preventivní kontrola
Napsal: 06 črc 2015 12:39
Prosím o kontrolu, děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-07-2015
Ran by zakaznik (administrator) on USER on 06-07-2015 13:30:57
Running from C:\Documents and Settings\zakaznik\Plocha
Loaded Profiles: zakaznik (Available Profiles: zakaznik & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
(Comodo) C:\Program Files\Comodo\Dragon\dragon_updater.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
(Crawler Group) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Canon Inc.) C:\Program Files\Canon\CAL\CALMAIN.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(Crawler Group) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-08-13] (Check Point Software Technologies Ltd.)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777296 2012-09-07] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [5456720 2015-07-01] (Crawler Group)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25] (ATI Technologies Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2052111302-2077806209-1801674531-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2052111302-2077806209-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> {5C5360F5-5F2D-4E4A-84B1-ABD053DB35A9} URL =
SearchScopes: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> {A3DD4E2F-70A3-483C-93B4-99593AD1FF7B} URL = http://www.google.cz/search?q={searchTe ... {startPage}
Toolbar: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
Tcpip\..\Interfaces\{AF426A88-4E87-4378-A11C-AE6CA70FBAD9}: [DhcpNameServer] 94.74.192.252 94.74.192.244
FireFox:
========
FF ProfilePath: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default
FF Homepage: https://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_64.dll [2013-06-11] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer -> C:\Program Files\TVUPlayer\npTVUAx.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\doplky-pro-firefox.xml [2013-01-11]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-esk-republika---pouze-esky.xml [2013-12-02]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-esk-republika.xml [2013-12-02]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-peklada.xml [2013-01-11]
FF Extension: Zoom It - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{89462ae1-31da-02b6-5a69-6ff1eb34a9de} [2015-07-03]
FF Extension: Search Engine Sorting - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\sese@yasanori.xpi [2014-05-10]
FF Extension: Utopia FFSE White - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{20C3BDFF-DA68-468d-8D9A-F5A6C76B0F9E}.xpi [2011-12-24]
FF Extension: Adblock Plus - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-10-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268976 2015-07-03] (Adobe Systems Incorporated) [File not signed]
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2009-02-25] () [File not signed]
R2 CCALib8; C:\Program Files\Canon\CAL\CALMAIN.exe [96370 2007-01-31] (Canon Inc.) [File not signed]
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-26] (Comodo)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2009-10-17] (Macrovision Europe Ltd.) [File not signed]
R2 FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [217088 2010-11-15] (Teruten) [File not signed]
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [1998672 2015-07-01] (Crawler Group) [File not signed]
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3596752 2014-08-13] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [96272 2014-08-13] (Check Point Software Technologies, Ltd.)
S2 wmcmgc; C:\Program Files\Common Files\\System\icm64.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
S3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [20480 2005-05-31] (IVT Corporation) [File not signed]
S3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [10804 2005-04-30] (IVT Corporation) [File not signed]
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [23000 2005-05-31] (IVT Corporation) [File not signed]
S3 BTHidEnum; C:\WINDOWS\System32\DRIVERS\vbtenum.sys [11860 2005-04-30] () [File not signed]
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [28271 2005-04-30] (IVT Corporation) [File not signed]
S3 BTNetFilter; C:\WINDOWS\system32\drivers\BTNetFilter.sys [13304 2004-12-16] () [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 FETNDIS; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36640 2010-11-15] () [File not signed]
R0 KL1; C:\WINDOWS\System32\DRIVERS\kl1.sys [135776 2014-06-11] (Kaspersky Lab ZAO)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [483936 2014-06-11] (Kaspersky Lab ZAO)
S3 LUsbFilt; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [28816 2008-12-18] (Logitech, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 null_flt; C:\WINDOWS\System32\Drivers\null_flt.sys [4736 2009-11-12] (null_flt) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [721904 2009-10-21] () [File not signed]
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
S3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [61312 2004-10-19] (IVT Corporation) [File not signed]
S3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [82148 2005-03-25] (IVT Corporation) [File not signed]
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [534024 2014-08-13] (Check Point Software Technologies Ltd.)
U3 a97lg6k7; C:\WINDOWS\system32\Drivers\a97lg6k7.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S4 IntelIde; No ImagePath
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74336 2014-06-11] (Kaspersky Lab ZAO)
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVC: wmcmgc -> C:\Program Files\Common Files\\System\icm64.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-06 13:18 - 2015-07-06 13:31 - 00011997 _____ C:\Documents and Settings\zakaznik\Plocha\FRST.txt
2015-07-06 13:17 - 2015-07-06 13:31 - 00000000 ____D C:\FRST
2015-07-06 13:14 - 2015-07-06 13:14 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\zakaznik\Plocha\FRSTLauncher.exe
2015-07-06 13:13 - 2015-07-06 13:13 - 01636352 _____ (Farbar) C:\Documents and Settings\zakaznik\Plocha\FRST.exe
2015-07-05 16:02 - 2015-07-06 13:28 - 00000382 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1436104876.job
2015-07-05 16:01 - 2015-07-05 16:01 - 00000681 _____ C:\Documents and Settings\All Users\Plocha\Opera.lnk
2015-07-05 16:01 - 2015-07-05 16:01 - 00000681 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
2015-07-05 16:00 - 2015-07-06 13:28 - 00000000 ____D C:\Program Files\Opera
2015-07-05 15:56 - 2015-07-05 15:57 - 00000062 _____ C:\Documents and Settings\zakaznik\Plocha\debug.log
2015-07-03 23:44 - 2015-07-06 13:25 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-03 23:44 - 2015-07-04 15:43 - 00000958 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-07-03 23:17 - 2015-07-03 23:17 - 00102400 _____ C:\WINDOWS\Minidump\Mini070315-01.dmp
2015-07-03 23:17 - 2011-06-21 11:24 - 00032768 _____ C:\WINDOWS\system32\Drivers\sp_rsdrv2.sys
2015-07-03 23:13 - 2015-07-03 23:15 - 00000000 ____D C:\AdwCleaner
2015-07-03 22:59 - 2015-07-03 23:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malwa
2015-07-03 22:57 - 2015-07-03 22:57 - 00000426 _____ C:\Documents and Settings\zakaznik\Plocha\cc_20150703_225731.reg
2015-07-03 22:49 - 2015-07-03 22:49 - 00003630 _____ C:\Documents and Settings\zakaznik\Plocha\cc_20150703_224933.reg
2015-07-03 14:35 - 2015-07-05 16:02 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\Opera Software
2015-07-03 14:35 - 2015-07-05 15:57 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Opera Software
2015-07-03 14:05 - 2015-07-03 14:05 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\Fiery_Color_001-002.pdf-JPG
2015-07-03 14:02 - 2015-07-03 14:10 - 00000004 _____ C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-07-03 13:56 - 2015-07-03 13:56 - 00000000 ____D C:\Program Files\PDF Helper
2015-06-27 18:36 - 2015-06-27 18:36 - 00054841 _____ C:\Documents and Settings\zakaznik\Plocha\On-the-Edge(0000195345).srt
2015-06-24 23:18 - 2015-07-03 11:24 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-14 11:46 - 2015-06-14 11:49 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\Noc-je-ještě-mladá-(2011)-CZ-Dabing---M941
2015-06-14 10:58 - 2015-06-14 11:38 - 727056505 _____ C:\Documents and Settings\zakaznik\Plocha\Noc-je-ještě-mladá-(2011)-CZ-Dabing---M941.rar
2015-06-10 22:22 - 2015-06-10 22:22 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Comodo
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-06 13:31 - 2012-07-05 17:55 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\temp
2015-07-06 13:29 - 2009-06-01 17:55 - 01057244 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-06 13:28 - 2009-06-01 19:49 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-07-06 13:28 - 2009-06-01 19:49 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-07-06 13:28 - 2009-06-01 18:00 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-06 13:27 - 2009-06-01 18:01 - 00000178 ___SH C:\Documents and Settings\zakaznik\ntuser.ini
2015-07-06 13:27 - 2009-06-01 18:00 - 00032458 _____ C:\WINDOWS\SchedLgU.Txt
2015-07-06 13:26 - 2009-06-01 18:01 - 00000000 ____D C:\Documents and Settings\zakaznik
2015-07-06 13:18 - 2009-06-01 18:01 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha
2015-07-06 13:15 - 2014-10-25 10:18 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\firefox stažené
2015-07-06 12:49 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-05 16:01 - 2009-06-01 19:46 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-07-05 16:01 - 2009-06-01 19:46 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-07-04 10:48 - 2011-01-01 03:08 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Opera
2015-07-04 10:48 - 2011-01-01 03:08 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\Opera
2015-07-04 10:47 - 2014-12-17 12:02 - 00000000 ___RD C:\Program Files\Skype
2015-07-04 10:47 - 2009-09-23 13:21 - 00000000 ___RD C:\Person
2015-07-04 08:03 - 2010-03-05 09:15 - 00000000 ____D C:\Program Files\Google
2015-07-04 08:02 - 2010-03-05 09:15 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Google
2015-07-03 23:56 - 2009-06-01 18:01 - 00000000 ___HD C:\Documents and Settings\zakaznik\Local Settings\Data aplikací
2015-07-03 23:46 - 2009-06-06 13:13 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Adobe
2015-07-03 23:46 - 2009-06-01 18:01 - 00000000 ___RD C:\Documents and Settings\zakaznik\Dokumenty
2015-07-03 23:44 - 2013-06-11 15:22 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-03 23:44 - 2013-06-11 15:22 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-07-03 23:17 - 2009-10-01 13:30 - 00000000 ____D C:\WINDOWS\Minidump
2015-07-03 23:15 - 2009-06-01 19:46 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-07-03 23:11 - 2015-05-11 08:10 - 00000000 ____D C:\Program Files\SRWare Iron
2015-07-03 22:56 - 2014-10-29 13:49 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-07-03 22:48 - 2009-06-07 10:29 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\uTorrent
2015-07-03 15:43 - 2014-10-29 08:00 - 00000000 ____D C:\Documents and Settings\Administrator
2015-07-03 15:43 - 2009-06-01 18:00 - 00000000 __SHD C:\Documents and Settings\LocalService
2015-07-03 15:43 - 2009-06-01 17:59 - 00000000 __SHD C:\Documents and Settings\NetworkService
2015-07-03 15:42 - 2009-06-01 18:01 - 00000000 ___HD C:\Documents and Settings\zakaznik\Data aplikací
2015-07-03 15:42 - 2009-06-01 17:53 - 00000000 ____D C:\WINDOWS\Registration
2015-07-02 23:11 - 2014-12-25 13:26 - 00000000 ____D C:\Program Files\Spyware Terminator
2015-07-01 18:07 - 2014-12-25 13:28 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2015-06-24 23:21 - 2015-05-05 20:52 - 00000000 ____D C:\Program Files\Mozilla Firefox.bak
2015-06-10 22:22 - 2014-10-26 11:31 - 00000000 ____D C:\Program Files\Comodo
2015-06-10 22:21 - 2014-10-26 11:35 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\COMODO
==================== Files in the root of some directories =======
2009-06-01 19:40 - 2009-06-01 19:40 - 0000180 _____ () C:\Documents and Settings\zakaznik\Data aplikací\setup.log
2009-06-01 19:40 - 2009-06-01 20:10 - 0000760 _____ () C:\Documents and Settings\zakaznik\Data aplikací\setup_ldm.iss
2009-06-12 15:38 - 2014-02-05 18:15 - 0065536 _____ () C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\zakaznik\Local Settings\temp\8348.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\fsdE8.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\Quarantine.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-07-2015
Ran by zakaznik (administrator) on USER on 06-07-2015 13:30:57
Running from C:\Documents and Settings\zakaznik\Plocha
Loaded Profiles: zakaznik (Available Profiles: zakaznik & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
(Comodo) C:\Program Files\Comodo\Dragon\dragon_updater.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
(Crawler Group) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Canon Inc.) C:\Program Files\Canon\CAL\CALMAIN.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(Crawler Group) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-08-13] (Check Point Software Technologies Ltd.)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777296 2012-09-07] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [5456720 2015-07-01] (Crawler Group)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25] (ATI Technologies Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2052111302-2077806209-1801674531-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2052111302-2077806209-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> {5C5360F5-5F2D-4E4A-84B1-ABD053DB35A9} URL =
SearchScopes: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> {A3DD4E2F-70A3-483C-93B4-99593AD1FF7B} URL = http://www.google.cz/search?q={searchTe ... {startPage}
Toolbar: HKU\S-1-5-21-2052111302-2077806209-1801674531-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
Tcpip\..\Interfaces\{AF426A88-4E87-4378-A11C-AE6CA70FBAD9}: [DhcpNameServer] 94.74.192.252 94.74.192.244
FireFox:
========
FF ProfilePath: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default
FF Homepage: https://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_64.dll [2013-06-11] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer -> C:\Program Files\TVUPlayer\npTVUAx.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\doplky-pro-firefox.xml [2013-01-11]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-esk-republika---pouze-esky.xml [2013-12-02]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-esk-republika.xml [2013-12-02]
FF SearchPlugin: C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\searchplugins\google-peklada.xml [2013-01-11]
FF Extension: Zoom It - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{89462ae1-31da-02b6-5a69-6ff1eb34a9de} [2015-07-03]
FF Extension: Search Engine Sorting - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\sese@yasanori.xpi [2014-05-10]
FF Extension: Utopia FFSE White - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{20C3BDFF-DA68-468d-8D9A-F5A6C76B0F9E}.xpi [2011-12-24]
FF Extension: Adblock Plus - C:\Documents and Settings\zakaznik\Data aplikací\Mozilla\Firefox\Profiles\s2ej2umb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-10-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268976 2015-07-03] (Adobe Systems Incorporated) [File not signed]
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2009-02-25] () [File not signed]
R2 CCALib8; C:\Program Files\Canon\CAL\CALMAIN.exe [96370 2007-01-31] (Canon Inc.) [File not signed]
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-26] (Comodo)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2009-10-17] (Macrovision Europe Ltd.) [File not signed]
R2 FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [217088 2010-11-15] (Teruten) [File not signed]
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [1998672 2015-07-01] (Crawler Group) [File not signed]
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3596752 2014-08-13] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [96272 2014-08-13] (Check Point Software Technologies, Ltd.)
S2 wmcmgc; C:\Program Files\Common Files\\System\icm64.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
S3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [20480 2005-05-31] (IVT Corporation) [File not signed]
S3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [10804 2005-04-30] (IVT Corporation) [File not signed]
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [23000 2005-05-31] (IVT Corporation) [File not signed]
S3 BTHidEnum; C:\WINDOWS\System32\DRIVERS\vbtenum.sys [11860 2005-04-30] () [File not signed]
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [28271 2005-04-30] (IVT Corporation) [File not signed]
S3 BTNetFilter; C:\WINDOWS\system32\drivers\BTNetFilter.sys [13304 2004-12-16] () [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 FETNDIS; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36640 2010-11-15] () [File not signed]
R0 KL1; C:\WINDOWS\System32\DRIVERS\kl1.sys [135776 2014-06-11] (Kaspersky Lab ZAO)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [483936 2014-06-11] (Kaspersky Lab ZAO)
S3 LUsbFilt; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [28816 2008-12-18] (Logitech, Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 null_flt; C:\WINDOWS\System32\Drivers\null_flt.sys [4736 2009-11-12] (null_flt) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [721904 2009-10-21] () [File not signed]
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
S3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [61312 2004-10-19] (IVT Corporation) [File not signed]
S3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [82148 2005-03-25] (IVT Corporation) [File not signed]
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [534024 2014-08-13] (Check Point Software Technologies Ltd.)
U3 a97lg6k7; C:\WINDOWS\system32\Drivers\a97lg6k7.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S4 IntelIde; No ImagePath
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74336 2014-06-11] (Kaspersky Lab ZAO)
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVC: wmcmgc -> C:\Program Files\Common Files\\System\icm64.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-06 13:18 - 2015-07-06 13:31 - 00011997 _____ C:\Documents and Settings\zakaznik\Plocha\FRST.txt
2015-07-06 13:17 - 2015-07-06 13:31 - 00000000 ____D C:\FRST
2015-07-06 13:14 - 2015-07-06 13:14 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\zakaznik\Plocha\FRSTLauncher.exe
2015-07-06 13:13 - 2015-07-06 13:13 - 01636352 _____ (Farbar) C:\Documents and Settings\zakaznik\Plocha\FRST.exe
2015-07-05 16:02 - 2015-07-06 13:28 - 00000382 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1436104876.job
2015-07-05 16:01 - 2015-07-05 16:01 - 00000681 _____ C:\Documents and Settings\All Users\Plocha\Opera.lnk
2015-07-05 16:01 - 2015-07-05 16:01 - 00000681 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
2015-07-05 16:00 - 2015-07-06 13:28 - 00000000 ____D C:\Program Files\Opera
2015-07-05 15:56 - 2015-07-05 15:57 - 00000062 _____ C:\Documents and Settings\zakaznik\Plocha\debug.log
2015-07-03 23:44 - 2015-07-06 13:25 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-03 23:44 - 2015-07-04 15:43 - 00000958 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-07-03 23:17 - 2015-07-03 23:17 - 00102400 _____ C:\WINDOWS\Minidump\Mini070315-01.dmp
2015-07-03 23:17 - 2011-06-21 11:24 - 00032768 _____ C:\WINDOWS\system32\Drivers\sp_rsdrv2.sys
2015-07-03 23:13 - 2015-07-03 23:15 - 00000000 ____D C:\AdwCleaner
2015-07-03 22:59 - 2015-07-03 23:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malwa
2015-07-03 22:57 - 2015-07-03 22:57 - 00000426 _____ C:\Documents and Settings\zakaznik\Plocha\cc_20150703_225731.reg
2015-07-03 22:49 - 2015-07-03 22:49 - 00003630 _____ C:\Documents and Settings\zakaznik\Plocha\cc_20150703_224933.reg
2015-07-03 14:35 - 2015-07-05 16:02 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\Opera Software
2015-07-03 14:35 - 2015-07-05 15:57 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Opera Software
2015-07-03 14:05 - 2015-07-03 14:05 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\Fiery_Color_001-002.pdf-JPG
2015-07-03 14:02 - 2015-07-03 14:10 - 00000004 _____ C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-07-03 13:56 - 2015-07-03 13:56 - 00000000 ____D C:\Program Files\PDF Helper
2015-06-27 18:36 - 2015-06-27 18:36 - 00054841 _____ C:\Documents and Settings\zakaznik\Plocha\On-the-Edge(0000195345).srt
2015-06-24 23:18 - 2015-07-03 11:24 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-14 11:46 - 2015-06-14 11:49 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\Noc-je-ještě-mladá-(2011)-CZ-Dabing---M941
2015-06-14 10:58 - 2015-06-14 11:38 - 727056505 _____ C:\Documents and Settings\zakaznik\Plocha\Noc-je-ještě-mladá-(2011)-CZ-Dabing---M941.rar
2015-06-10 22:22 - 2015-06-10 22:22 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Comodo
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-06 13:31 - 2012-07-05 17:55 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\temp
2015-07-06 13:29 - 2009-06-01 17:55 - 01057244 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-06 13:28 - 2009-06-01 19:49 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-07-06 13:28 - 2009-06-01 19:49 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-07-06 13:28 - 2009-06-01 18:00 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-06 13:27 - 2009-06-01 18:01 - 00000178 ___SH C:\Documents and Settings\zakaznik\ntuser.ini
2015-07-06 13:27 - 2009-06-01 18:00 - 00032458 _____ C:\WINDOWS\SchedLgU.Txt
2015-07-06 13:26 - 2009-06-01 18:01 - 00000000 ____D C:\Documents and Settings\zakaznik
2015-07-06 13:18 - 2009-06-01 18:01 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha
2015-07-06 13:15 - 2014-10-25 10:18 - 00000000 ____D C:\Documents and Settings\zakaznik\Plocha\firefox stažené
2015-07-06 12:49 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-05 16:01 - 2009-06-01 19:46 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-07-05 16:01 - 2009-06-01 19:46 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-07-04 10:48 - 2011-01-01 03:08 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Opera
2015-07-04 10:48 - 2011-01-01 03:08 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\Opera
2015-07-04 10:47 - 2014-12-17 12:02 - 00000000 ___RD C:\Program Files\Skype
2015-07-04 10:47 - 2009-09-23 13:21 - 00000000 ___RD C:\Person
2015-07-04 08:03 - 2010-03-05 09:15 - 00000000 ____D C:\Program Files\Google
2015-07-04 08:02 - 2010-03-05 09:15 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Google
2015-07-03 23:56 - 2009-06-01 18:01 - 00000000 ___HD C:\Documents and Settings\zakaznik\Local Settings\Data aplikací
2015-07-03 23:46 - 2009-06-06 13:13 - 00000000 ____D C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\Adobe
2015-07-03 23:46 - 2009-06-01 18:01 - 00000000 ___RD C:\Documents and Settings\zakaznik\Dokumenty
2015-07-03 23:44 - 2013-06-11 15:22 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-03 23:44 - 2013-06-11 15:22 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-07-03 23:17 - 2009-10-01 13:30 - 00000000 ____D C:\WINDOWS\Minidump
2015-07-03 23:15 - 2009-06-01 19:46 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-07-03 23:11 - 2015-05-11 08:10 - 00000000 ____D C:\Program Files\SRWare Iron
2015-07-03 22:56 - 2014-10-29 13:49 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-07-03 22:48 - 2009-06-07 10:29 - 00000000 ____D C:\Documents and Settings\zakaznik\Data aplikací\uTorrent
2015-07-03 15:43 - 2014-10-29 08:00 - 00000000 ____D C:\Documents and Settings\Administrator
2015-07-03 15:43 - 2009-06-01 18:00 - 00000000 __SHD C:\Documents and Settings\LocalService
2015-07-03 15:43 - 2009-06-01 17:59 - 00000000 __SHD C:\Documents and Settings\NetworkService
2015-07-03 15:42 - 2009-06-01 18:01 - 00000000 ___HD C:\Documents and Settings\zakaznik\Data aplikací
2015-07-03 15:42 - 2009-06-01 17:53 - 00000000 ____D C:\WINDOWS\Registration
2015-07-02 23:11 - 2014-12-25 13:26 - 00000000 ____D C:\Program Files\Spyware Terminator
2015-07-01 18:07 - 2014-12-25 13:28 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2015-06-24 23:21 - 2015-05-05 20:52 - 00000000 ____D C:\Program Files\Mozilla Firefox.bak
2015-06-10 22:22 - 2014-10-26 11:31 - 00000000 ____D C:\Program Files\Comodo
2015-06-10 22:21 - 2014-10-26 11:35 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\COMODO
==================== Files in the root of some directories =======
2009-06-01 19:40 - 2009-06-01 19:40 - 0000180 _____ () C:\Documents and Settings\zakaznik\Data aplikací\setup.log
2009-06-01 19:40 - 2009-06-01 20:10 - 0000760 _____ () C:\Documents and Settings\zakaznik\Data aplikací\setup_ldm.iss
2009-06-12 15:38 - 2014-02-05 18:15 - 0065536 _____ () C:\Documents and Settings\zakaznik\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\zakaznik\Local Settings\temp\8348.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\fsdE8.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\Quarantine.exe
C:\Documents and Settings\zakaznik\Local Settings\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================