Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:10-10-2015
Ran by Doma (administrator) on MICHAL (10-10-2015 17:51:24)
Running from C:\Documents and Settings\Doma\Plocha
Loaded Profiles: Doma & UpdatusUser (Available Profiles: Doma & UpdatusUser)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\Kies\KiesTrayAgent.exe
(Samsung) C:\Program Files\SAMSUNG\Kies\Kies.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-06] (AVAST Software)
HKLM\...\Run: [igfxhkcmd] => C:\WINDOWS\system32\hkcmd.exe [77824 2006-03-23] (Intel Corporation)
HKLM\...\Run: [igfxpers] => C:\WINDOWS\system32\igfxpers.exe [118784 2006-03-23] (Intel Corporation)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1404928 2004-10-14] (Analog Devices, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [413696 2009-01-05] (Apple Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2602784 2013-11-11] ()
HKLM\...\Run: [Nvtmru] => C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-02-14] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-1644491937-1004336348-725345543-1003\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKU\S-1-5-21-1644491937-1004336348-725345543-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\System32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Google Update] => C:\WINDOWS\system32\config\systemprofile\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [116648 2015-06-04] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-10-06] (AVAST Software)
CHR HKU\S-1-5-21-1644491937-1004336348-725345543-1003\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C3A5B4F7-D842-4F63-B62C-A8D4F59460C1}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-1644491937-1004336348-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.seznam.cz/?clid=22668
HKU\S-1-5-21-1644491937-1004336348-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-1644491937-1004336348-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://
www.seznam.cz/?clid=22668
URLSearchHook: HKU\S-1-5-21-1644491937-1004336348-725345543-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation)
URLSearchHook: [S-1-5-21-1644491937-1004336348-725345543-1005] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope value is missing
Toolbar: HKU\S-1-5-21-1644491937-1004336348-725345543-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll [2008-04-14] (Společnost Microsoft)
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2015-04-08] (Citrix Systems, Inc.)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Doma\Data aplikací\Mozilla\Firefox\Profiles\vz68vjng.default
FF DefaultSearchEngine: Seznam
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Homepage: hxxp://
www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-10-09] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.)
FF Plugin: @Citrix.com/npican -> C:\Program Files\Citrix\ICA Client\npicaN.dll [2015-04-08] (Citrix Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\.DEFAULT: @tools.google.com/Google Update;version=3 -> C:\WINDOWS\system32\config\systemprofile\Local Settings\Data aplikací\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2015-06-04] (Google Inc.)
FF Plugin HKU\.DEFAULT: @tools.google.com/Google Update;version=9 -> C:\WINDOWS\system32\config\systemprofile\Local Settings\Data aplikací\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2015-06-04] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Doma\Data aplikací\Mozilla\Firefox\Profiles\vz68vjng.default\searchplugins\seznam-avast.xml [2014-12-14]
FF Extension: Adblock Plus - C:\Documents and Settings\Doma\Data aplikací\Mozilla\Firefox\Profiles\vz68vjng.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-25]
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-18]
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.seznam.cz/?clid=22668
CHR StartupUrls: Default -> "hxxps://
www.seznam.cz/?clid=22668"
CHR Profile: C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-17]
CHR Extension: (Disk Google) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-17]
CHR Extension: (YouTube) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-17]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-17]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-09]
CHR Extension: (Peněženka Google) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-17]
CHR Extension: (Gmail) - C:\Documents and Settings\Doma\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-17]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-22]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-06] (AVAST Software)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-10-06] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-10-06] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-10-06] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-10-06] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [789296 2015-10-06] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434184 2015-10-06] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-10-06] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-10-06] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-10-06] (AVAST Software)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128672 2013-06-16] (NVIDIA Corporation)
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 uosjbhpu; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-10 17:50 - 2015-10-10 17:50 - 00000000 ____D C:\Documents and Settings\Doma\Plocha\FRST-OlderVersion
2015-10-10 12:13 - 2015-10-10 12:20 - 00000000 ____D C:\AdwCleaner
2015-10-10 12:13 - 2015-10-10 12:13 - 01682432 _____ C:\Documents and Settings\Doma\Plocha\adwcleaner_5.013.exe
2015-10-10 11:08 - 2015-10-10 11:08 - 00012427 _____ C:\Documents and Settings\Doma\Plocha\Plocha.zip
2015-10-10 11:07 - 2015-10-10 11:07 - 00025558 _____ C:\Documents and Settings\Doma\Plocha\Addition.txt
2015-10-10 11:06 - 2015-10-10 17:51 - 00014485 _____ C:\Documents and Settings\Doma\Plocha\FRST.txt
2015-10-10 11:06 - 2015-10-10 17:51 - 00000000 ____D C:\FRST
2015-10-10 10:52 - 2015-10-10 17:50 - 01699328 _____ (Farbar) C:\Documents and Settings\Doma\Plocha\FRST.exe
2015-10-09 20:26 - 2015-10-10 12:28 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-06 19:10 - 2015-10-06 19:11 - 00080490 _____ C:\WINDOWS\Wdf01009Inst.log
2015-10-06 19:10 - 2015-10-06 19:11 - 00019230 _____ C:\WINDOWS\setupapi.log
2015-10-06 19:10 - 2015-10-06 19:10 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-06 19:10 - 2015-10-06 19:10 - 00000000 _____ C:\WINDOWS\setupact.log
2015-10-06 19:10 - 2015-10-06 19:09 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-10-06 19:09 - 2015-10-06 19:09 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-10-05 21:20 - 2015-10-05 21:20 - 00000000 _____ C:\Documents and Settings\All Users\Data aplikací\Flange Saw
2015-10-05 21:20 - 2015-10-05 21:20 - 00000000 _____ C:\Documents and Settings\All Users\Data aplikací\External Build System
2015-10-02 22:24 - 2015-10-02 22:54 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-09-27 23:19 - 2015-09-27 23:19 - 00000000 ____D C:\WINDOWS\system32\appmgmt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-10 17:51 - 2013-11-16 16:00 - 00000000 ____D C:\Documents and Settings\Doma\Local Settings\Temp
2015-10-10 17:50 - 2013-11-18 21:07 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-10-10 17:50 - 2013-11-16 17:04 - 00400276 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-10 17:50 - 2013-11-16 16:00 - 00000000 ____D C:\Documents and Settings\Doma\Plocha
2015-10-10 17:49 - 2013-11-28 21:54 - 00011770 _____ C:\WINDOWS\system32\nvAppTimestamps
2015-10-10 17:44 - 2013-11-17 14:56 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-10 17:44 - 2013-11-16 16:46 - 00000157 _____ C:\WINDOWS\wiadebug.log
2015-10-10 17:44 - 2013-11-16 16:46 - 00000050 _____ C:\WINDOWS\wiaservc.log
2015-10-10 17:44 - 2013-11-16 15:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-10 13:15 - 2013-11-16 16:00 - 00000178 ___SH C:\Documents and Settings\Doma\ntuser.ini
2015-10-10 13:15 - 2013-11-16 16:00 - 00000000 ____D C:\Documents and Settings\Doma
2015-10-10 13:15 - 2013-11-16 15:59 - 00032514 _____ C:\WINDOWS\SchedLgU.Txt
2015-10-10 13:08 - 2013-11-17 14:56 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-10 13:02 - 2015-06-04 20:57 - 00001046 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-18UA.job
2015-10-10 12:20 - 2013-11-28 21:50 - 00000178 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini
2015-10-10 12:20 - 2013-11-16 16:00 - 00000000 __RHD C:\Documents and Settings\Doma\Data aplikací
2015-10-10 12:20 - 2013-11-16 16:00 - 00000000 ___RD C:\Documents and Settings\Doma\Nabídka Start\Programy
2015-10-10 12:20 - 2013-11-16 16:00 - 00000000 ___HD C:\Documents and Settings\Doma\Local Settings\Data aplikací
2015-10-10 12:11 - 2015-01-06 19:34 - 00305664 _____ C:\Documents and Settings\Doma\Plocha\FORTUNA.xls
2015-10-09 21:02 - 2015-06-04 20:57 - 00000994 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-18Core.job
2015-10-09 20:26 - 2013-11-18 21:18 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-09 20:26 - 2013-11-18 21:18 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-10-09 20:18 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-10-08 19:09 - 2013-11-28 21:50 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Local Settings\Temp
2015-10-06 19:09 - 2015-08-15 20:25 - 00157888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2015-10-06 19:09 - 2014-08-01 17:17 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00789296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00434184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-10-06 19:09 - 2013-11-18 21:07 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-10-05 21:33 - 2013-11-22 23:49 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2015-10-05 21:20 - 2014-02-23 06:19 - 00000000 ____D C:\Program Files\Nikon
2015-10-05 21:20 - 2014-02-23 06:19 - 00000000 ____D C:\Program Files\Common Files\Nikon
2015-10-05 21:20 - 2014-02-23 06:18 - 00000000 ____H C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
2015-10-05 21:20 - 2014-02-23 06:18 - 00000000 _____ C:\Documents and Settings\Doma\Data aplikací\Flanger
2015-10-05 21:20 - 2013-11-16 16:43 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-10-05 21:20 - 2013-11-16 16:43 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-10-05 21:18 - 2015-05-25 20:32 - 00000000 ____D C:\Program Files\CCleaner
2015-10-05 21:18 - 2015-05-25 20:32 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2015-10-05 21:15 - 2013-11-17 14:05 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-10-05 21:15 - 2013-11-17 14:05 - 00000000 ____D C:\Program Files\Common Files\InstallShield
2015-10-04 19:30 - 2013-11-21 23:49 - 00095232 _____ C:\Documents and Settings\Doma\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-03 11:27 - 2013-11-16 17:38 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-09-27 23:26 - 2013-12-30 21:33 - 00000000 ____D C:\Program Files\Nokia
2015-09-27 23:23 - 2013-11-17 14:56 - 00000000 ____D C:\Program Files\Google
2015-09-19 22:08 - 2013-11-28 21:54 - 00000000 ____D C:\Documents and Settings\Doma\Nabídka Start\Hry
==================== Files in the root of some directories =======
2013-11-25 12:26 - 2013-11-25 12:26 - 12436848 _____ (Citrix Systems, Inc.) C:\Program Files\CitrixOnlinePluginWeb.exe
2014-02-23 06:18 - 2015-10-05 21:20 - 0000000 _____ () C:\Documents and Settings\Doma\Data aplikací\Flanger
2014-02-23 06:24 - 2014-02-23 06:24 - 0000268 ___RH () C:\Documents and Settings\Doma\Data aplikací\Folder Actions
2014-02-23 06:21 - 2014-02-23 06:21 - 0000268 ___RH () C:\Documents and Settings\Doma\Data aplikací\Fonts
2013-11-21 23:49 - 2015-10-04 19:30 - 0095232 _____ () C:\Documents and Settings\Doma\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\Doma\Local Settings\Temp\20n55tlx.dll
C:\Documents and Settings\Doma\Local Settings\Temp\AutoRun.exe
C:\Documents and Settings\Doma\Local Settings\Temp\AutoRunGUI.dll
C:\Documents and Settings\Doma\Local Settings\Temp\fp_pl_pfs_installer.exe
C:\Documents and Settings\Doma\Local Settings\Temp\Shockwave_Installer_FF.exe
C:\Documents and Settings\Doma\Local Settings\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================