prosím o preventivní kontrolu
Napsal: 05 srp 2015 21:03
Pc je zpomalené, seká se, videa chodí trhaně....děkuji za kontrolu
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by Petr (administrator) on DOMA (05-08-2015 21:58:59)
Running from C:\Documents and Settings\Petr\Plocha
Loaded Profiles: Petr (Available Profiles: Petr)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Crawler.com) C:\Program Files\Spyware Terminator\sp_rsser.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Pinnacle Systems GmbH) C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\WFWIZ.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [PtiuPbmd] => Rundll32.exe ptipbm.dll,SetWriteBack
HKLM\...\Run: [WinFastDTV] => C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [90112 2009-10-02] (Leadtek Research Inc.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [USBToolTip] => C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [199752 2007-02-20] (Pinnacle Systems GmbH)
HKLM\...\Run: [SpywareTerminator] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2176512 2010-07-27] (Crawler.com)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKLM\...\Run: [Bonus.SSR.FR12] => C:\Program Files\ABBYY FineReader 12\Bonus.ScreenshotReader.exe [1472312 2014-05-11] (ABBYY Production LLC.)
HKLM\...\Run: [Ptipbmf] => rundll32.exe ptipbmf.dll,SetWriteCacheMode
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2010-08-26] (ATI Technologies Inc.)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [WinFast Schedule] => C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2912256 2009-03-11] (Leadtek Research Inc.)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [SpywareTerminatorUpdate] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3037696 2010-07-27] (Crawler.com)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk [2010-07-05]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-220523388-2147186123-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-220523388-2147186123-839522115-1003\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dl ... date&O1=b1
URLSearchHook: HKU\S-1-5-21-220523388-2147186123-839522115-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-26] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-26] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-220523388-2147186123-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{39CD1C0B-E062-419A-8631-C63F54885A74}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default
FF DefaultSearchUrl:
FF SelectedSearchEngine:
FF Homepage: https://seznam.cz/
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-26] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-12-14] (mozilla.org)
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\firmycz.xml [2015-03-28]
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\mapycz.xml [2015-03-28]
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\zbocz.xml [2015-03-28]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-10-28]
FF Extension: Seznam lištička - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-05-30]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-06-05]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [606208 2010-08-26] (ATI Technologies Inc.) [File not signed]
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2007-09-14] () [File not signed]
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771456 2015-04-03] (Enigma Software Group USA, LLC.)
R2 sp_rssrv; C:\Program Files\Spyware Terminator\sp_rsser.exe [488960 2010-07-27] (Crawler.com) [File not signed]
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
R3 ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [5386752 2010-08-26] (ATI Technologies Inc.) [File not signed]
R3 camfilt2; C:\WINDOWS\System32\DRIVERS\camfilt2.sys [96384 2007-08-29] (Guillemot Corporation) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 cmuda; C:\WINDOWS\System32\drivers\cmuda.sys [743367 2003-05-01] (C-Media Inc)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2015-04-03] ()
S0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [156672 2003-06-10] (Promise Technology, Inc.)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 ovt530; C:\WINDOWS\System32\Drivers\ov530vid.sys [167464 2007-02-02] (OmniVision Technologies, Inc.)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-07-29] (VSO Software) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2010-06-03] () [File not signed]
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [142592 2010-07-27] () [File not signed]
R0 UlSata; C:\WINDOWS\System32\DRIVERS\ulsata.sys [64256 2003-01-26] (Promise Technology, Inc.) [File not signed]
R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [26880 2002-12-27] (VIA Technologies, Inc.)
R0 viasraid; C:\WINDOWS\System32\drivers\viasraid.sys [75904 2003-06-12] (VIA Technologies inc,.ltd) [File not signed]
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2002-10-24] (VIA Technologies, Inc.) [File not signed]
R3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [10496 2002-11-13] (VIA Technologies, Inc.) [File not signed]
R3 WFLR6654; C:\WINDOWS\System32\drivers\wfeaglxt.sys [433920 2009-10-21] (Leadtek Research Inc.)
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.)
U3 ayfz3d81; C:\WINDOWS\system32\Drivers\ayfz3d81.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [X]
S4 IntelIde; No ImagePath
S3 nmwcd; system32\drivers\ccdcmb.sys [X]
S3 nmwcdc; system32\drivers\ccdcmbo.sys [X]
S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X]
S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 UsbserFilt; system32\DRIVERS\usbser_lowerfltj.sys [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 21:58 - 2015-08-05 21:59 - 00013896 _____ C:\Documents and Settings\Petr\Plocha\FRST.txt
2015-08-05 21:58 - 2015-08-05 21:59 - 00000000 ____D C:\FRST
2015-08-05 21:56 - 2015-08-05 21:56 - 00688992 _____ (Swearware) C:\Documents and Settings\Petr\Plocha\dds.exe
2015-08-05 21:55 - 2015-08-05 21:55 - 01107968 _____ C:\Documents and Settings\Petr\Plocha\RSIT.exe
2015-08-05 21:53 - 2015-08-05 21:53 - 01673728 _____ (Farbar) C:\Documents and Settings\Petr\Plocha\FRST.exe
2015-07-26 09:00 - 2015-07-26 09:01 - 00819200 _____ C:\Documents and Settings\Petr\Dokumenty\Kontakty1.accdb
2015-07-26 08:57 - 2015-07-26 08:59 - 00577536 _____ C:\Documents and Settings\Petr\Dokumenty\Database1.accdb
2015-07-26 08:56 - 2015-07-26 08:57 - 00749568 _____ C:\Documents and Settings\Petr\Dokumenty\Kontakty.accdb
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 21:59 - 2010-06-03 19:52 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Temp
2015-08-05 21:58 - 2010-06-03 19:52 - 00000000 ____D C:\Documents and Settings\Petr\Plocha
2015-08-05 21:56 - 2010-11-24 13:40 - 00000000 ____D C:\Documents and Settings\Petr\Dokumenty\Stažené soubory
2015-08-05 21:08 - 2015-03-29 09:42 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-05 15:53 - 2015-03-29 09:09 - 00059601 _____ C:\WINDOWS\AutoKMS.log
2015-08-05 15:53 - 2015-03-29 08:39 - 00000198 _____ C:\WINDOWS\Tasks\AutoKMS.job
2015-08-05 15:53 - 2010-06-03 19:46 - 01749577 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-05 15:52 - 2010-06-03 21:37 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-08-05 15:52 - 2010-06-03 21:37 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-08-05 15:51 - 2010-06-03 19:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-05 10:08 - 2010-06-03 19:52 - 00032352 _____ C:\WINDOWS\SchedLgU.Txt
2015-08-04 22:10 - 2010-06-03 19:52 - 00000178 ___SH C:\Documents and Settings\Petr\ntuser.ini
2015-08-04 16:47 - 2001-10-25 16:00 - 00002228 _____ C:\WINDOWS\system32\wpa.dbl
2015-08-03 23:05 - 2010-08-08 13:19 - 00131072 _____ C:\WINDOWS\system32\config\OAlerts.evt
2015-08-03 07:21 - 2015-03-28 21:20 - 00734653 _____ C:\WINDOWS\setupapi.log
2015-07-27 20:20 - 2010-06-11 15:02 - 00000000 ____D C:\Documents and Settings\Petr\Dokumenty\Petr
2015-07-26 09:00 - 2010-06-03 19:52 - 00000000 ___RD C:\Documents and Settings\Petr\Dokumenty
2015-07-26 08:59 - 2015-04-03 07:11 - 00002475 _____ C:\Documents and Settings\Petr\Plocha\Microsoft Access 2010.lnk
2015-07-25 19:26 - 2010-09-04 16:24 - 00002463 _____ C:\Documents and Settings\Petr\Plocha\Microsoft Excel 2010.lnk
2015-07-15 16:08 - 2015-03-29 09:42 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-15 16:08 - 2015-03-29 09:42 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2010-08-08 21:50 - 2010-11-24 14:25 - 0000172 ____C () C:\Documents and Settings\Petr\Data aplikací\default.rss
2010-07-29 21:15 - 2010-07-29 22:09 - 0087608 ____C () C:\Documents and Settings\Petr\Data aplikací\inst.exe
2010-07-29 21:15 - 2010-07-29 22:09 - 0007887 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.cat
2010-07-29 21:15 - 2010-07-29 22:09 - 0001144 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.inf
2010-07-29 21:15 - 2010-07-29 22:09 - 0000033 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.log
2010-07-29 21:15 - 2010-07-29 22:09 - 0047360 ____C (VSO Software) C:\Documents and Settings\Petr\Data aplikací\pcouffin.sys
2010-07-29 21:16 - 2010-07-29 22:07 - 0001057 ____C () C:\Documents and Settings\Petr\Data aplikací\vso_ts_preview.xml
2010-09-10 21:07 - 2015-03-28 14:40 - 0007680 _____ () C:\Documents and Settings\Petr\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\Petr\Local Settings\Temp\SHSetup.exe
C:\Documents and Settings\Petr\Local Settings\Temp\Utils.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by Petr (administrator) on DOMA (05-08-2015 21:58:59)
Running from C:\Documents and Settings\Petr\Plocha
Loaded Profiles: Petr (Available Profiles: Petr)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Crawler.com) C:\Program Files\Spyware Terminator\sp_rsser.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Pinnacle Systems GmbH) C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\WFWIZ.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [PtiuPbmd] => Rundll32.exe ptipbm.dll,SetWriteBack
HKLM\...\Run: [WinFastDTV] => C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [90112 2009-10-02] (Leadtek Research Inc.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [USBToolTip] => C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [199752 2007-02-20] (Pinnacle Systems GmbH)
HKLM\...\Run: [SpywareTerminator] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2176512 2010-07-27] (Crawler.com)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKLM\...\Run: [Bonus.SSR.FR12] => C:\Program Files\ABBYY FineReader 12\Bonus.ScreenshotReader.exe [1472312 2014-05-11] (ABBYY Production LLC.)
HKLM\...\Run: [Ptipbmf] => rundll32.exe ptipbmf.dll,SetWriteCacheMode
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2010-08-26] (ATI Technologies Inc.)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [WinFast Schedule] => C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2912256 2009-03-11] (Leadtek Research Inc.)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [SpywareTerminatorUpdate] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3037696 2010-07-27] (Crawler.com)
HKU\S-1-5-21-220523388-2147186123-839522115-1003\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk [2010-07-05]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-220523388-2147186123-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-220523388-2147186123-839522115-1003\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dl ... date&O1=b1
URLSearchHook: HKU\S-1-5-21-220523388-2147186123-839522115-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-26] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-26] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-220523388-2147186123-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{39CD1C0B-E062-419A-8631-C63F54885A74}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default
FF DefaultSearchUrl:
FF SelectedSearchEngine:
FF Homepage: https://seznam.cz/
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-26] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-12-14] (mozilla.org)
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\firmycz.xml [2015-03-28]
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\mapycz.xml [2015-03-28]
FF SearchPlugin: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\searchplugins\zbocz.xml [2015-03-28]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-10-28]
FF Extension: Seznam lištička - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x2t7b3ip.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-05-30]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-06-05]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [606208 2010-08-26] (ATI Technologies Inc.) [File not signed]
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2007-09-14] () [File not signed]
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771456 2015-04-03] (Enigma Software Group USA, LLC.)
R2 sp_rssrv; C:\Program Files\Spyware Terminator\sp_rsser.exe [488960 2010-07-27] (Crawler.com) [File not signed]
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
R3 ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [5386752 2010-08-26] (ATI Technologies Inc.) [File not signed]
R3 camfilt2; C:\WINDOWS\System32\DRIVERS\camfilt2.sys [96384 2007-08-29] (Guillemot Corporation) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 cmuda; C:\WINDOWS\System32\drivers\cmuda.sys [743367 2003-05-01] (C-Media Inc)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2015-04-03] ()
S0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [156672 2003-06-10] (Promise Technology, Inc.)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 ovt530; C:\WINDOWS\System32\Drivers\ov530vid.sys [167464 2007-02-02] (OmniVision Technologies, Inc.)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-07-29] (VSO Software) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2010-06-03] () [File not signed]
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [142592 2010-07-27] () [File not signed]
R0 UlSata; C:\WINDOWS\System32\DRIVERS\ulsata.sys [64256 2003-01-26] (Promise Technology, Inc.) [File not signed]
R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [26880 2002-12-27] (VIA Technologies, Inc.)
R0 viasraid; C:\WINDOWS\System32\drivers\viasraid.sys [75904 2003-06-12] (VIA Technologies inc,.ltd) [File not signed]
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2002-10-24] (VIA Technologies, Inc.) [File not signed]
R3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [10496 2002-11-13] (VIA Technologies, Inc.) [File not signed]
R3 WFLR6654; C:\WINDOWS\System32\drivers\wfeaglxt.sys [433920 2009-10-21] (Leadtek Research Inc.)
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.)
U3 ayfz3d81; C:\WINDOWS\system32\Drivers\ayfz3d81.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [X]
S4 IntelIde; No ImagePath
S3 nmwcd; system32\drivers\ccdcmb.sys [X]
S3 nmwcdc; system32\drivers\ccdcmbo.sys [X]
S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X]
S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 UsbserFilt; system32\DRIVERS\usbser_lowerfltj.sys [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 21:58 - 2015-08-05 21:59 - 00013896 _____ C:\Documents and Settings\Petr\Plocha\FRST.txt
2015-08-05 21:58 - 2015-08-05 21:59 - 00000000 ____D C:\FRST
2015-08-05 21:56 - 2015-08-05 21:56 - 00688992 _____ (Swearware) C:\Documents and Settings\Petr\Plocha\dds.exe
2015-08-05 21:55 - 2015-08-05 21:55 - 01107968 _____ C:\Documents and Settings\Petr\Plocha\RSIT.exe
2015-08-05 21:53 - 2015-08-05 21:53 - 01673728 _____ (Farbar) C:\Documents and Settings\Petr\Plocha\FRST.exe
2015-07-26 09:00 - 2015-07-26 09:01 - 00819200 _____ C:\Documents and Settings\Petr\Dokumenty\Kontakty1.accdb
2015-07-26 08:57 - 2015-07-26 08:59 - 00577536 _____ C:\Documents and Settings\Petr\Dokumenty\Database1.accdb
2015-07-26 08:56 - 2015-07-26 08:57 - 00749568 _____ C:\Documents and Settings\Petr\Dokumenty\Kontakty.accdb
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 21:59 - 2010-06-03 19:52 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Temp
2015-08-05 21:58 - 2010-06-03 19:52 - 00000000 ____D C:\Documents and Settings\Petr\Plocha
2015-08-05 21:56 - 2010-11-24 13:40 - 00000000 ____D C:\Documents and Settings\Petr\Dokumenty\Stažené soubory
2015-08-05 21:08 - 2015-03-29 09:42 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-05 15:53 - 2015-03-29 09:09 - 00059601 _____ C:\WINDOWS\AutoKMS.log
2015-08-05 15:53 - 2015-03-29 08:39 - 00000198 _____ C:\WINDOWS\Tasks\AutoKMS.job
2015-08-05 15:53 - 2010-06-03 19:46 - 01749577 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-05 15:52 - 2010-06-03 21:37 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-08-05 15:52 - 2010-06-03 21:37 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-08-05 15:51 - 2010-06-03 19:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-05 10:08 - 2010-06-03 19:52 - 00032352 _____ C:\WINDOWS\SchedLgU.Txt
2015-08-04 22:10 - 2010-06-03 19:52 - 00000178 ___SH C:\Documents and Settings\Petr\ntuser.ini
2015-08-04 16:47 - 2001-10-25 16:00 - 00002228 _____ C:\WINDOWS\system32\wpa.dbl
2015-08-03 23:05 - 2010-08-08 13:19 - 00131072 _____ C:\WINDOWS\system32\config\OAlerts.evt
2015-08-03 07:21 - 2015-03-28 21:20 - 00734653 _____ C:\WINDOWS\setupapi.log
2015-07-27 20:20 - 2010-06-11 15:02 - 00000000 ____D C:\Documents and Settings\Petr\Dokumenty\Petr
2015-07-26 09:00 - 2010-06-03 19:52 - 00000000 ___RD C:\Documents and Settings\Petr\Dokumenty
2015-07-26 08:59 - 2015-04-03 07:11 - 00002475 _____ C:\Documents and Settings\Petr\Plocha\Microsoft Access 2010.lnk
2015-07-25 19:26 - 2010-09-04 16:24 - 00002463 _____ C:\Documents and Settings\Petr\Plocha\Microsoft Excel 2010.lnk
2015-07-15 16:08 - 2015-03-29 09:42 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-15 16:08 - 2015-03-29 09:42 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2010-08-08 21:50 - 2010-11-24 14:25 - 0000172 ____C () C:\Documents and Settings\Petr\Data aplikací\default.rss
2010-07-29 21:15 - 2010-07-29 22:09 - 0087608 ____C () C:\Documents and Settings\Petr\Data aplikací\inst.exe
2010-07-29 21:15 - 2010-07-29 22:09 - 0007887 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.cat
2010-07-29 21:15 - 2010-07-29 22:09 - 0001144 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.inf
2010-07-29 21:15 - 2010-07-29 22:09 - 0000033 ____C () C:\Documents and Settings\Petr\Data aplikací\pcouffin.log
2010-07-29 21:15 - 2010-07-29 22:09 - 0047360 ____C (VSO Software) C:\Documents and Settings\Petr\Data aplikací\pcouffin.sys
2010-07-29 21:16 - 2010-07-29 22:07 - 0001057 ____C () C:\Documents and Settings\Petr\Data aplikací\vso_ts_preview.xml
2010-09-10 21:07 - 2015-03-28 14:40 - 0007680 _____ () C:\Documents and Settings\Petr\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\Petr\Local Settings\Temp\SHSetup.exe
C:\Documents and Settings\Petr\Local Settings\Temp\Utils.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================