Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2015
Ran by HP (administrator) on HOVORCI on 11-06-2015 19:59:58
Running from C:\Documents and Settings\HP\Plocha
Loaded Profiles: HP (Available Profiles: HP & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\Program Files\UPHClean\uphclean.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [update] => wscript.exe //B "C:\DOCUME~1\HP\LOCALS~1\Temp\update.js" <===== ATTENTION
HKLM\...\Run: [system] => wscript.exe //B "C:\DOCUME~1\HP\LOCALS~1\Temp\system.js" <===== ATTENTION
HKU\S-1-5-21-790525478-117609710-839522115-1004\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-05-27] (Google Inc.)
HKU\S-1-5-21-790525478-117609710-839522115-1004\...\Run: [update] => wscript.exe //B "C:\DOCUME~1\HP\LOCALS~1\Temp\update.js" <===== ATTENTION
HKU\S-1-5-21-790525478-117609710-839522115-1004\...\Run: [system] => wscript.exe //B "C:\DOCUME~1\HP\LOCALS~1\Temp\system.js" <===== ATTENTION
HKU\S-1-5-21-790525478-117609710-839522115-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\System32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
Startup: C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění\system.js [2015-06-10] ()
Startup: C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění\update.js [2015-05-27] ()
BootExecute: autocheck autochk /p \??\D:autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-790525478-117609710-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll [2015-03-04] (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12] (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-12] (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupda ... 3448011171
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 3448054093
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}
http://office.microsoft.com/officeupdat ... /opuc4.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
FireFox:
========
FF ProfilePath: C:\Documents and Settings\HP\Data aplikací\Mozilla\Firefox\Profiles\uneb2417.default
FF Homepage: hxxp://
www.seznam.cz/
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2009-04-28] (Adobe Systems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-790525478-117609710-839522115-1004: @kb-ext.cz/PKIComponent -> C:\Documents and Settings\HP\Data aplikací\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll [2013-09-26] (Komerční banka, a.s.)
FF HKLM\...\Firefox\Extensions: [
jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-05-27]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2010-04-12] (Sun Microsystems, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 UPHClean; C:\Program Files\UPHClean\uphclean.exe [192573 2004-03-05] (Microsoft Corporation) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
S2 NvUpdSrv; C:\Program Files\NVIDIA Corporation\Updates\NvdUpd.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ac97intc; C:\WINDOWS\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 MpKsl58380f92; c:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{B1CCDD2D-845A-4D33-9C69-BED6CF6B3FA5}\MpKsl58380f92.sys [39464 2015-06-11] (Microsoft Corporation)
S3 nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [731648 2001-08-17] (NVIDIA Corporation)
R2 pmem; C:\WINDOWS\System32\DRIVERS\pmemnt.sys [7012 2004-08-02] (Microsoft Corporation)
S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
S1 aauupecj; \??\C:\WINDOWS\system32\drivers\aauupecj.sys [X]
S1 epkhjwrh; \??\C:\WINDOWS\system32\drivers\epkhjwrh.sys [X]
S1 gktuxbpi; \??\C:\WINDOWS\system32\drivers\gktuxbpi.sys [X]
S1 hjoqixaz; \??\C:\WINDOWS\system32\drivers\hjoqixaz.sys [X]
S4 hpt3xx; No ImagePath
S1 itovsago; \??\C:\WINDOWS\system32\drivers\itovsago.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]
S1 qumdevtt; \??\C:\WINDOWS\system32\drivers\qumdevtt.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S1 ussisyuc; \??\C:\WINDOWS\system32\drivers\ussisyuc.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 12:24 - 2015-06-11 12:24 - 00006081 _____ C:\Documents and Settings\HP\Plocha\Addition.rar
2015-06-11 12:08 - 2015-06-11 12:08 - 00047280 _____ C:\Documents and Settings\HP\Plocha\Addition.txt
2015-06-11 12:06 - 2015-06-11 20:00 - 00010050 _____ C:\Documents and Settings\HP\Plocha\FRST.txt
2015-06-11 12:06 - 2015-06-11 20:00 - 00000000 ____D C:\FRST
2015-06-11 12:05 - 2015-06-11 12:05 - 00029696 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
2015-06-11 12:05 - 2015-06-11 12:05 - 00015327 _____ C:\Documents and Settings\HP\Plocha\LM.bat
2015-06-11 12:04 - 2015-06-11 12:04 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\HP\Plocha\FRSTLauncher.exe
2015-06-11 12:03 - 2015-06-11 12:03 - 01147904 _____ (Farbar) C:\Documents and Settings\HP\Plocha\FRST.exe
2015-06-10 15:19 - 2015-06-10 15:22 - 00000000 ____D C:\KVRT_Data
2015-06-03 12:15 - 2015-06-04 21:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-02 23:33 - 2015-06-02 23:33 - 00002534 _____ C:\Documents and Settings\HP\Plocha\RKreport[8]_S_06022015_02d2333.txt
2015-06-02 23:23 - 2015-06-03 01:20 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\BCKP_USB
2015-05-17 02:39 - 2015-06-11 11:29 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d09039f6744036.job
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 20:00 - 2011-12-17 17:40 - 00000000 ____D C:\Documents and Settings\HP\Local Settings\Temp
2015-06-11 20:00 - 2009-05-27 19:45 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2015-06-11 19:58 - 2009-05-27 21:11 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{5D0B30D7-FF8F-4D24-92BE-6881A78A51DD}.job
2015-06-11 19:19 - 2011-12-21 01:27 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-11 18:58 - 2009-05-27 19:45 - 00032282 _____ C:\WINDOWS\SchedLgU.Txt
2015-06-11 12:24 - 2011-12-17 17:40 - 00000000 ____D C:\Documents and Settings\HP\Plocha
2015-06-11 12:05 - 2011-12-17 17:40 - 00000000 ___HD C:\Documents and Settings\HP\Local Settings\Data aplikací
2015-06-11 12:04 - 2015-02-22 00:59 - 00000000 ____D C:\Program Files\Instalačky
2015-06-11 11:41 - 2011-12-21 02:15 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Filmy
2015-06-11 11:39 - 2013-10-27 14:02 - 00000396 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2015-06-11 11:39 - 2012-07-16 01:46 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Hudba
2015-06-11 11:30 - 2009-05-27 21:33 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-06-11 11:30 - 2009-05-27 21:33 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-06-11 11:30 - 2009-05-27 20:11 - 01884384 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-11 11:30 - 2004-08-02 20:03 - 00004598 _____ C:\WINDOWS\system32\nvapps.xml
2015-06-11 11:30 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-06-11 11:29 - 2015-02-05 00:36 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040cbb27bfbc.job
2015-06-11 11:29 - 2014-09-04 13:58 - 00000356 _____ C:\WINDOWS\Tasks\{4F233664-495B-7CC4-096E-B162862A0B24}.job
2015-06-11 11:29 - 2011-12-21 01:27 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-11 11:29 - 2009-05-27 19:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-10 16:09 - 2015-02-11 00:30 - 00000000 ____D C:\WINDOWS\system32\NtmsData
2015-06-10 15:54 - 2011-12-17 17:40 - 00000000 ___RD C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění
2015-06-10 01:33 - 2001-10-25 14:00 - 00000554 _____ C:\WINDOWS\win.ini
2015-06-09 01:41 - 2011-12-17 17:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Obrázky
2015-06-08 15:00 - 2015-04-21 10:28 - 00000210 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2015-06-07 13:50 - 2014-11-13 22:31 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\MEDIC
2015-06-07 12:18 - 2014-04-23 01:44 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2015-06-07 12:05 - 2014-04-23 01:44 - 00000000 ____D C:\Documents and Settings\HP\Local Settings\Data aplikací\AskPartnerNetwork
2015-06-06 12:50 - 2009-05-27 20:06 - 00058299 _____ C:\WINDOWS\wmsetup.log
2015-06-06 12:47 - 2011-12-21 09:57 - 00140288 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-05 10:56 - 2015-03-09 00:51 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-06-03 01:15 - 2013-04-04 07:34 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-06-02 23:33 - 2013-05-04 04:15 - 00000000 ____D C:\Documents and Settings\HP\Plocha\RK_Quarantine
2015-06-02 23:23 - 2011-12-17 17:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty
2015-06-02 23:19 - 2009-05-27 21:31 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-06-02 23:18 - 2009-05-27 21:31 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start
2015-06-01 18:30 - 2011-12-17 17:40 - 00000000 ___RD C:\Documents and Settings\HP\Oblíbené položky
2015-05-18 02:03 - 2011-12-28 21:39 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-05-18 02:01 - 2012-01-20 20:25 - 00000000 ____D C:\Documents and Settings\HP\Data aplikací\foobar2000
2015-05-14 12:49 - 2013-09-21 23:54 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-05-14 12:38 - 2009-05-27 21:05 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2013-09-12 12:48 - 2013-09-12 13:00 - 0000004 _____ () C:\Documents and Settings\HP\Data aplikací\settings.ini
2011-12-21 09:57 - 2015-06-06 12:47 - 0140288 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-11 12:05 - 2015-06-11 12:05 - 0029696 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
Files to move or delete:
====================
C:\Windows\Tasks\{4F233664-495B-7CC4-096E-B162862A0B24}.job
Some files in TEMP:
====================
C:\Documents and Settings\HP\Local Settings\Temp\0GOzOLM.exe
C:\Documents and Settings\HP\Local Settings\Temp\GBCVD.EXE
C:\Documents and Settings\HP\Local Settings\Temp\HJKL.EXE
C:\Documents and Settings\HP\Local Settings\Temp\hjo.exe
C:\Documents and Settings\HP\Local Settings\Temp\KJKJH.EXE
C:\Documents and Settings\HP\Local Settings\Temp\LKO.EXE
C:\Documents and Settings\HP\Local Settings\Temp\MLK.EXE
C:\Documents and Settings\HP\Local Settings\Temp\NEventMessages.dll
C:\Documents and Settings\HP\Local Settings\Temp\NOSEventMessages.dll
C:\Documents and Settings\HP\Local Settings\Temp\PKIComponent-KBExt-setup.exe
C:\Documents and Settings\HP\Local Settings\Temp\Tierra.exe
C:\Documents and Settings\HP\Local Settings\Temp\~121.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================