Antivir zachytil Ransom, prosím o kontrolu logu
Napsal: 04 lis 2015 09:19
Zdravím,
antivir zachytil Ransom/Isda. Otrava se nijak neprojevil, ale projistotu prosím o kontrolu logu. PC se nekontrolovalo tak rok a navíc se mi stejně poslední dobou zdá nějaké zpomalené, takže prověrka mu jen prospěje.
Díky
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-10-2015
Ran by HP (administrator) on HOVORCI (04-11-2015 09:11:21)
Running from C:\Documents and Settings\HP\Plocha
Loaded Profiles: HP (Available Profiles: HP & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\Program Files\UPHClean\uphclean.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-05-27] (Google Inc.)
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [] => [X]
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [NokiaOviSuite2] => C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
HKU\S-1-5-21-790525478-117609710-839522115-1004\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-05-27] (Google Inc.)
HKU\S-1-5-21-790525478-117609710-839522115-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\System32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
Startup: C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění\53.tmp [2015-11-04] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{9138E8A4-2BCF-4AA2-AC70-174176F177EB}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Internet Explorer:
==================
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=cs-CZ&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fwww.seznam.cz%2F&OSP=http%3A%2F%2Fwww.google.com%2Fsearch%3Fq%3D%7BsearchTerms%7D%26sourceid%3Die7%26rls%3Dcom.microsoft%3Aen%2DUS%26ie%3Dutf8%26oe%3Dutf8%26rlz%3D
HKU\S-1-5-21-790525478-117609710-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> DefaultScope {B373D2CA-9723-4642-ACD7-C280BA53E8EF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> {B373D2CA-9723-4642-ACD7-C280BA53E8EF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll => No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243448011171
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243448054093
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\HP\Data aplikací\Mozilla\Firefox\Profiles\uneb2417.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2009-04-28] (Adobe Systems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-790525478-117609710-839522115-1004: @kb-ext.cz/PKIComponent -> C:\Documents and Settings\HP\Data aplikací\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll [2013-09-26] (Komerční banka, a.s.)
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff => not found
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 UPHClean; C:\Program Files\UPHClean\uphclean.exe [192573 2004-03-04] (Microsoft Corporation) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ac97intc; C:\WINDOWS\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 MpKsl39057249; c:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CFCD4A1C-C923-4BA7-B6F5-FB22794CF6C6}\MpKsl39057249.sys [39168 2015-11-04] (Microsoft Corporation)
S3 nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [731648 2001-08-17] (NVIDIA Corporation)
R2 pmem; C:\WINDOWS\System32\DRIVERS\pmemnt.sys [7012 2004-08-02] (Microsoft Corporation)
S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-04 09:11 - 2015-11-04 09:11 - 00009394 _____ C:\Documents and Settings\HP\Plocha\FRST.txt
2015-11-04 09:11 - 2015-11-04 09:11 - 00000000 ____D C:\FRST
2015-11-04 09:03 - 2015-11-04 09:04 - 01701888 _____ (Farbar) C:\Documents and Settings\HP\Plocha\FRST.exe
2015-11-04 01:38 - 2015-10-30 18:10 - 01694208 _____ C:\Documents and Settings\HP\Plocha\adwcleaner_5.015.exe
2015-11-01 16:48 - 2015-11-01 16:48 - 00029696 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
2015-10-30 18:13 - 2015-11-04 01:39 - 00000000 ____D C:\AdwCleaner
2015-10-26 19:34 - 2015-10-26 19:34 - 00000000 __SHD C:\Documents and Settings\HP\IECompatCache
2015-10-18 01:33 - 2015-10-18 07:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-04 09:11 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP\Plocha
2015-11-04 09:11 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP\Local Settings\Temp
2015-11-04 09:08 - 2009-05-27 20:11 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{5D0B30D7-FF8F-4D24-92BE-6881A78A51DD}.job
2015-11-04 08:33 - 2009-05-27 18:45 - 00032424 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-04 04:14 - 2015-09-15 03:09 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0ef5b89f9a383.job
2015-11-04 04:14 - 2015-08-30 19:06 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e34e8eb623c0.job
2015-11-04 01:24 - 2013-10-27 13:02 - 00000396 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2015-11-04 00:54 - 2009-05-27 20:31 - 00191674 _____ C:\WINDOWS\setupact.log
2015-11-04 00:50 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění
2015-11-03 22:45 - 2015-07-15 21:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d09039f6744036.job
2015-11-03 20:11 - 2015-07-15 21:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3e6ea708e4.job
2015-11-03 14:38 - 2009-05-27 19:11 - 01227523 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-03 14:38 - 2009-05-27 18:45 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2015-11-03 13:22 - 2009-05-27 20:33 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-03 13:22 - 2009-05-27 20:33 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-03 13:22 - 2009-05-27 18:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-03 13:22 - 2004-08-02 19:03 - 00004598 _____ C:\WINDOWS\system32\nvapps.xml
2015-11-03 13:22 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-02 06:01 - 2012-01-20 19:25 - 00000000 ____D C:\Documents and Settings\HP\Data aplikací\foobar2000
2015-11-01 17:16 - 2011-12-17 16:40 - 00000000 ___HD C:\Documents and Settings\HP\Local Settings\Data aplikací
2015-11-01 17:16 - 2009-05-27 20:31 - 00000000 ___RD C:\Documents and Settings\All Users\Data aplikací
2015-10-31 03:16 - 2012-07-16 00:46 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Hudba
2015-10-30 18:54 - 2015-02-22 17:00 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Stažené soubory
2015-10-30 18:52 - 2012-02-22 16:04 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Platby
2015-10-26 19:34 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP
2015-10-25 13:20 - 2009-05-27 20:32 - 00714754 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-25 05:08 - 2011-12-21 08:57 - 00147968 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-20 20:32 - 2011-12-21 01:15 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Filmy
2015-10-18 14:02 - 2015-03-08 23:51 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-16 17:20 - 2014-12-02 02:00 - 00000000 ____D C:\Program Files\DOSBox-0.74
2015-10-16 16:44 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty
2015-10-14 01:21 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Obrázky
==================== Files in the root of some directories =======
2013-09-12 11:48 - 2013-09-12 12:00 - 0000004 _____ () C:\Documents and Settings\HP\Data aplikací\settings.ini
2011-12-21 08:57 - 2015-10-25 05:08 - 0147968 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-01 16:48 - 2015-11-01 16:48 - 0029696 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
antivir zachytil Ransom/Isda. Otrava se nijak neprojevil, ale projistotu prosím o kontrolu logu. PC se nekontrolovalo tak rok a navíc se mi stejně poslední dobou zdá nějaké zpomalené, takže prověrka mu jen prospěje.
Díky
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-10-2015
Ran by HP (administrator) on HOVORCI (04-11-2015 09:11:21)
Running from C:\Documents and Settings\HP\Plocha
Loaded Profiles: HP (Available Profiles: HP & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\Program Files\UPHClean\uphclean.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-05-27] (Google Inc.)
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [] => [X]
HKU\S-1-5-21-790525478-117609710-839522115-1003\...\Run: [NokiaOviSuite2] => C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
HKU\S-1-5-21-790525478-117609710-839522115-1004\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-05-27] (Google Inc.)
HKU\S-1-5-21-790525478-117609710-839522115-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\System32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
Startup: C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění\53.tmp [2015-11-04] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{9138E8A4-2BCF-4AA2-AC70-174176F177EB}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Internet Explorer:
==================
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-790525478-117609710-839522115-1003\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=cs-CZ&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fwww.seznam.cz%2F&OSP=http%3A%2F%2Fwww.google.com%2Fsearch%3Fq%3D%7BsearchTerms%7D%26sourceid%3Die7%26rls%3Dcom.microsoft%3Aen%2DUS%26ie%3Dutf8%26oe%3Dutf8%26rlz%3D
HKU\S-1-5-21-790525478-117609710-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> DefaultScope {B373D2CA-9723-4642-ACD7-C280BA53E8EF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> {B373D2CA-9723-4642-ACD7-C280BA53E8EF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll => No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-117609710-839522115-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243448011171
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243448054093
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\HP\Data aplikací\Mozilla\Firefox\Profiles\uneb2417.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2009-04-28] (Adobe Systems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-790525478-117609710-839522115-1004: @kb-ext.cz/PKIComponent -> C:\Documents and Settings\HP\Data aplikací\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll [2013-09-26] (Komerční banka, a.s.)
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff => not found
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 UPHClean; C:\Program Files\UPHClean\uphclean.exe [192573 2004-03-04] (Microsoft Corporation) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ac97intc; C:\WINDOWS\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 MpKsl39057249; c:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CFCD4A1C-C923-4BA7-B6F5-FB22794CF6C6}\MpKsl39057249.sys [39168 2015-11-04] (Microsoft Corporation)
S3 nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [731648 2001-08-17] (NVIDIA Corporation)
R2 pmem; C:\WINDOWS\System32\DRIVERS\pmemnt.sys [7012 2004-08-02] (Microsoft Corporation)
S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-04 09:11 - 2015-11-04 09:11 - 00009394 _____ C:\Documents and Settings\HP\Plocha\FRST.txt
2015-11-04 09:11 - 2015-11-04 09:11 - 00000000 ____D C:\FRST
2015-11-04 09:03 - 2015-11-04 09:04 - 01701888 _____ (Farbar) C:\Documents and Settings\HP\Plocha\FRST.exe
2015-11-04 01:38 - 2015-10-30 18:10 - 01694208 _____ C:\Documents and Settings\HP\Plocha\adwcleaner_5.015.exe
2015-11-01 16:48 - 2015-11-01 16:48 - 00029696 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
2015-10-30 18:13 - 2015-11-04 01:39 - 00000000 ____D C:\AdwCleaner
2015-10-26 19:34 - 2015-10-26 19:34 - 00000000 __SHD C:\Documents and Settings\HP\IECompatCache
2015-10-18 01:33 - 2015-10-18 07:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-04 09:11 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP\Plocha
2015-11-04 09:11 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP\Local Settings\Temp
2015-11-04 09:08 - 2009-05-27 20:11 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{5D0B30D7-FF8F-4D24-92BE-6881A78A51DD}.job
2015-11-04 08:33 - 2009-05-27 18:45 - 00032424 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-04 04:14 - 2015-09-15 03:09 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0ef5b89f9a383.job
2015-11-04 04:14 - 2015-08-30 19:06 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e34e8eb623c0.job
2015-11-04 01:24 - 2013-10-27 13:02 - 00000396 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2015-11-04 00:54 - 2009-05-27 20:31 - 00191674 _____ C:\WINDOWS\setupact.log
2015-11-04 00:50 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Nabídka Start\Programy\Po spuštění
2015-11-03 22:45 - 2015-07-15 21:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d09039f6744036.job
2015-11-03 20:11 - 2015-07-15 21:40 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3e6ea708e4.job
2015-11-03 14:38 - 2009-05-27 19:11 - 01227523 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-03 14:38 - 2009-05-27 18:45 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2015-11-03 13:22 - 2009-05-27 20:33 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-03 13:22 - 2009-05-27 20:33 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-03 13:22 - 2009-05-27 18:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-03 13:22 - 2004-08-02 19:03 - 00004598 _____ C:\WINDOWS\system32\nvapps.xml
2015-11-03 13:22 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-02 06:01 - 2012-01-20 19:25 - 00000000 ____D C:\Documents and Settings\HP\Data aplikací\foobar2000
2015-11-01 17:16 - 2011-12-17 16:40 - 00000000 ___HD C:\Documents and Settings\HP\Local Settings\Data aplikací
2015-11-01 17:16 - 2009-05-27 20:31 - 00000000 ___RD C:\Documents and Settings\All Users\Data aplikací
2015-10-31 03:16 - 2012-07-16 00:46 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Hudba
2015-10-30 18:54 - 2015-02-22 17:00 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Stažené soubory
2015-10-30 18:52 - 2012-02-22 16:04 - 00000000 ____D C:\Documents and Settings\HP\Dokumenty\Platby
2015-10-26 19:34 - 2011-12-17 16:40 - 00000000 ____D C:\Documents and Settings\HP
2015-10-25 13:20 - 2009-05-27 20:32 - 00714754 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-25 05:08 - 2011-12-21 08:57 - 00147968 _____ C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-20 20:32 - 2011-12-21 01:15 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Filmy
2015-10-18 14:02 - 2015-03-08 23:51 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-16 17:20 - 2014-12-02 02:00 - 00000000 ____D C:\Program Files\DOSBox-0.74
2015-10-16 16:44 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty
2015-10-14 01:21 - 2011-12-17 16:40 - 00000000 ___RD C:\Documents and Settings\HP\Dokumenty\Obrázky
==================== Files in the root of some directories =======
2013-09-12 11:48 - 2013-09-12 12:00 - 0000004 _____ () C:\Documents and Settings\HP\Data aplikací\settings.ini
2011-12-21 08:57 - 2015-10-25 05:08 - 0147968 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-01 16:48 - 2015-11-01 16:48 - 0029696 _____ () C:\Documents and Settings\HP\Local Settings\Data aplikací\MSGBOX.EXE
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================