Modrá obrazovka, systém těžkopádný
Napsal: 27 zář 2015 15:36
Dobrý den, obracím se znovu. Bohužel problém se zase vrátil, a PC je celkově "ztuhlý". Dělala jsem defragmentaci Defragglerem, mám 8 % fragmentovaných souborů (cca 16.6 GB), což je hodně, protože mám celkem 149 GB, ale zbývá 35.1 GB volného místa.
Teď před deset min. se mi udělala modrá obrazovka, že systém má nějaký problém. Proto přikládám kromě hlavního logu FRST i "adddition".
Budu vděčná za pomoc, platí, že přispěju po výplatě, jako vždy.
Hlavní zpráva:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-09-2015
Ran by uzivatel (administrator) on NTBACER (27-09-2015 16:31:58)
Running from C:\Documents and Settings\uzivatel\Plocha
Loaded Profiles: uzivatel (Available Profiles: uzivatel)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\savedump.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
(Atheros Communications, Inc.) C:\Program Files\Atheros\ACU.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16871936 2008-06-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [53248 2006-07-17] (Realtek Semiconductor Corp.)
HKLM\...\Run: [ACU] => C:\Program Files\Atheros\ACU.exe [450648 2008-09-02] (Atheros Communications, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-26] (AVAST Software)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-26] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{814493D2-C058-4A42-985E-232526CDA0F8}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.centrum.cz/
URLSearchHook: [S-1-5-21-343818398-1547161642-1801674531-1003] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-343818398-1547161642-1801674531-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-08] (AVAST Software)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\1m6ofwn1.default-1430766865906
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-21] ()
FF Plugin: @xstandard.com/XStandard -> C:\Program Files\XStandard\Bin\NPXStandard.dll [2010-11-16] (Belus Technology Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-05-08]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-18]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACS; C:\WINDOWS\system32\acs.exe [467028 2008-09-02] (Atheros) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-26] (AVAST Software)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.) [File not signed]
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-26] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-26] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-26] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-26] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [789296 2015-09-26] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434184 2015-09-26] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-26] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-26] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-26] (AVAST Software)
S3 DrvAgent32; C:\WINDOWS\system32\Drivers\DrvAgent32.sys [23456 2015-06-17] (Phoenix Technologies) [File not signed]
R2 Ethpdrv; C:\WINDOWS\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 IntcHdmiAddService; C:\WINDOWS\System32\drivers\IntcHdmi.sys [105984 2007-05-05] (Intel(R) Corporation) [File not signed]
S3 ipw_bus; C:\WINDOWS\System32\DRIVERS\ipw_bus.sys [58320 2005-09-27] (MCCI)
S3 ipw_mdfl; C:\WINDOWS\System32\DRIVERS\ipw_mdfl.sys [8272 2005-09-27] (MCCI)
S3 ipw_mdm; C:\WINDOWS\System32\DRIVERS\ipw_mdm.sys [95440 2005-09-27] (MCCI)
R3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 WSIMD; C:\WINDOWS\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.) [File not signed]
S1 DritekPortIO; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-27 16:31 - 2015-09-27 16:32 - 00007864 _____ C:\Documents and Settings\uzivatel\Plocha\FRST.txt
2015-09-27 16:29 - 2015-09-27 16:29 - 00065536 _____ C:\WINDOWS\Minidump\Mini092715-01.dmp
2015-09-26 20:43 - 2015-09-26 21:09 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\italove
2015-09-26 19:01 - 2015-09-26 20:16 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\na net
2015-09-26 08:14 - 2015-09-26 08:13 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-26 08:13 - 2015-09-26 08:13 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-09-21 21:11 - 2015-09-27 16:32 - 00000000 ____D C:\Documents and Settings\uzivatel\Local Settings\Temp
2015-09-17 21:52 - 2015-09-24 17:59 - 00002283 _____ C:\Documents and Settings\All Users\Plocha\Skype.lnk
2015-09-17 21:52 - 2015-09-17 21:52 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2015-09-17 21:51 - 2015-09-17 21:52 - 00000000 ___RD C:\Program Files\Skype
2015-09-13 20:17 - 2015-09-13 20:17 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\COMODO
2015-08-28 20:29 - 2015-08-29 10:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-27 16:32 - 2015-03-23 00:37 - 00000000 ____D C:\FRST
2015-09-27 16:31 - 2015-06-15 20:50 - 00000000 ____D C:\Documents and Settings\uzivatel\Plocha\FRST-OlderVersion
2015-09-27 16:31 - 2015-03-23 00:36 - 01695744 _____ (Farbar) C:\Documents and Settings\uzivatel\Plocha\FRST.exe
2015-09-27 16:31 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel\Plocha
2015-09-27 16:31 - 2009-12-23 01:54 - 01807934 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-27 16:30 - 2012-07-09 08:06 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-09-27 16:30 - 2009-12-23 02:48 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-09-27 16:30 - 2009-12-23 02:48 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-09-27 16:30 - 2009-12-23 01:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-27 16:29 - 2015-06-19 22:23 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-27 16:29 - 2009-12-23 02:39 - 101113856 _____ C:\WINDOWS\MEMORY.DMP
2015-09-27 16:00 - 2015-07-04 15:56 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-27 15:00 - 2012-01-03 14:46 - 00032616 _____ C:\WINDOWS\Tasks\SCHEDLGU.TXT
2015-09-27 08:50 - 2010-03-14 14:26 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
2015-09-27 07:41 - 2014-09-18 21:36 - 00002563 _____ C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Word 2007.lnk
2015-09-26 23:26 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel
2015-09-26 21:20 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty
2015-09-26 20:43 - 2010-05-23 20:11 - 00158278 ____H C:\treeinfo.wc
2015-09-26 19:02 - 2009-12-23 02:45 - 00928972 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-26 19:00 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty\Obrázky
2015-09-26 12:18 - 2009-12-23 01:59 - 00000272 ___SH C:\Documents and Settings\uzivatel\ntuser.ini
2015-09-26 08:14 - 2015-07-24 17:12 - 00157888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2015-09-26 08:14 - 2014-08-01 21:32 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00434184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-09-26 08:13 - 2011-05-08 08:45 - 00789296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-25 20:13 - 2015-06-02 21:33 - 00002184 _____ C:\WINDOWS\system32\wpa.dbl
2015-09-24 18:01 - 2012-09-05 17:41 - 00000000 ____D C:\Documents and Settings\uzivatel\Data aplikací\Skype
2015-09-21 21:00 - 2013-03-18 23:30 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-21 21:00 - 2011-05-23 08:40 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-20 21:24 - 2015-05-30 22:08 - 00000000 ____D C:\AdwCleaner
2015-09-20 21:24 - 2009-12-23 02:44 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-09-20 21:24 - 2009-12-23 01:59 - 00000000 ___HD C:\Documents and Settings\uzivatel\Local Settings\Data aplikací
2015-09-20 21:24 - 2009-12-23 01:58 - 00000178 ___SH C:\Documents and Settings\LocalService\ntuser.ini
2015-09-18 22:45 - 2010-05-25 13:44 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\rodiny
2015-09-17 21:52 - 2010-01-15 20:01 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2015-09-17 21:52 - 2009-12-23 02:44 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-09-17 21:52 - 2009-12-23 02:44 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-09-16 23:08 - 2015-03-21 23:14 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\osmaci
2015-09-13 20:17 - 2009-12-23 01:58 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2015-08-29 15:06 - 2014-09-18 20:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2010-01-09 18:35 - 2013-09-28 01:21 - 0123392 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-16 23:03 - 2012-05-28 23:17 - 0002568 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).err
2011-10-16 21:28 - 2012-11-03 15:07 - 0001080 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).nast
2010-10-01 22:52 - 2012-08-10 18:48 - 0001064 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.err
2010-10-01 22:59 - 2012-08-10 21:39 - 0001120 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.nast
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Teď před deset min. se mi udělala modrá obrazovka, že systém má nějaký problém. Proto přikládám kromě hlavního logu FRST i "adddition".
Budu vděčná za pomoc, platí, že přispěju po výplatě, jako vždy.
Hlavní zpráva:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-09-2015
Ran by uzivatel (administrator) on NTBACER (27-09-2015 16:31:58)
Running from C:\Documents and Settings\uzivatel\Plocha
Loaded Profiles: uzivatel (Available Profiles: uzivatel)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\savedump.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
(Atheros Communications, Inc.) C:\Program Files\Atheros\ACU.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16871936 2008-06-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [53248 2006-07-17] (Realtek Semiconductor Corp.)
HKLM\...\Run: [ACU] => C:\Program Files\Atheros\ACU.exe [450648 2008-09-02] (Atheros Communications, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-26] (AVAST Software)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-26] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{814493D2-C058-4A42-985E-232526CDA0F8}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-343818398-1547161642-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.centrum.cz/
URLSearchHook: [S-1-5-21-343818398-1547161642-1801674531-1003] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-343818398-1547161642-1801674531-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-08] (AVAST Software)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\1m6ofwn1.default-1430766865906
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-21] ()
FF Plugin: @xstandard.com/XStandard -> C:\Program Files\XStandard\Bin\NPXStandard.dll [2010-11-16] (Belus Technology Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-05-08]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-18]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACS; C:\WINDOWS\system32\acs.exe [467028 2008-09-02] (Atheros) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-26] (AVAST Software)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.) [File not signed]
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-26] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-26] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-26] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-26] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [789296 2015-09-26] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434184 2015-09-26] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-26] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-26] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-26] (AVAST Software)
S3 DrvAgent32; C:\WINDOWS\system32\Drivers\DrvAgent32.sys [23456 2015-06-17] (Phoenix Technologies) [File not signed]
R2 Ethpdrv; C:\WINDOWS\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 IntcHdmiAddService; C:\WINDOWS\System32\drivers\IntcHdmi.sys [105984 2007-05-05] (Intel(R) Corporation) [File not signed]
S3 ipw_bus; C:\WINDOWS\System32\DRIVERS\ipw_bus.sys [58320 2005-09-27] (MCCI)
S3 ipw_mdfl; C:\WINDOWS\System32\DRIVERS\ipw_mdfl.sys [8272 2005-09-27] (MCCI)
S3 ipw_mdm; C:\WINDOWS\System32\DRIVERS\ipw_mdm.sys [95440 2005-09-27] (MCCI)
R3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 WSIMD; C:\WINDOWS\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.) [File not signed]
S1 DritekPortIO; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-27 16:31 - 2015-09-27 16:32 - 00007864 _____ C:\Documents and Settings\uzivatel\Plocha\FRST.txt
2015-09-27 16:29 - 2015-09-27 16:29 - 00065536 _____ C:\WINDOWS\Minidump\Mini092715-01.dmp
2015-09-26 20:43 - 2015-09-26 21:09 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\italove
2015-09-26 19:01 - 2015-09-26 20:16 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\na net
2015-09-26 08:14 - 2015-09-26 08:13 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-26 08:13 - 2015-09-26 08:13 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-09-21 21:11 - 2015-09-27 16:32 - 00000000 ____D C:\Documents and Settings\uzivatel\Local Settings\Temp
2015-09-17 21:52 - 2015-09-24 17:59 - 00002283 _____ C:\Documents and Settings\All Users\Plocha\Skype.lnk
2015-09-17 21:52 - 2015-09-17 21:52 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
2015-09-17 21:51 - 2015-09-17 21:52 - 00000000 ___RD C:\Program Files\Skype
2015-09-13 20:17 - 2015-09-13 20:17 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\COMODO
2015-08-28 20:29 - 2015-08-29 10:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-27 16:32 - 2015-03-23 00:37 - 00000000 ____D C:\FRST
2015-09-27 16:31 - 2015-06-15 20:50 - 00000000 ____D C:\Documents and Settings\uzivatel\Plocha\FRST-OlderVersion
2015-09-27 16:31 - 2015-03-23 00:36 - 01695744 _____ (Farbar) C:\Documents and Settings\uzivatel\Plocha\FRST.exe
2015-09-27 16:31 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel\Plocha
2015-09-27 16:31 - 2009-12-23 01:54 - 01807934 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-27 16:30 - 2012-07-09 08:06 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-09-27 16:30 - 2009-12-23 02:48 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-09-27 16:30 - 2009-12-23 02:48 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-09-27 16:30 - 2009-12-23 01:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-27 16:29 - 2015-06-19 22:23 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-27 16:29 - 2009-12-23 02:39 - 101113856 _____ C:\WINDOWS\MEMORY.DMP
2015-09-27 16:00 - 2015-07-04 15:56 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-27 15:00 - 2012-01-03 14:46 - 00032616 _____ C:\WINDOWS\Tasks\SCHEDLGU.TXT
2015-09-27 08:50 - 2010-03-14 14:26 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
2015-09-27 07:41 - 2014-09-18 21:36 - 00002563 _____ C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Word 2007.lnk
2015-09-26 23:26 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel
2015-09-26 21:20 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty
2015-09-26 20:43 - 2010-05-23 20:11 - 00158278 ____H C:\treeinfo.wc
2015-09-26 19:02 - 2009-12-23 02:45 - 00928972 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-26 19:00 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty\Obrázky
2015-09-26 12:18 - 2009-12-23 01:59 - 00000272 ___SH C:\Documents and Settings\uzivatel\ntuser.ini
2015-09-26 08:14 - 2015-07-24 17:12 - 00157888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2015-09-26 08:14 - 2014-08-01 21:32 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-26 08:14 - 2013-03-17 14:50 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00434184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-09-26 08:14 - 2011-05-08 08:45 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-09-26 08:13 - 2011-05-08 08:45 - 00789296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-25 20:13 - 2015-06-02 21:33 - 00002184 _____ C:\WINDOWS\system32\wpa.dbl
2015-09-24 18:01 - 2012-09-05 17:41 - 00000000 ____D C:\Documents and Settings\uzivatel\Data aplikací\Skype
2015-09-21 21:00 - 2013-03-18 23:30 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-21 21:00 - 2011-05-23 08:40 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-20 21:24 - 2015-05-30 22:08 - 00000000 ____D C:\AdwCleaner
2015-09-20 21:24 - 2009-12-23 02:44 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-09-20 21:24 - 2009-12-23 01:59 - 00000000 ___HD C:\Documents and Settings\uzivatel\Local Settings\Data aplikací
2015-09-20 21:24 - 2009-12-23 01:58 - 00000178 ___SH C:\Documents and Settings\LocalService\ntuser.ini
2015-09-18 22:45 - 2010-05-25 13:44 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\rodiny
2015-09-17 21:52 - 2010-01-15 20:01 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2015-09-17 21:52 - 2009-12-23 02:44 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-09-17 21:52 - 2009-12-23 02:44 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-09-16 23:08 - 2015-03-21 23:14 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\osmaci
2015-09-13 20:17 - 2009-12-23 01:58 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2015-08-29 15:06 - 2014-09-18 20:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2010-01-09 18:35 - 2013-09-28 01:21 - 0123392 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-16 23:03 - 2012-05-28 23:17 - 0002568 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).err
2011-10-16 21:28 - 2012-11-03 15:07 - 0001080 _____ () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader(1).nast
2010-10-01 22:52 - 2012-08-10 18:48 - 0001064 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.err
2010-10-01 22:59 - 2012-08-10 21:39 - 0001120 ____C () C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\SRDownloader.nast
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================