Vyskakování reklam v prohlížeči
Napsal: 22 zář 2015 20:32
Přítelkyni v notebooku v prohlížečí vyskočí každou chvilku nějaké okýnko s reklamou a dělá to ve všech prohlížečích.
Log FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-09-2015
Ran by Míša (administrator) on MÍŠA-PC (22-09-2015 21:28:02)
Running from C:\Users\Míša\Downloads
Loaded Profiles: Míša (Available Profiles: Míša)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Cinema PlusV17.08) C:\Program Files\CinemaP-1.9cV17.08\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-6.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-26] (AVAST Software)
HKLM\...\Run: [ISBMgr.exe] => C:\Program Files\Sony\ISB Utility\ISBMgr.exe [311296 2007-11-21] (Sony Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll [2007-08-14] (Sony Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-08-11] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\..\Interfaces\{27EBEBF9-4D93-4465-A190-E031993E3DCD}: [DhcpNameServer] 192.168.1.1 0.0.0.0
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3409466872-446764647-380554783-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3409466872-446764647-380554783-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3409466872-446764647-380554783-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {01E6CB2A-7CC4-4F52-AF89-102E8494EB50} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {5710CBBE-040E-4060-BA54-00FBD1D0A0FE} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {6DF57F23-0AF9-446E-A9D8-4D3FB7153596} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {77DCB513-A3C6-43F5-B8AA-149BA85C86D7} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {8341AC0B-2569-40D7-BA5A-822C1E4554E5} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {A8824F5F-7F90-4421-BCB5-256AD335254C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {AB4C2A44-8AAA-4C9C-986C-971F0652E574} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {D387345A-A149-4418-8189-76E976D00481} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {D86633F8-E177-4F8A-9C77-EB8808116F7B} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-11] (AVAST Software)
FireFox:
========
FF ProfilePath: C:\Users\Míša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [No File]
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: CinemaP-1.9cV17.08 - C:\Users\Míša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default\Extensions\AVJYFVOD75109374@HCDE39471360.com [2015-09-22]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-10]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-04-10]
FF Extension: No Name - C:\Users\MĂša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default\extensions\AVJYFVOD75109374@HCDE39471360.com [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-08-28]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-10]
Opera:
=======
OPR Extension: (CinemaP-1.9cV17.08) - C:\Users\Míša\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-08-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-11] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-08-11] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3218624 2015-08-11] (Avast Software)
R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392 2007-08-14] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-08-11] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-08-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-08-11] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12112 2015-05-15] (ALWIL Software)
R0 aswNdis2; C:\Windows\system32\Drivers\aswNdis2.sys [256160 2015-08-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-08-11] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-08-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788784 2015-08-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [433264 2015-08-11] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [161472 2015-08-11] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-08-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-08-11] (AVAST Software)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [95112 2015-08-11] (AVAST Software)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 ti21sony; C:\Windows\System32\drivers\ti21sony.sys [818688 2007-11-16] (Texas Instruments)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-08-11] (Avast Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MA7580~1\AppData\Local\Temp\catchme.sys [X]
S3 cpuz134; \??\C:\Users\MA7580~1\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-22 21:24 - 2015-09-22 21:26 - 00023857 _____ C:\Users\Míša\Downloads\Addition.txt
2015-09-22 21:23 - 2015-09-22 21:28 - 00011600 _____ C:\Users\Míša\Downloads\FRST.txt
2015-09-22 21:23 - 2015-09-22 21:28 - 00000000 ____D C:\FRST
2015-09-22 21:23 - 2015-09-22 21:23 - 01695232 _____ (Farbar) C:\Users\Míša\Downloads\FRST.exe
2015-09-22 21:22 - 2015-09-22 21:22 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\reimagerepair(2).exe
2015-09-22 21:00 - 2015-09-22 21:15 - 00003726 _____ C:\Users\Míša\Downloads\hijackthis.log
2015-09-22 21:00 - 2015-09-22 21:00 - 00388608 _____ (Trend Micro Inc.) C:\Users\Míša\Downloads\HijackThis.exe
2015-09-22 19:19 - 2015-09-22 19:19 - 00000000 ___SD C:\ComboFix
2015-09-22 19:19 - 2015-09-22 19:19 - 00000000 ___SD C:\32788R22FWJFW
2015-09-22 19:12 - 2015-09-22 19:12 - 00013267 _____ C:\ComboFix.txt
2015-09-22 19:01 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-09-22 19:01 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-09-22 19:01 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-09-22 19:00 - 2015-09-22 19:19 - 00000000 ____D C:\Qoobox
2015-09-22 18:59 - 2015-09-22 19:10 - 00000000 ____D C:\Windows\erdnt
2015-09-22 18:59 - 2015-09-22 18:59 - 05635484 ____R (Swearware) C:\Users\Míša\Downloads\ComboFix.exe
2015-09-22 18:41 - 2015-09-22 18:41 - 00000858 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-22 18:41 - 2015-09-22 18:41 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Users\Míša\AppData\Roaming\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Users\Míša\AppData\Local\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\ProgramData\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-09-22 18:40 - 2015-07-07 16:25 - 00000000 ____D C:\Users\Míša\Desktop\firefox
2015-09-20 12:46 - 2015-08-13 16:15 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-09-20 12:46 - 2015-08-13 16:15 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-09-20 12:45 - 2015-09-02 23:26 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-20 12:45 - 2015-09-02 23:26 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-20 12:43 - 2015-07-10 16:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-20 12:41 - 2015-09-02 23:26 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-20 12:41 - 2015-09-02 21:55 - 02067456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-20 12:41 - 2015-09-02 21:54 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-20 12:41 - 2015-08-05 17:59 - 00602112 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-16 08:57 - 2015-08-17 19:18 - 01814016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-16 08:57 - 2015-08-17 19:17 - 12388352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-16 08:57 - 2015-08-17 19:14 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-16 08:57 - 2015-08-17 19:13 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-16 08:57 - 2015-08-17 19:12 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-16 08:57 - 2015-08-17 19:12 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-16 08:57 - 2015-08-17 19:11 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-16 08:57 - 2015-08-17 19:11 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-16 08:57 - 2015-08-17 19:10 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-09-16 08:57 - 2015-08-17 19:10 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-09-16 08:57 - 2015-08-17 19:09 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-16 07:40 - 2015-09-22 20:07 - 00011596 _____ C:\Windows\PFRO.log
2015-09-15 14:43 - 2015-09-15 14:43 - 00242912 _____ C:\Users\Míša\Downloads\Firefox Setup Stub 40.0.3.exe
2015-09-15 14:09 - 2015-09-15 14:09 - 00000000 ____D C:\Users\Míša\Desktop\Původní data aplikace Firefox
2015-09-03 08:05 - 2015-09-14 08:08 - 00000148 _____ C:\Windows\Reimage.ini
2015-09-03 08:04 - 2015-09-03 08:05 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\ReimageRepair(1).exe
2015-09-03 07:51 - 2015-09-03 07:52 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\ReimageRepair.exe
2015-08-28 14:28 - 2015-09-22 18:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-22 21:21 - 2006-11-02 14:47 - 00003760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-22 21:21 - 2006-11-02 14:47 - 00003760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-22 21:16 - 2009-04-11 14:37 - 01714242 _____ C:\Windows\WindowsUpdate.log
2015-09-22 21:15 - 2015-08-17 17:15 - 00003118 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-6.job
2015-09-22 21:14 - 2015-08-17 17:14 - 00005498 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-6.job
2015-09-22 21:00 - 2015-04-10 08:00 - 00000000 ____D C:\Users\Míša\AppData\Local\VirtualStore
2015-09-22 20:07 - 2015-08-17 17:15 - 00004138 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-4.job
2015-09-22 20:07 - 2015-08-17 17:15 - 00003118 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-7.job
2015-09-22 20:07 - 2015-08-17 17:15 - 00002426 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-5.job
2015-09-22 20:07 - 2015-08-17 17:14 - 00005164 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-11.job
2015-09-22 20:07 - 2015-08-17 17:14 - 00005162 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-7.job
2015-09-22 20:07 - 2015-08-17 17:13 - 00004138 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-3.job
2015-09-22 20:07 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-22 19:24 - 2015-04-10 07:53 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-09-22 19:24 - 2006-11-02 15:01 - 00032546 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-22 19:12 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2015-09-22 19:12 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2015-09-22 19:10 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2015-09-22 19:09 - 2015-08-17 17:14 - 00000000 ____D C:\Program Files\1c1ee5ff-506b-4738-995c-9df6e82731c4
2015-09-22 19:09 - 2015-08-17 17:13 - 00000000 ____D C:\Program Files\CinemaP-1.9cV17.08
2015-09-22 19:09 - 2015-04-12 16:56 - 00000000 ____D C:\Program Files\Apple Software Update
2015-09-22 18:33 - 2015-04-10 21:15 - 00000000 ____D C:\Program Files\The KMPlayer
2015-09-22 18:08 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-09-21 09:38 - 2009-04-13 11:32 - 01418230 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-21 09:10 - 2015-04-12 09:14 - 00002673 _____ C:\Users\Míša\Desktop\Microsoft Office Word 2003.lnk
2015-09-21 08:59 - 2015-07-08 13:49 - 367052800 _____ C:\Users\Míša\Downloads\5x05-Dr.-House..avi
2015-09-21 08:59 - 2015-07-08 13:26 - 367065088 _____ C:\Users\Míša\Downloads\5x07-Dr.-House..avi
2015-09-20 16:20 - 2015-04-27 08:01 - 00000000 ____D C:\Users\Míša\AppData\Local\Apple Computer
2015-09-20 13:30 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2015-09-20 13:10 - 2006-11-02 14:47 - 00345448 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-20 13:07 - 2015-08-17 17:11 - 00000000 ____D C:\Program Files\Opera
2015-09-20 13:04 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-20 12:33 - 2015-04-10 12:39 - 00000000 ____D C:\Windows\system32\MRT
2015-09-15 14:33 - 2015-04-28 09:06 - 00000000 ____D C:\Program Files\Google
2015-09-15 14:32 - 2015-08-17 17:15 - 00000000 ____D C:\Users\Míša\AppData\Roaming\Seznam.cz
2015-09-15 14:32 - 2015-04-28 09:06 - 00000000 ____D C:\Users\Míša\AppData\Local\Google
2015-09-10 18:40 - 2015-04-10 09:56 - 00100864 _____ C:\Users\Míša\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-02 10:27 - 2015-04-19 14:20 - 00000626 _____ C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T
2015-08-26 18:36 - 2006-11-02 12:24 - 132039072 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
==================== Files in the root of some directories =======
2015-04-19 14:20 - 2015-09-02 10:27 - 0000626 _____ () C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T.exe
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Míša\AppData\Roaming\YzSbCbeczPcWe7sA
2015-04-10 08:00 - 2015-04-10 08:22 - 0000680 _____ () C:\Users\Míša\AppData\Local\d3d9caps.dat
2015-04-10 09:56 - 2015-09-10 18:40 - 0100864 _____ () C:\Users\Míša\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-22 20:13
==================== End of FRST.txt ============================
Log FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-09-2015
Ran by Míša (administrator) on MÍŠA-PC (22-09-2015 21:28:02)
Running from C:\Users\Míša\Downloads
Loaded Profiles: Míša (Available Profiles: Míša)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Cinema PlusV17.08) C:\Program Files\CinemaP-1.9cV17.08\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-6.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-26] (AVAST Software)
HKLM\...\Run: [ISBMgr.exe] => C:\Program Files\Sony\ISB Utility\ISBMgr.exe [311296 2007-11-21] (Sony Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll [2007-08-14] (Sony Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-08-11] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\..\Interfaces\{27EBEBF9-4D93-4465-A190-E031993E3DCD}: [DhcpNameServer] 192.168.1.1 0.0.0.0
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3409466872-446764647-380554783-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3409466872-446764647-380554783-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3409466872-446764647-380554783-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {01E6CB2A-7CC4-4F52-AF89-102E8494EB50} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {5710CBBE-040E-4060-BA54-00FBD1D0A0FE} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {6DF57F23-0AF9-446E-A9D8-4D3FB7153596} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {77DCB513-A3C6-43F5-B8AA-149BA85C86D7} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {8341AC0B-2569-40D7-BA5A-822C1E4554E5} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {A8824F5F-7F90-4421-BCB5-256AD335254C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {AB4C2A44-8AAA-4C9C-986C-971F0652E574} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {D387345A-A149-4418-8189-76E976D00481} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3409466872-446764647-380554783-1000 -> {D86633F8-E177-4F8A-9C77-EB8808116F7B} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-11] (AVAST Software)
FireFox:
========
FF ProfilePath: C:\Users\Míša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [No File]
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: CinemaP-1.9cV17.08 - C:\Users\Míša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default\Extensions\AVJYFVOD75109374@HCDE39471360.com [2015-09-22]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-10]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-04-10]
FF Extension: No Name - C:\Users\MĂša\AppData\Roaming\Mozilla\Firefox\Profiles\1l2i5rjh.default\extensions\AVJYFVOD75109374@HCDE39471360.com [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-08-28]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-10]
Opera:
=======
OPR Extension: (CinemaP-1.9cV17.08) - C:\Users\Míša\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-08-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-11] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-08-11] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3218624 2015-08-11] (Avast Software)
R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392 2007-08-14] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-08-11] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-08-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-08-11] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12112 2015-05-15] (ALWIL Software)
R0 aswNdis2; C:\Windows\system32\Drivers\aswNdis2.sys [256160 2015-08-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-08-11] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-08-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788784 2015-08-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [433264 2015-08-11] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [161472 2015-08-11] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-08-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-08-11] (AVAST Software)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [95112 2015-08-11] (AVAST Software)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 ti21sony; C:\Windows\System32\drivers\ti21sony.sys [818688 2007-11-16] (Texas Instruments)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-08-11] (Avast Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MA7580~1\AppData\Local\Temp\catchme.sys [X]
S3 cpuz134; \??\C:\Users\MA7580~1\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-22 21:24 - 2015-09-22 21:26 - 00023857 _____ C:\Users\Míša\Downloads\Addition.txt
2015-09-22 21:23 - 2015-09-22 21:28 - 00011600 _____ C:\Users\Míša\Downloads\FRST.txt
2015-09-22 21:23 - 2015-09-22 21:28 - 00000000 ____D C:\FRST
2015-09-22 21:23 - 2015-09-22 21:23 - 01695232 _____ (Farbar) C:\Users\Míša\Downloads\FRST.exe
2015-09-22 21:22 - 2015-09-22 21:22 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\reimagerepair(2).exe
2015-09-22 21:00 - 2015-09-22 21:15 - 00003726 _____ C:\Users\Míša\Downloads\hijackthis.log
2015-09-22 21:00 - 2015-09-22 21:00 - 00388608 _____ (Trend Micro Inc.) C:\Users\Míša\Downloads\HijackThis.exe
2015-09-22 19:19 - 2015-09-22 19:19 - 00000000 ___SD C:\ComboFix
2015-09-22 19:19 - 2015-09-22 19:19 - 00000000 ___SD C:\32788R22FWJFW
2015-09-22 19:12 - 2015-09-22 19:12 - 00013267 _____ C:\ComboFix.txt
2015-09-22 19:01 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-09-22 19:01 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-09-22 19:01 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-09-22 19:01 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-09-22 19:00 - 2015-09-22 19:19 - 00000000 ____D C:\Qoobox
2015-09-22 18:59 - 2015-09-22 19:10 - 00000000 ____D C:\Windows\erdnt
2015-09-22 18:59 - 2015-09-22 18:59 - 05635484 ____R (Swearware) C:\Users\Míša\Downloads\ComboFix.exe
2015-09-22 18:41 - 2015-09-22 18:41 - 00000858 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-22 18:41 - 2015-09-22 18:41 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Users\Míša\AppData\Roaming\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Users\Míša\AppData\Local\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\ProgramData\Mozilla
2015-09-22 18:41 - 2015-09-22 18:41 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-09-22 18:40 - 2015-07-07 16:25 - 00000000 ____D C:\Users\Míša\Desktop\firefox
2015-09-20 12:46 - 2015-08-13 16:15 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-09-20 12:46 - 2015-08-13 16:15 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-09-20 12:45 - 2015-09-02 23:26 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-20 12:45 - 2015-09-02 23:26 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-20 12:43 - 2015-07-10 16:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-20 12:41 - 2015-09-02 23:26 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-20 12:41 - 2015-09-02 21:55 - 02067456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-20 12:41 - 2015-09-02 21:54 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-20 12:41 - 2015-08-05 17:59 - 00602112 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-16 08:57 - 2015-08-17 19:18 - 01814016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-16 08:57 - 2015-08-17 19:17 - 12388352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-16 08:57 - 2015-08-17 19:14 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-16 08:57 - 2015-08-17 19:13 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-16 08:57 - 2015-08-17 19:12 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-16 08:57 - 2015-08-17 19:12 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-16 08:57 - 2015-08-17 19:11 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-16 08:57 - 2015-08-17 19:11 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-16 08:57 - 2015-08-17 19:10 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-09-16 08:57 - 2015-08-17 19:10 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-09-16 08:57 - 2015-08-17 19:10 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-09-16 08:57 - 2015-08-17 19:09 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-16 07:40 - 2015-09-22 20:07 - 00011596 _____ C:\Windows\PFRO.log
2015-09-15 14:43 - 2015-09-15 14:43 - 00242912 _____ C:\Users\Míša\Downloads\Firefox Setup Stub 40.0.3.exe
2015-09-15 14:09 - 2015-09-15 14:09 - 00000000 ____D C:\Users\Míša\Desktop\Původní data aplikace Firefox
2015-09-03 08:05 - 2015-09-14 08:08 - 00000148 _____ C:\Windows\Reimage.ini
2015-09-03 08:04 - 2015-09-03 08:05 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\ReimageRepair(1).exe
2015-09-03 07:51 - 2015-09-03 07:52 - 00772016 _____ (Reimage®) C:\Users\Míša\Downloads\ReimageRepair.exe
2015-08-28 14:28 - 2015-09-22 18:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-22 21:21 - 2006-11-02 14:47 - 00003760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-22 21:21 - 2006-11-02 14:47 - 00003760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-22 21:16 - 2009-04-11 14:37 - 01714242 _____ C:\Windows\WindowsUpdate.log
2015-09-22 21:15 - 2015-08-17 17:15 - 00003118 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-6.job
2015-09-22 21:14 - 2015-08-17 17:14 - 00005498 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-6.job
2015-09-22 21:00 - 2015-04-10 08:00 - 00000000 ____D C:\Users\Míša\AppData\Local\VirtualStore
2015-09-22 20:07 - 2015-08-17 17:15 - 00004138 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-4.job
2015-09-22 20:07 - 2015-08-17 17:15 - 00003118 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-1-7.job
2015-09-22 20:07 - 2015-08-17 17:15 - 00002426 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-5.job
2015-09-22 20:07 - 2015-08-17 17:14 - 00005164 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-11.job
2015-09-22 20:07 - 2015-08-17 17:14 - 00005162 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-7.job
2015-09-22 20:07 - 2015-08-17 17:13 - 00004138 _____ C:\Windows\Tasks\fd805d1e-abba-4789-9a46-8d2ea4467df1-3.job
2015-09-22 20:07 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-22 19:24 - 2015-04-10 07:53 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-09-22 19:24 - 2006-11-02 15:01 - 00032546 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-22 19:12 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2015-09-22 19:12 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2015-09-22 19:10 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2015-09-22 19:09 - 2015-08-17 17:14 - 00000000 ____D C:\Program Files\1c1ee5ff-506b-4738-995c-9df6e82731c4
2015-09-22 19:09 - 2015-08-17 17:13 - 00000000 ____D C:\Program Files\CinemaP-1.9cV17.08
2015-09-22 19:09 - 2015-04-12 16:56 - 00000000 ____D C:\Program Files\Apple Software Update
2015-09-22 18:33 - 2015-04-10 21:15 - 00000000 ____D C:\Program Files\The KMPlayer
2015-09-22 18:08 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-09-21 09:38 - 2009-04-13 11:32 - 01418230 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-21 09:10 - 2015-04-12 09:14 - 00002673 _____ C:\Users\Míša\Desktop\Microsoft Office Word 2003.lnk
2015-09-21 08:59 - 2015-07-08 13:49 - 367052800 _____ C:\Users\Míša\Downloads\5x05-Dr.-House..avi
2015-09-21 08:59 - 2015-07-08 13:26 - 367065088 _____ C:\Users\Míša\Downloads\5x07-Dr.-House..avi
2015-09-20 16:20 - 2015-04-27 08:01 - 00000000 ____D C:\Users\Míša\AppData\Local\Apple Computer
2015-09-20 13:30 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2015-09-20 13:10 - 2006-11-02 14:47 - 00345448 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-20 13:07 - 2015-08-17 17:11 - 00000000 ____D C:\Program Files\Opera
2015-09-20 13:04 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-20 12:33 - 2015-04-10 12:39 - 00000000 ____D C:\Windows\system32\MRT
2015-09-15 14:33 - 2015-04-28 09:06 - 00000000 ____D C:\Program Files\Google
2015-09-15 14:32 - 2015-08-17 17:15 - 00000000 ____D C:\Users\Míša\AppData\Roaming\Seznam.cz
2015-09-15 14:32 - 2015-04-28 09:06 - 00000000 ____D C:\Users\Míša\AppData\Local\Google
2015-09-10 18:40 - 2015-04-10 09:56 - 00100864 _____ C:\Users\Míša\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-02 10:27 - 2015-04-19 14:20 - 00000626 _____ C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T
2015-08-26 18:36 - 2006-11-02 12:24 - 132039072 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
==================== Files in the root of some directories =======
2015-04-19 14:20 - 2015-09-02 10:27 - 0000626 _____ () C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Míša\AppData\Roaming\pl57zk8307h5UTVM8pJ3T.exe
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Míša\AppData\Roaming\YzSbCbeczPcWe7sA
2015-04-10 08:00 - 2015-04-10 08:22 - 0000680 _____ () C:\Users\Míša\AppData\Local\d3d9caps.dat
2015-04-10 09:56 - 2015-09-10 18:40 - 0100864 _____ () C:\Users\Míša\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-22 20:13
==================== End of FRST.txt ============================