zdravím a děkuji .
tady je odkaz
https://www.virustotal.com/cs/file/c759 ... 447351540/
a log :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by Dodo (administrator) on GROUP-4B24797DB (12-11-2015 19:28:49)
Running from C:\Documents and Settings\Dodo\Plocha
Loaded Profiles: Dodo (Available Profiles: Dodo & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Check Point Software Technologies LTD) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
(Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Check Point Software Technologies LTD) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Black List Software) C:\Program Files\Assassin G13\assassin.exe
(Flux Software LLC) C:\Documents and Settings\Dodo\Local Settings\Data aplikací\FluxSoftware\Flux\flux.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-12-16] (Check Point Software Technologies LTD)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1434920 2009-03-05] (Synaptics Incorporated)
HKLM\...\Run: [snuvcdsm] => C:\WINDOWS\snuvcdsm.exe [30080 2011-01-13] ()
HKLM\...\Run: [snp2uvc] => rundll32.exe C:\WINDOWS\system32\csnp2uvc.dll,ResetCIDS
HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Assassin G13] => C:\Program Files\Assassin G13\assassin.exe [1318912 2006-12-21] (Black List Software)
HKLM\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKU\S-1-5-21-854245398-1677128483-842925246-1004\...\Run: [f.lux] => C:\Documents and Settings\Dodo\Local Settings\Data aplikací\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-854245398-1677128483-842925246-1004\...\Run: [GoogleChromeAutoLaunch_498CA8CB76697D2490F3CA2E3BD5BAD8] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-07-25] (Google Inc.)
HKU\S-1-5-21-854245398-1677128483-842925246-1004\...\Run: [SlimDrivers] => C:\Program Files\SlimDrivers\SlimDrivers.exe [29731096 2015-02-27] (SlimWare Utilities, Inc.)
HKU\S-1-5-21-854245398-1677128483-842925246-1004\...\Run: [Loaris Trojan Remover] => C:\Program Files\Loaris\Trojan Remover\ltr.exe [9434624 2014-08-15] (Loaris Inc.)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2010-01-14] (Microsoft Corporation)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2013-05-09] (AVAST Software)
BootExecute: autocheck autochk * sdnclean.exesprestrt
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{56F82C23-E7A4-4152-90FF-DA03751B4002}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-854245398-1677128483-842925246-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.msn.com/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-854245398-1677128483-842925246-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09] (AVAST Software)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09] (AVAST Software)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Dodo\Data aplikací\Mozilla\Firefox\Profiles\WfXWPG0P.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-09-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll [2010-01-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-854245398-1677128483-842925246-1004: @citrixonline.com/appdetectorplugin -> C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Citrix\Plugins\104\npappdetector.dll [2015-03-27] (Citrix Online)
FF Extension: Avira Browser Safety - C:\Documents and Settings\Dodo\Data aplikací\Mozilla\Firefox\Profiles\WfXWPG0P.default\Extensions\
abs@avira.com [2015-04-18] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-06-01] [not signed]
FF Extension: No Name - C:\Documents and Settings\Dodo\Data aplikacĂ\Mozilla\Firefox\Profiles\WfXWPG0P.default\extensions\
abs@avira.com [not found]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Sniply - Drive Conversion Through Content) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aepeihpnlhiiipbchlidcipfpiaecpkd [2015-10-26]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-22]
CHR Extension: (AdBlock) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-10-15]
CHR Extension: (LastPass: Free Password Manager) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-10-28]
CHR Extension: (Tag Assistant (by Google)) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2015-10-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-21]
CHR Extension: (Fast Video Downloader) - C:\Documents and Settings\Dodo\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nocpfkkbaekckhcoekockfbidpcjgkbd [2015-08-31]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-12] (Adobe Systems) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [2445816 2013-12-16] (Check Point Software Technologies LTD)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [50704 2013-10-15] (Check Point Software Technologies, Ltd.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [2067936 2012-04-30] (Atheros Communications, Inc.)
R2 aswFsBlk; C:\WINDOWS\system32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\Drivers\AswRdr.sys [49760 2013-05-09] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
S1 aswSnx; C:\WINDOWS\system32\Drivers\aswSnx.sys [770344 2015-11-12] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\Drivers\aswSP.sys [369584 2015-11-12] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [175176 2015-11-12] ()
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [47272 2009-04-01] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 CnxtHdAudService; C:\WINDOWS\System32\drivers\CHDAU32.sys [815616 2000-01-01] (Conexant Systems Inc.)
S1 DumpDrv; C:\WINDOWS\system32\Drivers\DumpDrv.sys [9472 2010-01-14] (Microsoft Corporation)
R3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [82072 2000-01-01] (Atheros Communications, Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2010-01-14] (Microsoft Corporation)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [10320 2013-09-30] ()
R3 SmbDrvI; C:\WINDOWS\System32\DRIVERS\Smb_driver_Intel.sys [28656 2014-08-17] (Synaptics Incorporated)
R3 SNP2UVC; C:\WINDOWS\System32\DRIVERS\snp2uvc.sys [1766784 2011-01-13] ()
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [31848 2015-09-10] (Avira Operations GmbH & Co. KG)
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [529640 2013-12-16] (Check Point Software Technologies LTD)
U5 Browser; C:\WINDOWS\system32\svchost.exe [14848 2010-01-14] (Microsoft Corporation)
R3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MEMSWEEP2; \??\C:\WINDOWS\system32\SophosMEMSWEEP.SYS [X]
U5 Messenger; C:\WINDOWS\system32\svchost.exe [14848 2010-01-14] (Microsoft Corporation)
U5 MRxSmb; C:\Windows\System32\Drivers\MRxSmb.sys [456704 2010-01-14] (Microsoft Corporation)
U5 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2008-04-14] (Microsoft Corporation)
S3 nlqrmejr; no ImagePath
S3 poshxhhc; no ImagePath
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
U5 Sdbus; C:\Windows\System32\Drivers\Sdbus.sys [80384 2010-01-14] (Microsoft Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [225856 2010-01-14] (Microsoft Corporation)
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
U3 mbr; \??\C:\DOCUME~1\Dodo\LOCALS~1\Temp\mbr.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-12 19:22 - 2015-11-12 19:22 - 00000401 _____ C:\Documents and Settings\Dodo\Plocha\Addition.txt
2015-11-12 19:21 - 2015-11-12 19:28 - 00014634 _____ C:\Documents and Settings\Dodo\Plocha\FRST.txt
2015-11-12 02:33 - 2015-11-12 02:33 - 00001689 _____ C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
2015-11-12 02:33 - 2015-11-12 02:33 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys.sum
2015-11-12 02:33 - 2015-11-12 02:33 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSP.sys.sum
2015-11-12 02:33 - 2015-11-12 02:33 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSnx.sys.sum
2015-11-12 02:33 - 2015-11-12 02:33 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
2015-11-12 02:33 - 2013-05-09 10:59 - 00029816 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswFsBlk.sys
2015-11-12 02:32 - 2015-11-12 02:33 - 00770344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-11-12 02:32 - 2015-11-12 02:33 - 00369584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-11-12 02:32 - 2015-11-12 02:33 - 00175176 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-11-12 02:32 - 2015-11-12 02:32 - 00000312 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-11-12 02:32 - 2013-05-09 10:59 - 00066336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-11-12 02:32 - 2013-05-09 10:59 - 00056080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-11-12 02:32 - 2013-05-09 10:59 - 00049760 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-11-12 02:32 - 2013-05-09 10:59 - 00049376 _____ C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-11-12 02:32 - 2013-05-09 10:58 - 00229648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-11-12 02:31 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-11-12 02:30 - 2015-11-12 02:30 - 00000000 ____D C:\WINDOWS\LastGood
2015-11-12 02:30 - 2015-11-12 02:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-11-12 02:23 - 2015-11-12 02:23 - 00009794 _____ C:\ComboFix.txt
2015-11-12 02:23 - 2015-11-12 02:23 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2015-11-12 02:23 - 2015-11-12 02:23 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp
2015-11-12 02:23 - 2015-11-12 02:23 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\temp
2015-11-12 00:56 - 2015-11-12 02:30 - 00000000 ____D C:\Program Files\AVAST Software
2015-11-12 00:00 - 2015-11-12 00:00 - 05903688 _____ (AVAST Software) C:\Documents and Settings\Dodo\Plocha\avastclear.exe
2015-11-11 10:03 - 2015-11-12 19:28 - 00000000 ____D C:\FRST
2015-11-11 10:00 - 2015-11-11 10:00 - 00015327 _____ C:\Documents and Settings\Dodo\Local Settings\Data aplikací\LM.bat
2015-11-11 09:59 - 2015-11-11 09:59 - 01702400 _____ (Farbar) C:\Documents and Settings\Dodo\Plocha\FRST.exe
2015-11-11 09:59 - 2015-11-11 09:59 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Dodo\Plocha\FRSTLauncher.exe
2015-11-11 09:50 - 2015-11-11 09:50 - 00000000 ____D C:\rsit
2015-11-11 08:06 - 2015-11-12 02:17 - 00005487 _____ C:\WINDOWS\setupapi.log
2015-11-11 08:04 - 2015-11-11 08:04 - 02329552 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-11 08:02 - 2015-11-11 08:02 - 00000156 _____ C:\Documents and Settings\Dodo\Dokumenty\cc_20151111_080210.reg
2015-11-10 09:45 - 2015-11-10 09:45 - 00000000 ____D C:\Documents and Settings\Dodo\Local Settings\Data aplikací\SlimWare Utilities Inc
2015-11-10 07:41 - 2015-11-10 07:41 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2015-11-10 07:39 - 2015-11-10 07:39 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2015-11-10 07:32 - 2015-11-10 07:36 - 00003664 _____ C:\Documents and Settings\Dodo\Plocha\Rkill.txt
2015-11-08 21:37 - 2011-06-26 07:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2015-11-08 21:37 - 2010-11-07 18:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2015-11-08 21:37 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00098816 _____ C:\WINDOWS\sed.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00080412 _____ C:\WINDOWS\grep.exe
2015-11-08 21:37 - 2000-08-31 01:00 - 00068096 _____ C:\WINDOWS\zip.exe
2015-11-08 21:36 - 2015-11-12 02:23 - 00000000 ____D C:\Qoobox
2015-10-27 21:40 - 2015-10-27 21:40 - 00017171 _____ C:\Documents and Settings\Dodo\Dokumenty\pi5XdLriB.jpeg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-12 19:29 - 2015-09-04 20:37 - 00000000 ____D C:\Documents and Settings\Dodo\Local Settings\temp
2015-11-12 19:22 - 2014-02-28 09:17 - 00000000 ____D C:\Documents and Settings\Dodo\Plocha
2015-11-12 07:53 - 2015-06-23 22:18 - 00000608 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-854245398-1677128483-842925246-1004.job
2015-11-12 02:33 - 2014-02-28 09:39 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-11-12 02:33 - 2014-02-28 09:39 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-11-12 02:32 - 2014-02-28 09:04 - 00002504 ____C C:\WINDOWS\system32\CONFIG.NT
2015-11-12 02:30 - 2014-02-28 09:38 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-11-12 02:25 - 2014-02-28 09:46 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avira
2015-11-12 02:24 - 2015-08-27 16:48 - 00037223 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-12 02:16 - 2008-04-14 12:00 - 00000227 _____ C:\WINDOWS\system.ini
2015-11-12 02:12 - 2014-06-24 18:01 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-12 02:12 - 2014-06-24 18:01 - 00000050 _____ C:\WINDOWS\wiaservc.log
2015-11-12 02:12 - 2014-02-28 09:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-12 02:11 - 2014-02-28 09:17 - 00000178 ___SH C:\Documents and Settings\Dodo\ntuser.ini
2015-11-12 02:10 - 2014-02-28 09:17 - 00000000 ___HD C:\Documents and Settings\Dodo\Local Settings\Data aplikací
2015-11-12 02:01 - 2014-02-28 09:17 - 00000000 __RHD C:\Documents and Settings\Dodo\Data aplikací
2015-11-12 01:59 - 2014-06-24 18:00 - 00032374 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-12 01:13 - 2014-02-28 09:37 - 00000327 ___SH C:\boot.ini
2015-11-12 00:35 - 2014-02-28 09:17 - 00000000 ____D C:\Documents and Settings\Dodo
2015-11-12 00:32 - 2015-07-18 20:18 - 05638248 ____R (Swearware) C:\Documents and Settings\Dodo\Plocha\ComboFix.exe
2015-11-11 08:48 - 2015-09-11 08:28 - 00002413 _____ C:\Documents and Settings\Dodo\Plocha\Assassin G13.lnk
2015-11-11 08:02 - 2014-02-28 09:17 - 00000000 ___RD C:\Documents and Settings\Dodo\Dokumenty
2015-11-11 08:01 - 2014-03-01 23:42 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2015-11-11 08:01 - 2014-02-28 09:00 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2015-11-11 08:01 - 2014-02-28 08:57 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-11-11 08:01 - 2014-02-28 08:57 - 00065536 _____ C:\WINDOWS\system32\config\EventForwarding-Operational.Evt
2015-11-10 09:41 - 2015-04-17 18:35 - 00000000 ____D C:\AdwCleaner
2015-11-10 03:00 - 2015-06-15 18:29 - 00000360 _____ C:\WINDOWS\Tasks\XoftSpySE.job
2015-11-10 02:58 - 2015-07-17 10:32 - 00000000 ____D C:\D přesunute
2015-11-10 02:18 - 2014-05-28 05:23 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Package Cache
2015-11-10 02:15 - 2015-09-11 08:19 - 00000000 ____D C:\Documents and Settings\Dodo\Plocha\screen shots
2015-11-09 20:36 - 2015-09-11 08:21 - 00000000 ____D C:\Documents and Settings\Dodo\Plocha\udrzba PC
2015-11-09 02:11 - 2014-02-28 09:40 - 01249222 ____C C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-09 02:05 - 2008-04-14 12:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-05 01:11 - 2014-04-09 02:23 - 00000000 ____D C:\WINDOWS\system32\LogFiles
2015-10-31 00:44 - 2014-02-28 11:47 - 00000000 ____D C:\Documents and Settings\Dodo\Data aplikací\Skype
2015-10-30 09:08 - 2014-05-28 03:28 - 00181248 __SHC C:\Documents and Settings\Dodo\Dokumenty\Thumbs.db
2015-10-29 19:06 - 2015-05-04 20:38 - 00002283 _____ C:\Documents and Settings\All Users\Plocha\Skype.lnk
2015-10-29 09:38 - 2015-08-24 22:17 - 00000000 ____D C:\Documents and Settings\Dodo\Dokumenty\acident
2015-10-28 19:32 - 2014-04-30 01:37 - 00000000 ____D C:\Documents and Settings\Dodo\Data aplikací\vlc
2015-10-28 19:30 - 2014-12-08 08:32 - 00000000 ____D C:\Documents and Settings\Dodo\Data aplikací\uTorrent
2015-10-22 19:24 - 2015-04-16 21:58 - 00000719 _____ C:\Documents and Settings\All Users\Plocha\VLC media player.lnk
2015-10-16 15:36 - 2015-04-13 01:06 - 00000000 ____D C:\Documents and Settings\Dodo\Local Settings\Data aplikací\UmmyVideoDownloader
==================== Files in the root of some directories =======
2014-12-27 04:09 - 2014-12-27 04:08 - 0644490 _____ () C:\Program Files\enzymy složení.jpg
2014-04-02 16:34 - 2015-09-02 23:44 - 0026112 _____ () C:\Documents and Settings\Dodo\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-11 10:00 - 2015-11-11 10:00 - 0015327 _____ () C:\Documents and Settings\Dodo\Local Settings\Data aplikací\LM.bat
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================