12 15:00 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Oracle
2014-12-09 23:50 - 2014-12-09 23:50 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2014-12-09 20:08 - 2015-01-02 19:42 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-09 10:58 - 2014-12-09 23:11 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-08 13:41 - 2014-12-08 13:42 - 15201368 _____ () C:\Documents and Settings\Radim\Plocha\RogueKiller.exe
2014-12-08 12:59 - 2014-12-08 12:59 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 12:56 - 2014-12-08 12:56 - 02153472 _____ () C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe
2014-12-06 20:16 - 2014-12-12 07:23 - 03540144 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-02 20:37 - 2014-05-31 13:35 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\temp
2015-01-02 20:36 - 2011-09-10 13:05 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha
2015-01-02 20:33 - 2011-09-12 02:35 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\uTorrent
2015-01-02 20:33 - 2011-09-10 19:17 - 00000000 ____D () C:\Install
2015-01-02 18:06 - 2011-09-10 14:36 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-01-02 18:06 - 2011-09-10 14:36 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2015-01-02 17:59 - 2014-05-15 10:06 - 00000000 ____D () C:\Program Files\Glary Utilities 5
2015-01-02 17:59 - 2011-09-10 13:05 - 00000000 ___HD () C:\Documents and Settings\Radim\Šablony
2015-01-02 15:06 - 2014-05-31 13:35 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp
2015-01-02 14:53 - 2011-09-12 02:02 - 00002521 _____ () C:\Documents and Settings\Radim\Plocha\Microsoft Office Outlook 2007.lnk
2015-01-02 05:08 - 2011-09-10 18:11 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt
2015-01-02 05:08 - 2011-09-10 17:34 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt
2015-01-02 05:08 - 2011-09-10 13:25 - 00065536 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2015-01-02 05:08 - 2011-09-10 13:05 - 00000000 ____D () C:\Documents and Settings\Radim
2015-01-02 02:46 - 2011-09-10 18:30 - 00000000 ____D () C:\Filmy
2015-01-01 23:53 - 2014-02-07 18:08 - 00000000 ____D () C:\Program Files\trend micro
2015-01-01 23:43 - 2011-09-10 18:23 - 00000000 ___RD () C:\Documents and Settings\Radim\Dokumenty\Obrázky
2015-01-01 23:15 - 2012-11-23 18:01 - 00002435 _____ () C:\Documents and Settings\Radim\Plocha\Microsoft Office Picture Manager.lnk
2015-01-01 20:35 - 2011-09-10 19:31 - 00000000 ____D () C:\Moje filmy
2015-01-01 13:39 - 2011-09-10 13:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-01 13:39 - 2008-04-14 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-12-31 22:21 - 2012-04-27 13:00 - 00000000 ____D () C:\Documents and Settings\Radim\Dokumenty\CSOBPSmlouvy
2014-12-31 22:21 - 2011-09-13 09:49 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\ČSOB_Pojišťovna,_a.s
2014-12-31 21:42 - 2013-07-10 16:07 - 00032312 _____ () C:\WINDOWS\Tasks\SCHEDLGU.TXT
2014-12-30 18:29 - 2013-11-11 18:16 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\Specialbit
2014-12-29 00:11 - 2014-04-27 13:08 - 00000000 ____D () C:\Documents and Settings\Radim\Data aplikací\vlc
2014-12-28 19:06 - 2011-09-10 13:04 - 00000178 ___SH () C:\Documents and Settings\LocalService\ntuser.ini
2014-12-28 18:14 - 2011-09-10 13:05 - 00000178 ___SH () C:\Documents and Settings\Radim\ntuser.ini
2014-12-25 02:48 - 2014-03-04 02:07 - 00000688 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-12-25 02:48 - 2014-03-04 02:07 - 00000000 ____D () C:\Program Files\CCleaner
2014-12-25 02:43 - 2014-06-24 13:09 - 00000761 _____ () C:\Documents and Settings\All Users\Plocha\Glary Utilities 5.lnk
2014-12-25 02:43 - 2014-05-15 10:07 - 00000767 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 5.lnk
2014-12-21 14:17 - 2011-09-10 14:37 - 01191610 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-19 17:42 - 2011-09-10 13:05 - 00000000 __RHD () C:\Documents and Settings\Radim\Data aplikací
2014-12-17 12:53 - 2013-11-01 14:11 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\PPR a TRUMF
2014-12-14 17:38 - 2013-07-05 16:03 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\RECEPTY
2014-12-13 21:38 - 2011-09-10 14:36 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2014-12-13 21:38 - 2011-09-10 14:35 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-12-13 21:36 - 2012-04-11 12:43 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-13 21:36 - 2011-09-10 17:44 - 00000000 ____D () C:\Documents and Settings\Radim\Local Settings\Data aplikací\Adobe
2014-12-13 21:36 - 2011-09-10 16:24 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-12-12 14:09 - 2011-09-10 17:14 - 00000000 ____D () C:\Program Files\Java
2014-12-12 14:08 - 2011-09-10 13:05 - 00000000 ___HD () C:\Documents and Settings\Radim\Local Settings\Data aplikací
2014-12-12 14:07 - 2011-09-10 17:57 - 00272296 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-12-12 14:07 - 2011-09-10 17:57 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-12-12 14:07 - 2011-09-10 17:57 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-12-12 14:07 - 2011-09-10 17:14 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-12-12 04:34 - 2013-04-26 16:50 - 00000189 _____ () C:\.dir
2014-12-11 09:34 - 2014-02-13 10:37 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\Faktury internet
2014-12-11 09:32 - 2014-07-07 07:20 - 00000000 ____D () C:\Documents and Settings\Radim\Plocha\SIPO
2014-12-10 02:58 - 2011-09-10 17:31 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-12-09 23:12 - 2013-02-13 00:35 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-12-09 23:12 - 2011-09-10 13:04 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-12-09 23:12 - 2011-09-10 13:04 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-12-09 23:12 - 2011-09-10 12:57 - 00000000 ____D () C:\WINDOWS\Registration
2014-12-08 13:40 - 2011-09-10 12:57 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-12-08 13:23 - 2014-06-01 19:38 - 00165888 _____ () C:\Documents and Settings\Radim\Plocha\T-Cleaner.exe
2014-12-06 20:33 - 2012-11-28 22:35 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\VSO
Some content of TEMP:
====================
C:\Documents and Settings\Radim\Local Settings\temp\i4jd6764946741729054765.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-01-2015
Ran by Radim at 2015-01-02 20:37:45
Running from C:\Documents and Settings\Radim\Plocha
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Disabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKLM\...\uTorrent) (Version: 2.2.1 - )
ACDSee 32 (HKLM\...\ACDSee 32) (Version: - )
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Aktualizace systému Windows Internet Explorer 8 (KB2447568) (HKLM\...\KB2447568-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace systému Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace systému Windows Internet Explorer 8 (KB2632503) (HKLM\...\KB2632503-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2510531) (HKLM\...\KB2510531-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2544521) (HKLM\...\KB2544521-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2559049) (HKLM\...\KB2559049-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2586448) (HKLM\...\KB2586448-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2618444) (HKLM\...\KB2618444-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2647516) (HKLM\...\KB2647516-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2675157) (HKLM\...\KB2675157-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2699988) (HKLM\...\KB2699988-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2722913) (HKLM\...\KB2722913-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2744842) (HKLM\...\KB2744842-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2761465) (HKLM\...\KB2761465-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2792100) (HKLM\...\KB2792100-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2797052) (HKLM\...\KB2797052-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2799329) (HKLM\...\KB2799329-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2809289) (HKLM\...\KB2809289-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2817183) (HKLM\...\KB2817183-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2829530) (HKLM\...\KB2829530-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2838727) (HKLM\...\KB2838727-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2846071) (HKLM\...\KB2846071-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2847204) (HKLM\...\KB2847204-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2862772) (HKLM\...\KB2862772-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2870699) (HKLM\...\KB2870699-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2879017) (HKLM\...\KB2879017-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2888505) (HKLM\...\KB2888505-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2898785) (HKLM\...\KB2898785-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2909210) (HKLM\...\KB2909210-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2909921) (HKLM\...\KB2909921-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2925418) (HKLM\...\KB2925418-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2936068) (HKLM\...\KB2936068-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2964358) (HKLM\...\KB2964358-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB982381) (HKLM\...\KB982381-IE8) (Version: 1 - Microsoft Corporation)
Aktualizace zabezpečení systému Windows XP (KB923789) (HKLM\...\KB923789) (Version: - Microsoft Corporation)
ATI - Software Uninstall Utility (HKLM\...\All ATI Software) (Version: 6.14.10.1014 - )
ATI Catalyst Control Center (HKLM\...\{386B6902-74AD-4579-B0BF-8841E886F041}) (Version: 1.2.2334.37172 - )
ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.261-060523a1-033345C - )
ATI Parental Control & Encoder (HKLM\...\{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}) (Version: 3.0 - Název společnosti:)
aTube Catcher (HKLM\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp)
aTube Catcher verze 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
ČSOBP Balíčky 2013 (HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\ČSOB Pojišťovna Balíčky_is1) (Version: - ČSOB Pojišťovna)
ČSOBP Kalkulátory 1.14.3.x (HKLM\...\Kalkulátory_is1) (Version: - )
DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version: - DVD Shrink)
EVEREST Ultimate Edition v5.50 (HKLM\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
FormatFactory 2.70 (HKLM\...\FormatFactory) (Version: 2.70 - Free Time)
Glary Utilities PRO 5.15 (HKLM\...\Glary Utilities 5) (Version: 5.15.0.28 - Glarysoft Ltd)
Google Chrome (HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
K-Lite Codec Pack 7.5.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 7.5.0 - )
KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.9.1.129 - PandoraTV)
Malwarebytes Anti-Malware verze 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY (HKLM\...\{A2C9CD1B-2551-3AED-B244-6698FB929FA6}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY (HKLM\...\{546C143E-68DC-314D-97BC-1E454E3BA429}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Motorola SM56 Data Fax Modem (HKLM\...\SMSERIAL) (Version: - )
Mozilla Firefox 34.0.5 (x86 cs) (HKLM\...\Mozilla Firefox 34.0.5 (x86 cs)) (Version: 34.0.5 - Mozilla)
Nero 7 Premium (HKLM\...\{235BBFC6-D863-4066-A01A-3BD504C31029}) (Version: 7.02.2620 - Nero AG)
Profesor Gustav - Zlovestna trojice v1.0 (HKLM\...\{Profesor Gustav - Zlovestna trojice}_is1) (Version: - Špidla Data Processing, s.r.o.)
Readon TV Movie Radio Player 7.5.0.0 (HKLM\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.6449 - Realtek Semiconductor Corp.)
Sada Compatibility Pack pro systém Office 2007 (HKLM\...\{90120000-0020-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Serviio (HKLM\...\Serviio) (Version: - )
Sestry - spojeny krví v1.0 (HKLM\...\{Sestry - spojeny krvi}_is1) (Version: - Špidla Data Processing, s.r.o.)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.10.13089 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Sony PC Companion 2.10.228 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.228 - Sony)
StreamTransport version: 1.0.2.1931 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
Subtitle Workshop 2.51 (HKLM\...\SubtitleWorkshop) (Version: - )
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.50 beta 15 - Ghisler Software GmbH)
Ulož.to File Manager verze 1.6 (HKLM\...\{8190420D-F4BA-4744-8940-A466F81AF89C}_is1) (Version: 1.6 - Nodus Technologies s.r.o.)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version: - )
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 5.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
XML Paper Specification Shared Components Language Pack 1.0 (Version: - Microsoft Corporation) Hidden
Zloději duší v1.1 (HKLM\...\{Zlodeji dusi}_is1) (Version: - Špidla Data Processing, s.r.o.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\delegate_execute.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1708537768-1364589140-1177238915-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.23.9\psuser.dll (Google Inc.)
==================== Restore Points =========================
13-12-2014 14:44:05 Software Distribution Service 3.0
13-12-2014 21:38:41 Revo Uninstaller Pro's restore point - McAfee Security Scan Plus
14-12-2014 22:18:39 Kontrolní bod systému
15-12-2014 09:05:16 Software Distribution Service 3.0
15-12-2014 18:07:43 Software Distribution Service 3.0
16-12-2014 18:51:43 Kontrolní bod systému
17-12-2014 01:31:51 Software Distribution Service 3.0
18-12-2014 08:18:26 Software Distribution Service 3.0
19-12-2014 09:31:36 Software Distribution Service 3.0
21-12-2014 08:09:56 Software Distribution Service 3.0
22-12-2014 08:46:01 Software Distribution Service 3.0
24-12-2014 08:11:05 Software Distribution Service 3.0
25-12-2014 08:19:10 Software Distribution Service 3.0
26-12-2014 14:41:09 Software Distribution Service 3.0
27-12-2014 16:31:53 Kontrolní bod systému
27-12-2014 16:55:15 Software Distribution Service 3.0
28-12-2014 17:26:10 Software Distribution Service 3.0
29-12-2014 19:31:18 Software Distribution Service 3.0
30-12-2014 20:34:54 Kontrolní bod systému
31-12-2014 09:23:09 Software Distribution Service 3.0
01-01-2015 09:37:00 Software Distribution Service 3.0
01-01-2015 22:11:58 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 2.0.4.1028
02-01-2015 15:06:17 Software Distribution Service 3.0
02-01-2015 17:54:57 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 2.0.4.1028
02-01-2015 17:55:48 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware verze 1.75.0.1300
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2008-04-14 13:00 - 2014-05-15 23:01 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-02-15 01:16 - 2013-10-30 09:54 - 00348160 _____ () C:\Program Files\WinRAR\rarlng.dll
2014-12-09 10:58 - 2014-12-09 10:59 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1708537768-1364589140-1177238915-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1708537768-1364589140-1177238915-1005 - Limited - Enabled)
Guest (S-1-5-21-1708537768-1364589140-1177238915-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1708537768-1364589140-1177238915-1000 - Limited - Disabled)
Radim (S-1-5-21-1708537768-1364589140-1177238915-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Radim
SUPPORT_388945a0 (S-1-5-21-1708537768-1364589140-1177238915-1002 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (01/02/2015 03:06:51 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Error: (01/02/2015 03:06:50 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Error: (01/02/2015 03:01:43 PM) (Source: Microsoft Antimalware) (EventID: 2041) (User: )
Description: Podpora pro váš operační systém vypršela. Používání součásti %%860 v operačním systému, který již není podporován, nepředstavuje adekvátní řešení ochrany před hrozbami.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Percentage of memory in use: 35%
Total physical RAM: 2558.11 MB
Available physical RAM: 1655.09 MB
Total Pagefile: 4445.75 MB
Available Pagefile: 3703.49 MB
Total Virtual: 2047.88 MB
Available Virtual: 1936.05 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:111.78 GB) (Free:11 GB) NTFS ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 111.8 GB) (Disk ID: 45248BED)
Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Re: Nejde nainstalovat Malwarebytes
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File FF user.js: detected! => C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js FF Extension: Seznam lištička - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-11-27] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09] CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Google Update) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File S4 IntelIde; No ImagePath U3 TlntSvr; No ImagePath 2015-01-02 20:36 - 2015-01-02 20:37 - 00013478 _____ () C:\Documents and Settings\Radim\Plocha\FRST.txt 2015-01-01 23:52 - 2015-01-01 23:53 - 00000000 ____D () C:\rsit 2015-01-01 23:52 - 2015-01-01 23:52 - 01107968 _____ () C:\Documents and Settings\Radim\Plocha\RSIT.exe 2014-12-08 13:41 - 2014-12-08 13:42 - 15201368 _____ () C:\Documents and Settings\Radim\Plocha\RogueKiller.exe 2014-12-08 12:59 - 2014-12-08 12:59 - 00000055 _____ () C:\AdwCleanerDebug.txt 2014-12-08 12:56 - 2014-12-08 12:56 - 02153472 _____ () C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe 2015-01-01 23:53 - 2014-02-07 18:08 - 00000000 ____D () C:\Program Files\trend micro Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Nejde nainstalovat Malwarebytes
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-01-2015
Ran by Radim at 2015-01-03 02:44:53 Run:1
Running from C:\Documents and Settings\Radim\Plocha
Loaded Profile: Radim (Available profiles: Radim & Administrator)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF user.js: detected! => C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js
FF Extension: Seznam lištička - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-11-27]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Google Update) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
S4 IntelIde; No ImagePath
U3 TlntSvr; No ImagePath
2015-01-02 20:36 - 2015-01-02 20:37 - 00013478 _____ () C:\Documents and Settings\Radim\Plocha\FRST.txt
2015-01-01 23:52 - 2015-01-01 23:53 - 00000000 ____D () C:\rsit
2015-01-01 23:52 - 2015-01-01 23:52 - 01107968 _____ () C:\Documents and Settings\Radim\Plocha\RSIT.exe
2014-12-08 13:41 - 2014-12-08 13:42 - 15201368 _____ () C:\Documents and Settings\Radim\Plocha\RogueKiller.exe
2014-12-08 12:59 - 2014-12-08 12:59 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 12:56 - 2014-12-08 12:56 - 02153472 _____ () C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe
2015-01-01 23:53 - 2014-02-07 18:08 - 00000000 ____D () C:\Program Files\trend micro
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation) => Value not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@java.com/JavaPlugin" => Key deleted successfully.
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js => Moved successfully.
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} => Moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll not found.
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll not found.
C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll not found.
C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll not found.
C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll not found.
C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found.
c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll not found.
IntelIde => Service deleted successfully.
TlntSvr => Service deleted successfully.
C:\Documents and Settings\Radim\Plocha\FRST.txt => Moved successfully.
C:\rsit => Moved successfully.
C:\Documents and Settings\Radim\Plocha\RSIT.exe => Moved successfully.
C:\Documents and Settings\Radim\Plocha\RogueKiller.exe => Moved successfully.
C:\AdwCleanerDebug.txt => Moved successfully.
C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 317.6 MB temporary data.
The system needed a reboot.
==== End of Fixlog 02:45:43 ====
Ran by Radim at 2015-01-03 02:44:53 Run:1
Running from C:\Documents and Settings\Radim\Plocha
Loaded Profile: Radim (Available profiles: Radim & Administrator)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF user.js: detected! => C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js
FF Extension: Seznam lištička - C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-11-27]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-09]
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Google Update) - C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
S4 IntelIde; No ImagePath
U3 TlntSvr; No ImagePath
2015-01-02 20:36 - 2015-01-02 20:37 - 00013478 _____ () C:\Documents and Settings\Radim\Plocha\FRST.txt
2015-01-01 23:52 - 2015-01-01 23:53 - 00000000 ____D () C:\rsit
2015-01-01 23:52 - 2015-01-01 23:52 - 01107968 _____ () C:\Documents and Settings\Radim\Plocha\RSIT.exe
2014-12-08 13:41 - 2014-12-08 13:42 - 15201368 _____ () C:\Documents and Settings\Radim\Plocha\RogueKiller.exe
2014-12-08 12:59 - 2014-12-08 12:59 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 12:56 - 2014-12-08 12:56 - 02153472 _____ () C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe
2015-01-01 23:53 - 2014-02-07 18:08 - 00000000 ____D () C:\Program Files\trend micro
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKLM\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation) => Value not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1708537768-1364589140-1177238915-1004\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@java.com/JavaPlugin" => Key deleted successfully.
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\user.js => Moved successfully.
C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\x5cv0bn6.default-1395370747187\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} => Moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Chrome\Application\34.0.1847.131\gcswf32.dll not found.
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll not found.
C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll not found.
C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll not found.
C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll not found.
C:\Documents and Settings\Radim\Local Settings\Data aplikací\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found.
c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll not found.
IntelIde => Service deleted successfully.
TlntSvr => Service deleted successfully.
C:\Documents and Settings\Radim\Plocha\FRST.txt => Moved successfully.
C:\rsit => Moved successfully.
C:\Documents and Settings\Radim\Plocha\RSIT.exe => Moved successfully.
C:\Documents and Settings\Radim\Plocha\RogueKiller.exe => Moved successfully.
C:\AdwCleanerDebug.txt => Moved successfully.
C:\Documents and Settings\Radim\Plocha\adwcleaner_4.104.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 317.6 MB temporary data.
The system needed a reboot.
==== End of Fixlog 02:45:43 ====
Re: Nejde nainstalovat Malwarebytes
Takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Nejde nainstalovat Malwarebytes
Díky moc a nashle.
Re: Nejde nainstalovat Malwarebytes
Nemate zac, rad jsem pomohl
Mejte se a treba zase nekdy

Mejte se a treba zase nekdy

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.