Pomalé načítání www stránek
Napsal: 09 lis 2015 13:28
Zdravím vás PC doktoři a mám na vás prosbu: dostal jsem starší PC (AMD Athlon 1,01GHz; 1,5GB RAM; Win XP SP3; IE8) s rozsypaným systémovým diskem, který bylo nutno přeformátovat. Ovladače jsem nějak postahoval z netu s tím výsledkem, že PC funguje, ale pohyb po netu je velmi zdlouhavý - dlouho trvá, než se stránka načte. Zkoušel jsem PC "odvšivit" aplikací Superantispyware (najde drobnou havěť, žádné trojany), MBAM nejde spustit - při spuštění vyskočí klasická hláška (Omlouváme se, ale aplikaci bylo nutno ukončit).
Děkuji za případnou pomoc.
Přidávám log z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Petr at 2015-11-09 13:14:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 25 GB (66%) free of 38 GB
Total RAM: 1535 MB (59% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2013-01-31 15517472]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-01-31 1982312]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-08-02 577536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"HP Deskjet 3050A J611 series (NET)"=C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2011-06-08 1804648]
"DownloadAccelerator"=C:\Program Files\DAP\DAP.EXE [2015-08-13 4242064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Outlook Express.lnk - C:\Program Files\Outlook Express\msimn.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2013-05-07 115440]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (C:\Program Files\Mozilla Firefox)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2015-11-09 13:14:50 ----D---- C:\rsit
2015-11-09 13:14:50 ----D---- C:\Program Files\trend micro
2015-11-09 12:58:30 ----D---- C:\FRST
2015-11-09 10:47:23 ----D---- C:\WINDOWS\LastGood
2015-11-02 09:13:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-10-26 22:26:44 ----A---- C:\WINDOWS\imsins.BAK
2015-10-26 22:26:41 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2015-10-26 22:26:36 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2015-10-26 22:22:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-10-21 17:02:50 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2015-10-21 17:02:48 ----D---- C:\Program Files\Realtek
2015-10-20 11:55:52 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
======List of files/folders modified in the last 1 months======
2015-11-09 13:14:50 ----RD---- C:\Program Files
2015-11-09 13:03:52 ----D---- C:\WINDOWS\Prefetch
2015-11-09 12:59:39 ----D---- C:\WINDOWS
2015-11-09 12:56:08 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2015-11-09 10:48:31 ----HD---- C:\WINDOWS\inf
2015-11-09 10:48:27 ----D---- C:\WINDOWS\system32
2015-11-09 10:48:22 ----D---- C:\WINDOWS\ie8updates
2015-11-09 10:47:23 ----D---- C:\WINDOWS\system32\CatRoot2
2015-11-09 10:39:39 ----D---- C:\WINDOWS\Temp
2015-11-08 20:22:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-11-06 11:59:36 ----D---- C:\Program Files\Mozilla Firefox
2015-11-02 09:42:36 ----D---- C:\WINDOWS\system32\drivers
2015-11-02 09:09:19 ----SD---- C:\WINDOWS\Tasks
2015-11-02 09:08:38 ----SD---- C:\WINDOWS\system32\Microsoft
2015-10-28 07:43:31 ----D---- C:\Program Files\DAP
2015-10-26 22:25:40 ----D---- C:\WINDOWS\WinSxS
2015-10-26 12:58:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-22 14:52:19 ----D---- C:\Program Files\SUPERAntiSpyware
2015-10-22 11:27:03 ----D---- C:\WINDOWS\Debug
2015-10-21 17:02:48 ----HD---- C:\Program Files\InstallShield Installation Information
2015-10-20 11:56:00 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-15 08:23:12 ----D---- C:\WINDOWS\system32\MRT
2015-10-15 08:15:19 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-08-18 4017536]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-01-31 12648960]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2009-03-18 30336]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2014-07-23 142648]
R2 MSSQLSERVER;MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [2000-08-06 7442493]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2013-01-31 156448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-01-31 1259296]
R2 ssinstall;SInstalátor; C:\WINDOWS\System32\ssins.exe [2015-08-13 2324216]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-20 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2000-08-06 65602]
S3 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [2000-08-06 303170]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
A z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by Petr (administrator) on PETR-4JVRCM7S0E (09-11-2015 12:58:36)
Running from C:\Documents and Settings\Petr\Plocha
Loaded Profiles: Petr & UpdatusUser (Available Profiles: Petr & UpdatusUser & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\soundman.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Program Files\Outlook Express\msimn.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(PS Media s.r.o.) C:\WINDOWS\system32\ssins.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(forum.viry.cz) C:\Documents and Settings\Petr\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1982312 2013-01-31] ()
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-02] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [1804648 2011-06-08] (Hewlett-Packard Co.)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [DownloadAccelerator] => C:\Program Files\DAP\DAP.EXE [4242064 2015-08-13] (Speedbit Ltd.)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk [2015-08-09]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Outlook Express.lnk [2015-08-09]
ShortcutTarget: Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90D45704-6FB9-46B3-B135-038D6C79A684}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
URLSearchHook: [S-1-5-21-1614895754-1229272821-682003330-1004] ATTENTION => Default URLSearchHook is missing
Toolbar: HKU\S-1-5-21-1614895754-1229272821-682003330-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll [2008-04-14] (Společnost Microsoft)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default
FF Homepage: hxxp://www.facebook.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-20] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: YouTube™ Flash® Player - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2015-09-23]
FF Extension: YouTube Flash Video Player - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2015-11-06]
FF HKLM\...\Firefox\Extensions: [daplinkchecker@speedbit.com] - C:\Program Files\DAP\daplinkchecker => not found
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-08-16] [not signed]
FF HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Firefox\Extensions: [{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}] - C:\Program Files\DAP\DAPFireFox
FF Extension: Download Accelerator Plus (DAP) extension - C:\Program Files\DAP\DAPFireFox [2015-08-13] [not signed]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [7442493 2000-08-06] (Microsoft Corporation) [File not signed]
S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [65602 2000-08-06] (Microsoft Corporation) [File not signed]
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [303170 2000-08-06] (Microsoft Corporation) [File not signed]
R2 ssinstall; C:\WINDOWS\System32\ssins.exe [2324216 2015-08-13] (PS Media s.r.o.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [4017536 2006-08-18] (Realtek Semiconductor Corp.)
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 NTSIM; C:\WINDOWS\system32\ntsim.sys [7040 2003-07-17] (VIA Networking Technologies, Inc. ) [File not signed]
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 12:58 - 2015-11-09 12:59 - 00008724 _____ C:\Documents and Settings\Petr\Plocha\FRST.txt
2015-11-09 12:58 - 2015-11-09 12:58 - 00000000 ____D C:\FRST
2015-11-09 12:56 - 2015-11-09 12:56 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Petr\Plocha\FRSTLauncher.exe
2015-11-09 12:55 - 2015-11-09 12:55 - 01702400 _____ (Farbar) C:\Documents and Settings\Petr\Plocha\FRST.exe
2015-11-09 10:47 - 2015-11-09 10:48 - 00004460 _____ C:\WINDOWS\KB2879017-IE8.log
2015-11-09 10:47 - 2015-11-09 10:47 - 00000000 ____D C:\WINDOWS\LastGood
2015-11-02 09:13 - 2015-11-02 09:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes Anti-Malware
2015-11-02 09:13 - 2015-11-02 09:13 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-11-02 09:13 - 2015-10-05 09:50 - 00121560 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-02 09:13 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-27 18:46 - 2015-10-27 18:46 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Data aplikací\Temp
2015-10-26 22:26 - 2015-11-09 10:48 - 00013517 _____ C:\WINDOWS\iis6.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00012366 _____ C:\WINDOWS\FaxSetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00005912 _____ C:\WINDOWS\ocgen.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00005642 _____ C:\WINDOWS\tsoc.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00004181 _____ C:\WINDOWS\comsetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00003918 _____ C:\WINDOWS\msmqinst.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00002530 _____ C:\WINDOWS\ntdtcsetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00002166 _____ C:\WINDOWS\netfxocm.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00001374 _____ C:\WINDOWS\imsins.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000850 _____ C:\WINDOWS\MedCtrOC.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000772 _____ C:\WINDOWS\ocmsn.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000622 _____ C:\WINDOWS\tabletoc.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000618 _____ C:\WINDOWS\msgsocm.log
2015-10-26 22:26 - 2015-10-29 18:24 - 00019515 _____ C:\WINDOWS\setupapi.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00008287 _____ C:\WINDOWS\Wdf01009Inst.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00001393 _____ C:\WINDOWS\imsins.BAK
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 _____ C:\WINDOWS\setupact.log
2015-10-26 22:26 - 2008-11-07 18:55 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
2015-10-26 22:22 - 2015-11-02 09:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Program Files\Realtek
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Documents and Settings\Petr\Nabídka Start\Programy\WinRAR
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\WinRAR
2015-10-21 17:02 - 2009-03-25 13:29 - 00130432 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\Rtnicxp.sys
2015-10-21 17:02 - 2009-03-03 19:18 - 00073728 _____ C:\WINDOWS\system32\RtNicProp32.dll
2015-10-20 11:55 - 2015-10-20 11:55 - 18833096 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 12:59 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Temp
2015-11-09 12:58 - 2015-08-08 13:27 - 00000000 ___HD C:\Documents and Settings\Petr\Local Settings\Data aplikací
2015-11-09 12:58 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr\Plocha
2015-11-09 12:56 - 2015-08-13 22:32 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\TEMP
2015-11-09 12:55 - 2015-08-17 14:29 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-09 10:48 - 2015-08-10 09:27 - 00000000 ____D C:\WINDOWS\ie8updates
2015-11-09 10:48 - 2015-08-08 14:02 - 01578409 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-09 10:39 - 2015-08-13 22:27 - 00000000 _____ C:\WINDOWS\system32\sinstall.log
2015-11-09 10:39 - 2015-08-08 14:54 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-09 10:39 - 2015-08-08 14:54 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-09 10:39 - 2015-08-08 13:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-08 20:22 - 2015-08-08 13:27 - 00000272 ___SH C:\Documents and Settings\Petr\ntuser.ini
2015-11-08 20:22 - 2015-08-08 13:21 - 00032562 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-08 20:13 - 2015-08-08 14:11 - 00001487 _____ C:\Documents and Settings\Petr\Plocha\Průzkumník Windows.lnk
2015-11-07 08:30 - 2015-08-09 12:14 - 00000240 _____ C:\Documents and Settings\Petr\Plocha\Servis 24.url
2015-11-06 11:59 - 2015-08-29 15:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-06 09:00 - 2001-10-25 13:00 - 00002262 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-05 07:41 - 2015-08-08 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-11-02 09:16 - 2015-08-08 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-11-02 09:16 - 2015-08-08 13:27 - 00000000 __RHD C:\Documents and Settings\Petr\Data aplikací
2015-11-02 09:13 - 2015-08-08 14:51 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-11-02 08:42 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Dokumenty\Obrázky
2015-10-28 16:24 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Oblíbené položky
2015-10-28 07:43 - 2015-08-13 22:32 - 00000000 ____D C:\Program Files\DAP
2015-10-27 18:11 - 2015-08-08 13:21 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-10-26 22:30 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr
2015-10-26 12:58 - 2015-08-08 14:52 - 01073660 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-22 14:52 - 2015-08-12 13:52 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-10-21 17:02 - 2015-08-08 15:04 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-10-21 17:02 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Nabídka Start\Programy
2015-10-20 11:56 - 2015-08-17 13:43 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-20 11:55 - 2015-08-17 13:43 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-10-15 08:23 - 2015-08-09 13:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-15 08:15 - 2015-08-09 13:09 - 141105520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-10 11:36 - 2015-08-08 14:59 - 00000178 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini
==================== Files in the root of some directories =======
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:37.3 GB) (Free:24.79 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:9.76 GB) (Free:5.55 GB) FAT32
Drive e: (Nový svazek) (Fixed) (Total:9.77 GB) (Free:9.7 GB) NTFS
Drive f: (New Volume) (Fixed) (Total:9.1 GB) (Free:9.04 GB) NTFS
Available physical RAM: 898.79 MB
Total physical RAM: 1535.49 MB
Percentage of memory in use: 41%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 37.3 GB) (Disk ID: E80CE80C)
Partition 1: (Active) - (Size=37.3 GB) - (Type=07 NTFS)
Disk: 1 (Size: 28.6 GB) (Disk ID: 50DC50DC)
Partition 1: (Active) - (Size=9.8 GB) - (Type=0C)
Partition 2: (Not Active) - (Size=18.9 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:56E2E879
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Petr\Plocha" je 1 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox (C:\\Program Files\\Mozilla Firefox)"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================
Děkuji za případnou pomoc.
Přidávám log z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Petr at 2015-11-09 13:14:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 25 GB (66%) free of 38 GB
Total RAM: 1535 MB (59% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2013-01-31 15517472]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-01-31 1982312]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-08-02 577536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"HP Deskjet 3050A J611 series (NET)"=C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2011-06-08 1804648]
"DownloadAccelerator"=C:\Program Files\DAP\DAP.EXE [2015-08-13 4242064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Outlook Express.lnk - C:\Program Files\Outlook Express\msimn.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2013-05-07 115440]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (C:\Program Files\Mozilla Firefox)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2015-11-09 13:14:50 ----D---- C:\rsit
2015-11-09 13:14:50 ----D---- C:\Program Files\trend micro
2015-11-09 12:58:30 ----D---- C:\FRST
2015-11-09 10:47:23 ----D---- C:\WINDOWS\LastGood
2015-11-02 09:13:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-10-26 22:26:44 ----A---- C:\WINDOWS\imsins.BAK
2015-10-26 22:26:41 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2015-10-26 22:26:36 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2015-10-26 22:22:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-10-21 17:02:50 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2015-10-21 17:02:48 ----D---- C:\Program Files\Realtek
2015-10-20 11:55:52 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
======List of files/folders modified in the last 1 months======
2015-11-09 13:14:50 ----RD---- C:\Program Files
2015-11-09 13:03:52 ----D---- C:\WINDOWS\Prefetch
2015-11-09 12:59:39 ----D---- C:\WINDOWS
2015-11-09 12:56:08 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2015-11-09 10:48:31 ----HD---- C:\WINDOWS\inf
2015-11-09 10:48:27 ----D---- C:\WINDOWS\system32
2015-11-09 10:48:22 ----D---- C:\WINDOWS\ie8updates
2015-11-09 10:47:23 ----D---- C:\WINDOWS\system32\CatRoot2
2015-11-09 10:39:39 ----D---- C:\WINDOWS\Temp
2015-11-08 20:22:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-11-06 11:59:36 ----D---- C:\Program Files\Mozilla Firefox
2015-11-02 09:42:36 ----D---- C:\WINDOWS\system32\drivers
2015-11-02 09:09:19 ----SD---- C:\WINDOWS\Tasks
2015-11-02 09:08:38 ----SD---- C:\WINDOWS\system32\Microsoft
2015-10-28 07:43:31 ----D---- C:\Program Files\DAP
2015-10-26 22:25:40 ----D---- C:\WINDOWS\WinSxS
2015-10-26 12:58:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-22 14:52:19 ----D---- C:\Program Files\SUPERAntiSpyware
2015-10-22 11:27:03 ----D---- C:\WINDOWS\Debug
2015-10-21 17:02:48 ----HD---- C:\Program Files\InstallShield Installation Information
2015-10-20 11:56:00 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-15 08:23:12 ----D---- C:\WINDOWS\system32\MRT
2015-10-15 08:15:19 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-08-18 4017536]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-01-31 12648960]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2009-03-18 30336]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2014-07-23 142648]
R2 MSSQLSERVER;MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [2000-08-06 7442493]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2013-01-31 156448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-01-31 1259296]
R2 ssinstall;SInstalátor; C:\WINDOWS\System32\ssins.exe [2015-08-13 2324216]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-20 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2000-08-06 65602]
S3 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [2000-08-06 303170]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
A z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by Petr (administrator) on PETR-4JVRCM7S0E (09-11-2015 12:58:36)
Running from C:\Documents and Settings\Petr\Plocha
Loaded Profiles: Petr & UpdatusUser (Available Profiles: Petr & UpdatusUser & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\soundman.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Program Files\Outlook Express\msimn.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(PS Media s.r.o.) C:\WINDOWS\system32\ssins.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(forum.viry.cz) C:\Documents and Settings\Petr\Plocha\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1982312 2013-01-31] ()
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-02] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [1804648 2011-06-08] (Hewlett-Packard Co.)
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Run: [DownloadAccelerator] => C:\Program Files\DAP\DAP.EXE [4242064 2015-08-13] (Speedbit Ltd.)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk [2015-08-09]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Outlook Express.lnk [2015-08-09]
ShortcutTarget: Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90D45704-6FB9-46B3-B135-038D6C79A684}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1614895754-1229272821-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
URLSearchHook: [S-1-5-21-1614895754-1229272821-682003330-1004] ATTENTION => Default URLSearchHook is missing
Toolbar: HKU\S-1-5-21-1614895754-1229272821-682003330-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll [2008-04-14] (Společnost Microsoft)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default
FF Homepage: hxxp://www.facebook.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-20] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: YouTube™ Flash® Player - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2015-09-23]
FF Extension: YouTube Flash Video Player - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\x21waaef.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2015-11-06]
FF HKLM\...\Firefox\Extensions: [daplinkchecker@speedbit.com] - C:\Program Files\DAP\daplinkchecker => not found
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-08-16] [not signed]
FF HKU\S-1-5-21-1614895754-1229272821-682003330-1003\...\Firefox\Extensions: [{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}] - C:\Program Files\DAP\DAPFireFox
FF Extension: Download Accelerator Plus (DAP) extension - C:\Program Files\DAP\DAPFireFox [2015-08-13] [not signed]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [7442493 2000-08-06] (Microsoft Corporation) [File not signed]
S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [65602 2000-08-06] (Microsoft Corporation) [File not signed]
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [303170 2000-08-06] (Microsoft Corporation) [File not signed]
R2 ssinstall; C:\WINDOWS\System32\ssins.exe [2324216 2015-08-13] (PS Media s.r.o.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [4017536 2006-08-18] (Realtek Semiconductor Corp.)
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 NTSIM; C:\WINDOWS\system32\ntsim.sys [7040 2003-07-17] (VIA Networking Technologies, Inc. ) [File not signed]
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 12:58 - 2015-11-09 12:59 - 00008724 _____ C:\Documents and Settings\Petr\Plocha\FRST.txt
2015-11-09 12:58 - 2015-11-09 12:58 - 00000000 ____D C:\FRST
2015-11-09 12:56 - 2015-11-09 12:56 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Petr\Plocha\FRSTLauncher.exe
2015-11-09 12:55 - 2015-11-09 12:55 - 01702400 _____ (Farbar) C:\Documents and Settings\Petr\Plocha\FRST.exe
2015-11-09 10:47 - 2015-11-09 10:48 - 00004460 _____ C:\WINDOWS\KB2879017-IE8.log
2015-11-09 10:47 - 2015-11-09 10:47 - 00000000 ____D C:\WINDOWS\LastGood
2015-11-02 09:13 - 2015-11-02 09:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes Anti-Malware
2015-11-02 09:13 - 2015-11-02 09:13 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2015-11-02 09:13 - 2015-10-05 09:50 - 00121560 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-02 09:13 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-27 18:46 - 2015-10-27 18:46 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Data aplikací\Temp
2015-10-26 22:26 - 2015-11-09 10:48 - 00013517 _____ C:\WINDOWS\iis6.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00012366 _____ C:\WINDOWS\FaxSetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00005912 _____ C:\WINDOWS\ocgen.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00005642 _____ C:\WINDOWS\tsoc.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00004181 _____ C:\WINDOWS\comsetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00003918 _____ C:\WINDOWS\msmqinst.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00002530 _____ C:\WINDOWS\ntdtcsetup.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00002166 _____ C:\WINDOWS\netfxocm.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00001374 _____ C:\WINDOWS\imsins.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000850 _____ C:\WINDOWS\MedCtrOC.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000772 _____ C:\WINDOWS\ocmsn.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000622 _____ C:\WINDOWS\tabletoc.log
2015-10-26 22:26 - 2015-11-09 10:48 - 00000618 _____ C:\WINDOWS\msgsocm.log
2015-10-26 22:26 - 2015-10-29 18:24 - 00019515 _____ C:\WINDOWS\setupapi.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00008287 _____ C:\WINDOWS\Wdf01009Inst.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00001393 _____ C:\WINDOWS\imsins.BAK
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-26 22:26 - 2015-10-26 22:26 - 00000000 _____ C:\WINDOWS\setupact.log
2015-10-26 22:26 - 2008-11-07 18:55 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
2015-10-26 22:22 - 2015-11-02 09:16 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Program Files\Realtek
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Documents and Settings\Petr\Nabídka Start\Programy\WinRAR
2015-10-21 17:02 - 2015-10-21 17:02 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\WinRAR
2015-10-21 17:02 - 2009-03-25 13:29 - 00130432 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\Rtnicxp.sys
2015-10-21 17:02 - 2009-03-03 19:18 - 00073728 _____ C:\WINDOWS\system32\RtNicProp32.dll
2015-10-20 11:55 - 2015-10-20 11:55 - 18833096 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 12:59 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr\Local Settings\Temp
2015-11-09 12:58 - 2015-08-08 13:27 - 00000000 ___HD C:\Documents and Settings\Petr\Local Settings\Data aplikací
2015-11-09 12:58 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr\Plocha
2015-11-09 12:56 - 2015-08-13 22:32 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\TEMP
2015-11-09 12:55 - 2015-08-17 14:29 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-09 10:48 - 2015-08-10 09:27 - 00000000 ____D C:\WINDOWS\ie8updates
2015-11-09 10:48 - 2015-08-08 14:02 - 01578409 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-09 10:39 - 2015-08-13 22:27 - 00000000 _____ C:\WINDOWS\system32\sinstall.log
2015-11-09 10:39 - 2015-08-08 14:54 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-09 10:39 - 2015-08-08 14:54 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-09 10:39 - 2015-08-08 13:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-08 20:22 - 2015-08-08 13:27 - 00000272 ___SH C:\Documents and Settings\Petr\ntuser.ini
2015-11-08 20:22 - 2015-08-08 13:21 - 00032562 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-08 20:13 - 2015-08-08 14:11 - 00001487 _____ C:\Documents and Settings\Petr\Plocha\Průzkumník Windows.lnk
2015-11-07 08:30 - 2015-08-09 12:14 - 00000240 _____ C:\Documents and Settings\Petr\Plocha\Servis 24.url
2015-11-06 11:59 - 2015-08-29 15:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-06 09:00 - 2001-10-25 13:00 - 00002262 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-05 07:41 - 2015-08-08 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-11-02 09:16 - 2015-08-08 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-11-02 09:16 - 2015-08-08 13:27 - 00000000 __RHD C:\Documents and Settings\Petr\Data aplikací
2015-11-02 09:13 - 2015-08-08 14:51 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-11-02 08:42 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Dokumenty\Obrázky
2015-10-28 16:24 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Oblíbené položky
2015-10-28 07:43 - 2015-08-13 22:32 - 00000000 ____D C:\Program Files\DAP
2015-10-27 18:11 - 2015-08-08 13:21 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-10-26 22:30 - 2015-08-08 13:27 - 00000000 ____D C:\Documents and Settings\Petr
2015-10-26 12:58 - 2015-08-08 14:52 - 01073660 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-22 14:52 - 2015-08-12 13:52 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-10-21 17:02 - 2015-08-08 15:04 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-10-21 17:02 - 2015-08-08 13:27 - 00000000 ___RD C:\Documents and Settings\Petr\Nabídka Start\Programy
2015-10-20 11:56 - 2015-08-17 13:43 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-20 11:55 - 2015-08-17 13:43 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-10-15 08:23 - 2015-08-09 13:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-15 08:15 - 2015-08-09 13:09 - 141105520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-10 11:36 - 2015-08-08 14:59 - 00000178 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini
==================== Files in the root of some directories =======
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:37.3 GB) (Free:24.79 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:9.76 GB) (Free:5.55 GB) FAT32
Drive e: (Nový svazek) (Fixed) (Total:9.77 GB) (Free:9.7 GB) NTFS
Drive f: (New Volume) (Fixed) (Total:9.1 GB) (Free:9.04 GB) NTFS
Available physical RAM: 898.79 MB
Total physical RAM: 1535.49 MB
Percentage of memory in use: 41%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 37.3 GB) (Disk ID: E80CE80C)
Partition 1: (Active) - (Size=37.3 GB) - (Type=07 NTFS)
Disk: 1 (Size: 28.6 GB) (Disk ID: 50DC50DC)
Partition 1: (Active) - (Size=9.8 GB) - (Type=0C)
Partition 2: (Not Active) - (Size=18.9 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:56E2E879
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Documents and Settings\Petr\Plocha" je 1 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox (C:\\Program Files\\Mozilla Firefox)"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
==================== End Of Log ==============================