virus - zablokoval mi super antispyware
Napsal: 17 úno 2015 00:27
Dobrý den, jsem tu zase s žádostí o pomoc.
Při vyhledávání gen. testu mě to poslalo nečekaně na porno stránku, okamžitě mi byl nahlášen virus, ale prý bloklý. Avast test ale ukázal, že je v PC. Nemámm ho jak sejmout, protože doposud fungující super antispyware mi nejde spustit, ani po reinstalaci, otevře se a ihned se zavře. Vše ostatní zatím funguje.
Vkládám FRST a moc děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01 (ATTENTION: ====> FRST version is 20 days old and could be outdated)
Ran by uzivatel (administrator) on NTBACER on 17-02-2015 00:18:34
Running from C:\Documents and Settings\uzivatel\Plocha
Loaded Profiles: uzivatel (Available profiles: uzivatel)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Lavasoft) C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Ad-Aware Browsing Protection] => C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [558672 2013-09-11] (Lavasoft)
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6699800 2015-01-22] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: [S-1-5-21-343818398-1547161642-1801674531-1003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\ujxhobqi.default-1423352464234
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @xstandard.com/XStandard -> C:\Program Files\XStandard\Bin\NPXStandard.dll (Belus Technology Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-05-08]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-10-08] (Oracle Corporation)
S3 CiSvc; %SystemRoot%\system32\cisvc.exe [X]
S4 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-24] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-24] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-24] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-24] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [423784 2014-11-24] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-24] ()
R2 Ethpdrv; C:\WINDOWS\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 IntcHdmiAddService; C:\WINDOWS\System32\drivers\IntcHdmi.sys [105984 2007-05-04] (Intel(R) Corporation) [File not signed]
S3 ipw_bus; C:\WINDOWS\System32\DRIVERS\ipw_bus.sys [58320 2005-09-27] (MCCI)
S3 ipw_mdfl; C:\WINDOWS\System32\DRIVERS\ipw_mdfl.sys [8272 2005-09-27] (MCCI)
S3 ipw_mdm; C:\WINDOWS\System32\DRIVERS\ipw_mdm.sys [95440 2005-09-27] (MCCI)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S4 IntelIde; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-17 00:18 - 2015-02-17 00:18 - 00009117 _____ () C:\Documents and Settings\uzivatel\Plocha\FRST.txt
2015-02-17 00:17 - 2015-02-17 00:18 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-02-17 00:17 - 2015-02-17 00:17 - 00001678 _____ () C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
2015-02-08 09:56 - 2015-02-09 07:18 - 00000516 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 3dc6b43c-7c9c-481a-982a-c600451c15b7.job
2015-02-08 09:56 - 2015-02-08 09:56 - 00000516 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task a636bf06-ae79-43f7-996c-386bc938bdbe.job
2015-02-08 00:41 - 2015-02-08 00:41 - 00000000 ____D () C:\Documents and Settings\uzivatel\Plocha\Původní data aplikace Firefox
2015-02-01 20:50 - 2015-02-01 20:50 - 00000000 ____D () C:\Documents and Settings\uzivatel\Data aplikací\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-02-01 20:49 - 2015-02-01 20:49 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-01-28 19:45 - 2015-02-17 00:18 - 00000000 ____D () C:\Documents and Settings\uzivatel\Local Settings\Temp
2015-01-27 22:15 - 2015-01-27 22:15 - 02194432 _____ () C:\Documents and Settings\uzivatel\Plocha\adwcleaner_4.109.exe
2015-01-26 20:28 - 2015-01-26 20:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-17 00:18 - 2013-10-02 09:43 - 00000000 ____D () C:\FRST
2015-02-17 00:18 - 2009-12-23 01:44 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2015-02-17 00:18 - 2009-12-23 00:59 - 00000000 ____D () C:\Documents and Settings\uzivatel\Plocha
2015-02-17 00:17 - 2009-12-23 01:44 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2015-02-17 00:14 - 2009-12-23 00:54 - 01841642 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-17 00:12 - 2009-12-23 01:48 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-02-17 00:12 - 2009-12-23 01:48 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-02-17 00:08 - 2009-12-23 00:59 - 00000272 ___SH () C:\Documents and Settings\uzivatel\ntuser.ini
2015-02-17 00:08 - 2009-12-23 00:59 - 00000000 ____D () C:\Documents and Settings\uzivatel
2015-02-16 23:16 - 2013-10-02 08:31 - 00000000 ____D () C:\AdwCleaner
2015-02-16 23:16 - 2010-03-14 13:26 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
2015-02-16 20:21 - 2009-12-23 00:59 - 00000000 ___RD () C:\Documents and Settings\uzivatel\Dokumenty
2015-02-16 12:48 - 2014-09-18 20:36 - 00002563 _____ () C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Word 2007.lnk
2015-02-16 09:48 - 2014-12-26 18:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection
2015-02-16 09:42 - 2001-10-25 17:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-02-15 22:38 - 2014-09-18 20:36 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt
2015-02-15 16:57 - 2014-09-18 20:36 - 00002477 _____ () C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Excel 2007.lnk
2015-02-10 13:55 - 2014-03-05 22:37 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\PRIVYDELKY
2015-02-10 13:55 - 2010-05-23 19:11 - 00149816 ____H () C:\treeinfo.wc
2015-02-10 13:54 - 2009-12-23 00:59 - 00000000 ___RD () C:\Documents and Settings\uzivatel\Dokumenty\Obrázky
2015-02-09 10:10 - 2010-01-15 17:29 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\works
2015-02-08 10:21 - 2009-12-23 02:12 - 00000000 ____D () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Adobe
2015-02-08 10:20 - 2013-03-18 22:31 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-08 10:20 - 2013-03-18 22:30 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-02-08 10:20 - 2011-05-23 07:40 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-02-08 10:10 - 2009-12-23 01:44 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-02-01 23:37 - 2014-03-02 14:10 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\www
2015-02-01 20:50 - 2009-12-23 00:59 - 00000000 __RHD () C:\Documents and Settings\uzivatel\Data aplikací
2015-02-01 20:49 - 2009-12-23 02:11 - 00000000 ____D () C:\Program Files\Adobe
2015-02-01 15:17 - 2014-05-07 18:38 - 00036363 _____ () C:\WINDOWS\CSTBox.INI
2015-01-28 19:37 - 2014-09-16 20:36 - 01121792 _____ (Farbar) C:\Documents and Settings\uzivatel\Plocha\FRST.exe
2015-01-27 22:19 - 2014-09-18 19:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-27 17:11 - 2011-08-06 10:24 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\prace
==================== Files in the root of some directories =======
2010-01-30 16:49 - 2012-03-16 08:31 - 0004397 _____ () C:\Documents and Settings\uzivatel\Data aplikací\HPCOM_48BitScanUpdate.log
2011-09-27 13:43 - 2011-09-27 13:43 - 0000268 ___RH () C:\Documents and Settings\uzivatel\Data aplikací\Sounds
2011-09-27 13:46 - 2012-01-04 22:20 - 0000000 _____ () C:\Documents and Settings\uzivatel\Data aplikací\Space Choir
2010-01-09 17:35 - 2013-09-28 00:21 - 0123392 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-16 22:03 - 2012-05-28 22:17 - 0002568 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).err
2011-10-16 20:28 - 2012-11-03 14:07 - 0001080 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).nast
2010-10-01 21:52 - 2012-08-10 17:48 - 0001064 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.err
2010-10-01 21:59 - 2012-08-10 20:39 - 0001120 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.nast
Some content of TEMP:
====================
C:\Documents and Settings\uzivatel\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\uzivatel\Local Settings\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Při vyhledávání gen. testu mě to poslalo nečekaně na porno stránku, okamžitě mi byl nahlášen virus, ale prý bloklý. Avast test ale ukázal, že je v PC. Nemámm ho jak sejmout, protože doposud fungující super antispyware mi nejde spustit, ani po reinstalaci, otevře se a ihned se zavře. Vše ostatní zatím funguje.
Vkládám FRST a moc děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01 (ATTENTION: ====> FRST version is 20 days old and could be outdated)
Ran by uzivatel (administrator) on NTBACER on 17-02-2015 00:18:34
Running from C:\Documents and Settings\uzivatel\Plocha
Loaded Profiles: uzivatel (Available profiles: uzivatel)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Lavasoft) C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Ad-Aware Browsing Protection] => C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [558672 2013-09-11] (Lavasoft)
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6699800 2015-01-22] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: [S-1-5-21-343818398-1547161642-1801674531-1003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\ujxhobqi.default-1423352464234
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @xstandard.com/XStandard -> C:\Program Files\XStandard\Bin\NPXStandard.dll (Belus Technology Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-05-08]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-10-08] (Oracle Corporation)
S3 CiSvc; %SystemRoot%\system32\cisvc.exe [X]
S4 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-24] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-24] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-24] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-24] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [423784 2014-11-24] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-24] ()
R2 Ethpdrv; C:\WINDOWS\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 IntcHdmiAddService; C:\WINDOWS\System32\drivers\IntcHdmi.sys [105984 2007-05-04] (Intel(R) Corporation) [File not signed]
S3 ipw_bus; C:\WINDOWS\System32\DRIVERS\ipw_bus.sys [58320 2005-09-27] (MCCI)
S3 ipw_mdfl; C:\WINDOWS\System32\DRIVERS\ipw_mdfl.sys [8272 2005-09-27] (MCCI)
S3 ipw_mdm; C:\WINDOWS\System32\DRIVERS\ipw_mdm.sys [95440 2005-09-27] (MCCI)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S4 IntelIde; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-17 00:18 - 2015-02-17 00:18 - 00009117 _____ () C:\Documents and Settings\uzivatel\Plocha\FRST.txt
2015-02-17 00:17 - 2015-02-17 00:18 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-02-17 00:17 - 2015-02-17 00:17 - 00001678 _____ () C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
2015-02-08 09:56 - 2015-02-09 07:18 - 00000516 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 3dc6b43c-7c9c-481a-982a-c600451c15b7.job
2015-02-08 09:56 - 2015-02-08 09:56 - 00000516 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task a636bf06-ae79-43f7-996c-386bc938bdbe.job
2015-02-08 00:41 - 2015-02-08 00:41 - 00000000 ____D () C:\Documents and Settings\uzivatel\Plocha\Původní data aplikace Firefox
2015-02-01 20:50 - 2015-02-01 20:50 - 00000000 ____D () C:\Documents and Settings\uzivatel\Data aplikací\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-02-01 20:49 - 2015-02-01 20:49 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-01-28 19:45 - 2015-02-17 00:18 - 00000000 ____D () C:\Documents and Settings\uzivatel\Local Settings\Temp
2015-01-27 22:15 - 2015-01-27 22:15 - 02194432 _____ () C:\Documents and Settings\uzivatel\Plocha\adwcleaner_4.109.exe
2015-01-26 20:28 - 2015-01-26 20:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-17 00:18 - 2013-10-02 09:43 - 00000000 ____D () C:\FRST
2015-02-17 00:18 - 2009-12-23 01:44 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2015-02-17 00:18 - 2009-12-23 00:59 - 00000000 ____D () C:\Documents and Settings\uzivatel\Plocha
2015-02-17 00:17 - 2009-12-23 01:44 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2015-02-17 00:14 - 2009-12-23 00:54 - 01841642 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-17 00:12 - 2009-12-23 01:48 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-02-17 00:12 - 2009-12-23 01:48 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-02-17 00:08 - 2009-12-23 00:59 - 00000272 ___SH () C:\Documents and Settings\uzivatel\ntuser.ini
2015-02-17 00:08 - 2009-12-23 00:59 - 00000000 ____D () C:\Documents and Settings\uzivatel
2015-02-16 23:16 - 2013-10-02 08:31 - 00000000 ____D () C:\AdwCleaner
2015-02-16 23:16 - 2010-03-14 13:26 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
2015-02-16 20:21 - 2009-12-23 00:59 - 00000000 ___RD () C:\Documents and Settings\uzivatel\Dokumenty
2015-02-16 12:48 - 2014-09-18 20:36 - 00002563 _____ () C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Word 2007.lnk
2015-02-16 09:48 - 2014-12-26 18:21 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection
2015-02-16 09:42 - 2001-10-25 17:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-02-15 22:38 - 2014-09-18 20:36 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt
2015-02-15 16:57 - 2014-09-18 20:36 - 00002477 _____ () C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Excel 2007.lnk
2015-02-10 13:55 - 2014-03-05 22:37 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\PRIVYDELKY
2015-02-10 13:55 - 2010-05-23 19:11 - 00149816 ____H () C:\treeinfo.wc
2015-02-10 13:54 - 2009-12-23 00:59 - 00000000 ___RD () C:\Documents and Settings\uzivatel\Dokumenty\Obrázky
2015-02-09 10:10 - 2010-01-15 17:29 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\works
2015-02-08 10:21 - 2009-12-23 02:12 - 00000000 ____D () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Adobe
2015-02-08 10:20 - 2013-03-18 22:31 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-08 10:20 - 2013-03-18 22:30 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-02-08 10:20 - 2011-05-23 07:40 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-02-08 10:10 - 2009-12-23 01:44 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-02-01 23:37 - 2014-03-02 14:10 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\www
2015-02-01 20:50 - 2009-12-23 00:59 - 00000000 __RHD () C:\Documents and Settings\uzivatel\Data aplikací
2015-02-01 20:49 - 2009-12-23 02:11 - 00000000 ____D () C:\Program Files\Adobe
2015-02-01 15:17 - 2014-05-07 18:38 - 00036363 _____ () C:\WINDOWS\CSTBox.INI
2015-01-28 19:37 - 2014-09-16 20:36 - 01121792 _____ (Farbar) C:\Documents and Settings\uzivatel\Plocha\FRST.exe
2015-01-27 22:19 - 2014-09-18 19:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-27 17:11 - 2011-08-06 10:24 - 00000000 ____D () C:\Documents and Settings\uzivatel\Dokumenty\prace
==================== Files in the root of some directories =======
2010-01-30 16:49 - 2012-03-16 08:31 - 0004397 _____ () C:\Documents and Settings\uzivatel\Data aplikací\HPCOM_48BitScanUpdate.log
2011-09-27 13:43 - 2011-09-27 13:43 - 0000268 ___RH () C:\Documents and Settings\uzivatel\Data aplikací\Sounds
2011-09-27 13:46 - 2012-01-04 22:20 - 0000000 _____ () C:\Documents and Settings\uzivatel\Data aplikací\Space Choir
2010-01-09 17:35 - 2013-09-28 00:21 - 0123392 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-16 22:03 - 2012-05-28 22:17 - 0002568 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).err
2011-10-16 20:28 - 2012-11-03 14:07 - 0001080 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).nast
2010-10-01 21:52 - 2012-08-10 17:48 - 0001064 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.err
2010-10-01 21:59 - 2012-08-10 20:39 - 0001120 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.nast
Some content of TEMP:
====================
C:\Documents and Settings\uzivatel\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\uzivatel\Local Settings\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================