V počítači byl trojan
Napsal: 20 led 2016 15:53
Prosím o pomoc - zkontrolování logu
V počítači jsem při kontrole programem emsisoft anti - malware, že v počítači byl trojan - viz. scan log
Emsisoft Anti-Malware - Version 10.0.0.5735
Last update: 19.1.2016 18:00:42
Initiated by: SN121905590318\Admin
Scan settings:
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
Scan start: 19.1.2016 18:35:03
Key: HKEY_USERS\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYFREECODEC Application.AdLoad (A)
C:\Documents and Settings\Admin\Dokumenty\bbc.exe Trojan.GenericKD.2478148 (B)
Scanned 73342
Found 2
Scan end: 19.1.2016 18:57:22
Scan time: 0:22:19
C:\Documents and Settings\Admin\Dokumenty\bbc.exe Deleted: Trojan.GenericKD.2478148 (B)
Key: HKEY_USERS\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYFREECODEC Deleted: Application.AdLoad (A)
Deleted: 2
Prosím proto o kontrolu počítače, zda tam ještě něco není. Scan FRST viz. níže
moc děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-01-2016
Ran by Admin (administrator) on SN121905590318 (20-01-2016 15:46:07)
Running from C:\Documents and Settings\Admin\Plocha
Loaded Profiles: Admin (Available Profiles: Admin & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
(Cyberlink) C:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
() C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
(OTi) C:\WINDOWS\system32\UStorSrv.exe
() C:\APPS\Powercinema\Kernel\TV\CLSched.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(CyberLink Corp.) C:\APPS\Powercinema\PCMService.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAui.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(TomTom) C:\Program Files\MyDrive Connect\TomTom MyDrive Connect.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Program Files\USB TV\EM28XX\BDARemote.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PCMService] => c:\APPS\Powercinema\PCMService.exe [147456 2006-02-23] (CyberLink Corp.)
HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files\Tall Emu\Online Armor\oaui.exe [7558464 2013-12-06] (Emsisoft GmbH)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-05-01] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [5836888 2015-10-09] (Emsisoft Ltd)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2006-12-17] (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [SmpcSys] => C:\APPS\SMP\SmpSys.exe [975360 2005-12-08] (Packard Bell BV)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [MyDriveConnect.exe] => C:\Program Files\MyDrive Connect\TomTom MyDrive Connect.exe [1958248 2015-11-20] (TomTom)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6495144 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
IFEO\Your Image File Name Here without a path: [Debugger]
ShellExecuteHooks: OA Shell Helper - {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Tall Emu\Online Armor\oaevent.dll [1033968 2013-12-06] (Emsisoft GmbH)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk [2012-09-09]
ShortcutTarget: BDARemote.lnk -> C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Secunia PSI Tray.lnk [2014-03-23]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
BootExecute: autocheck autochk * C:\WINDOWS\5615718.exe \??\C:\WINDOWS\5615718.dat
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{B48AEB00-381B-4A3F-9FBC-4FF76D95A67D}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.idnes.cz/
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> DefaultScope {38A2E73D-1CD5-4245-961A-822CD1D22FDA} URL = hxxp://www.google.cz/search?q={searchTerms}&rl ... NA_enCZ225
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = hxxp://www.crawler.com/search/dispatcher.aspx? ... tbid=60046
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> {38A2E73D-1CD5-4245-961A-822CD1D22FDA} URL = hxxp://www.google.cz/search?q={searchTerms}&rl ... NA_enCZ225
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKLM - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> No Name - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-02] [not signed]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
Chrome:
=======
CHR Profile: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-01]
CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path\update_url>
StartMenuInternet: chrome.exe - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
StartMenuInternet: Google Chrome.PHLN6MGVEQ5F6V4PJ2EJCUOP3E - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [7084784 2015-10-09] (Emsisoft Ltd)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2010-02-10] () [File not signed]
R2 CLCapSvc; c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe [266338 2006-02-23] () [File not signed]
R2 CLSched; c:\APPS\Powercinema\Kernel\TV\CLSched.exe [114784 2006-02-23] () [File not signed]
R2 CyberLink Media Library Service; c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe [1073152 2006-02-23] (Cyberlink) [File not signed]
R2 OAcat; C:\Program Files\Tall Emu\Online Armor\OAcat.exe [584864 2013-12-06] (Emsisoft GmbH)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [993848 2011-04-19] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [399416 2011-04-19] (Secunia)
R2 SvcOnlineArmor; C:\Program Files\Tall Emu\Online Armor\oasrv.exe [4457688 2013-12-06] (Emsisoft GmbH)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2005-01-31] (Ulead Systems, Inc.) [File not signed]
R2 USBDeviceService; C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe [90112 2005-10-20] () [File not signed]
R2 UStorage Server Service; C:\WINDOWS\system32\UStorSrv.exe [139264 2006-02-17] (OTi) [File not signed]
S3 nosGetPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper_3004.dll [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 epp32; C:\Program Files\Emsisoft Anti-Malware\epp32.sys [114200 2015-10-09] (Emsisoft GmbH)
R3 FET5X86V; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [43520 2008-09-22] (VIA Technologies, Inc. )
S3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [43520 2008-09-22] (VIA Technologies, Inc. )
R3 LgBttPort; C:\WINDOWS\System32\DRIVERS\lgbtport.sys [12160 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\WINDOWS\System32\DRIVERS\lgbtbus.sys [10496 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\WINDOWS\System32\DRIVERS\lgvmodem.sys [12928 2009-09-29] (LG Electronics Inc.)
R3 ltmodem5; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [606556 2004-08-17] (LT)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R1 OADevice; C:\WINDOWS\system32\drivers\OADriver.sys [210360 2013-12-06] ()
R1 oahlpXX; C:\WINDOWS\system32\drivers\oahlp32.sys [44984 2013-12-06] ()
R1 OAmon; C:\WINDOWS\system32\drivers\OAmon.sys [34856 2013-12-06] (Emsisoft)
R1 OAnet; C:\WINDOWS\system32\drivers\OAnet.sys [31912 2013-12-06] (Emsisoft)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2007-04-14] (VSO Software) [File not signed]
S3 PLCND532; C:\WINDOWS\System32\Drivers\PLCND532.sys [46848 2008-02-17] (Intellon, Inc.) [File not signed]
R3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed]
S3 usbbus; C:\WINDOWS\System32\DRIVERS\lgusbbus.sys [13056 2013-04-24] (LG Electronics Inc.)
S3 UsbDiag; C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys [20864 2013-04-24] (LG Electronics Inc.)
S3 USBModem; C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys [25216 2013-04-24] (LG Electronics Inc.)
R0 ViaIde; C:\WINDOWS\System32\DRIVERS\viaidexp.sys [6144 2006-05-29] (VIA Technologies, Inc.)
S0 viamraid; C:\WINDOWS\System32\DRIVERS\viamraid.sys [92672 2006-05-29] (VIA Technologies inc,.ltd) [File not signed]
U5 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44184 2012-05-02] ()
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-20 15:46 - 2016-01-20 15:46 - 00016388 _____ C:\Documents and Settings\Admin\Plocha\FRST.txt
2016-01-20 15:43 - 2016-01-20 15:46 - 00000000 ____D C:\FRST
2016-01-20 15:39 - 2016-01-20 15:39 - 01721856 _____ (Farbar) C:\Documents and Settings\Admin\Plocha\FRST.exe
2015-12-30 18:34 - 2015-12-30 18:34 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
2015-12-30 16:48 - 2015-12-30 16:48 - 00000216 _____ C:\Documents and Settings\Admin\Plocha\Age of Empires III Complete Collection.url
2015-12-30 16:34 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2015-12-30 16:34 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2015-12-30 16:34 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 15:10 - 2015-12-30 15:10 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\CEF
2015-12-30 15:10 - 2015-12-30 15:10 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikacĂ
2015-12-30 15:09 - 2015-12-30 15:09 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\Steam
2015-12-30 14:58 - 2016-01-20 15:18 - 00000000 ____D C:\Program Files\Steam
2015-12-30 14:58 - 2015-12-30 14:58 - 00000641 _____ C:\Documents and Settings\All Users\Plocha\Steam.lnk
2015-12-30 14:58 - 2015-12-30 14:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Steam
2015-12-29 19:55 - 2016-01-20 15:42 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-29 19:55 - 2015-12-29 19:55 - 00796864 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-12-29 19:55 - 2015-12-29 19:55 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-12-26 12:47 - 2015-12-26 12:48 - 01247112 _____ (Mojang) C:\Documents and Settings\Admin\Plocha\Minecraft (1).exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-20 15:46 - 2010-02-03 15:08 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-20 15:46 - 2009-08-15 13:38 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\temp
2016-01-20 15:46 - 2007-02-10 16:25 - 00000000 ___RD C:\Documents and Settings\Admin\Plocha
2016-01-20 15:43 - 2005-07-05 16:02 - 00000000 ____D C:\WINDOWS
2016-01-20 15:30 - 2007-02-10 16:26 - 00000228 _____ C:\WINDOWS\Tasks\Master CD_DVD Creator.job
2016-01-20 15:25 - 2012-02-18 16:36 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2016-01-20 15:10 - 2005-07-05 15:52 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2016-01-20 15:09 - 2005-07-05 16:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-19 22:44 - 2014-04-12 12:43 - 00032636 _____ C:\WINDOWS\SchedLgU.Txt
2016-01-19 22:44 - 2007-02-10 16:25 - 00000178 __SHC C:\Documents and Settings\Admin\ntuser.ini
2016-01-19 19:45 - 2010-06-28 14:46 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cb16c843781baa.job
2016-01-19 19:45 - 2007-02-10 16:25 - 00000000 ___HD C:\Documents and Settings\Admin\Local Settings\Data aplikací
2016-01-19 19:27 - 2007-06-02 12:17 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google
2016-01-19 18:58 - 2007-02-10 16:25 - 00000000 ___RD C:\Documents and Settings\Admin\Dokumenty
2016-01-15 14:55 - 2014-09-13 09:39 - 00001816 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2016-01-14 00:00 - 2007-02-25 13:27 - 141317472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-08 15:00 - 2014-03-07 13:38 - 00000216 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-01-07 14:23 - 2007-09-03 20:32 - 00000000 ____D C:\Documents and Settings\Admin\Data aplikací\Skype
2015-12-31 10:27 - 2015-10-06 21:54 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Package Cache
2015-12-30 18:34 - 2008-02-04 18:05 - 00000000 ____D C:\Documents and Settings\Admin\Dokumenty\My Games
2015-12-30 18:34 - 2005-07-05 16:08 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-12-30 18:31 - 2005-07-05 16:15 - 00000000 ____D C:\WINDOWS\system32\DirectX
2015-12-30 16:34 - 2005-07-05 16:02 - 00000000 ___HD C:\WINDOWS\inf
2015-12-30 14:58 - 2005-07-05 16:09 - 00000000 ___RD C:\Documents and Settings\All Users\Plocha
2015-12-30 14:58 - 2005-07-05 16:09 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-12-29 19:58 - 2010-02-28 11:19 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2015-12-26 12:49 - 2015-07-21 14:26 - 00000751 _____ C:\Documents and Settings\Admin\Plocha\nativelog.txt
2015-12-23 12:02 - 2015-09-30 20:39 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
==================== Files in the root of some directories =======
2014-09-13 08:47 - 2014-09-13 08:47 - 6010880 _____ () C:\Program Files\GUTD.tmp
2007-04-14 16:46 - 2007-04-14 16:46 - 0087608 ____C () C:\Documents and Settings\Admin\Data aplikací\ezpinst.exe
2012-03-15 09:50 - 2012-03-15 09:54 - 0087608 ____C () C:\Documents and Settings\Admin\Data aplikací\inst.exe
2007-04-14 16:46 - 2012-03-15 09:54 - 0007887 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.cat
2007-04-14 16:46 - 2012-03-15 09:54 - 0001144 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.inf
2007-03-25 07:29 - 2012-03-15 09:54 - 0000055 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.log
2007-04-14 16:46 - 2012-03-15 09:54 - 0047360 ____C (VSO Software) C:\Documents and Settings\Admin\Data aplikací\pcouffin.sys
2011-01-13 11:53 - 2015-05-17 12:16 - 0015360 ____C () C:\Documents and Settings\Admin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-02-10 16:25 - 2007-02-10 16:26 - 0000125 _____ () C:\Documents and Settings\Admin\Local Settings\Data aplikací\fusioncache.dat
Some files in TEMP:
====================
C:\Documents and Settings\Admin\Local Settings\temp\drm_dialogs.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7330005.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7360006.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7370012.dll
C:\Documents and Settings\Admin\Local Settings\temp\InstallPlugin_19_0_0_245.exe
C:\Documents and Settings\Admin\Local Settings\temp\InstallPlugin_20_0_0_267.exe
C:\Documents and Settings\Admin\Local Settings\temp\SkypeSetup.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
V počítači jsem při kontrole programem emsisoft anti - malware, že v počítači byl trojan - viz. scan log
Emsisoft Anti-Malware - Version 10.0.0.5735
Last update: 19.1.2016 18:00:42
Initiated by: SN121905590318\Admin
Scan settings:
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
Scan start: 19.1.2016 18:35:03
Key: HKEY_USERS\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYFREECODEC Application.AdLoad (A)
C:\Documents and Settings\Admin\Dokumenty\bbc.exe Trojan.GenericKD.2478148 (B)
Scanned 73342
Found 2
Scan end: 19.1.2016 18:57:22
Scan time: 0:22:19
C:\Documents and Settings\Admin\Dokumenty\bbc.exe Deleted: Trojan.GenericKD.2478148 (B)
Key: HKEY_USERS\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYFREECODEC Deleted: Application.AdLoad (A)
Deleted: 2
Prosím proto o kontrolu počítače, zda tam ještě něco není. Scan FRST viz. níže
moc děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-01-2016
Ran by Admin (administrator) on SN121905590318 (20-01-2016 15:46:07)
Running from C:\Documents and Settings\Admin\Plocha
Loaded Profiles: Admin (Available Profiles: Admin & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
(Cyberlink) C:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
() C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
(OTi) C:\WINDOWS\system32\UStorSrv.exe
() C:\APPS\Powercinema\Kernel\TV\CLSched.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(CyberLink Corp.) C:\APPS\Powercinema\PCMService.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAui.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Emsisoft GmbH) C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(TomTom) C:\Program Files\MyDrive Connect\TomTom MyDrive Connect.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Program Files\USB TV\EM28XX\BDARemote.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PCMService] => c:\APPS\Powercinema\PCMService.exe [147456 2006-02-23] (CyberLink Corp.)
HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files\Tall Emu\Online Armor\oaui.exe [7558464 2013-12-06] (Emsisoft GmbH)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-05-01] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [5836888 2015-10-09] (Emsisoft Ltd)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2006-12-17] (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [SmpcSys] => C:\APPS\SMP\SmpSys.exe [975360 2005-12-08] (Packard Bell BV)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [MyDriveConnect.exe] => C:\Program Files\MyDrive Connect\TomTom MyDrive Connect.exe [1958248 2015-11-20] (TomTom)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6495144 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
IFEO\Your Image File Name Here without a path: [Debugger]
ShellExecuteHooks: OA Shell Helper - {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Tall Emu\Online Armor\oaevent.dll [1033968 2013-12-06] (Emsisoft GmbH)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk [2012-09-09]
ShortcutTarget: BDARemote.lnk -> C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Secunia PSI Tray.lnk [2014-03-23]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
BootExecute: autocheck autochk * C:\WINDOWS\5615718.exe \??\C:\WINDOWS\5615718.dat
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{B48AEB00-381B-4A3F-9FBC-4FF76D95A67D}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.idnes.cz/
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-312608035-1206604926-2722864315-1006\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> DefaultScope {38A2E73D-1CD5-4245-961A-822CD1D22FDA} URL = hxxp://www.google.cz/search?q={searchTerms}&rl ... NA_enCZ225
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = hxxp://www.crawler.com/search/dispatcher.aspx? ... tbid=60046
SearchScopes: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> {38A2E73D-1CD5-4245-961A-822CD1D22FDA} URL = hxxp://www.google.cz/search?q={searchTerms}&rl ... NA_enCZ225
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKLM - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> No Name - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-312608035-1206604926-2722864315-1006 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-02] [not signed]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
Chrome:
=======
CHR Profile: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-01]
CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path\update_url>
StartMenuInternet: chrome.exe - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
StartMenuInternet: Google Chrome.PHLN6MGVEQ5F6V4PJ2EJCUOP3E - C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [7084784 2015-10-09] (Emsisoft Ltd)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2010-02-10] () [File not signed]
R2 CLCapSvc; c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe [266338 2006-02-23] () [File not signed]
R2 CLSched; c:\APPS\Powercinema\Kernel\TV\CLSched.exe [114784 2006-02-23] () [File not signed]
R2 CyberLink Media Library Service; c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe [1073152 2006-02-23] (Cyberlink) [File not signed]
R2 OAcat; C:\Program Files\Tall Emu\Online Armor\OAcat.exe [584864 2013-12-06] (Emsisoft GmbH)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [993848 2011-04-19] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [399416 2011-04-19] (Secunia)
R2 SvcOnlineArmor; C:\Program Files\Tall Emu\Online Armor\oasrv.exe [4457688 2013-12-06] (Emsisoft GmbH)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2005-01-31] (Ulead Systems, Inc.) [File not signed]
R2 USBDeviceService; C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe [90112 2005-10-20] () [File not signed]
R2 UStorage Server Service; C:\WINDOWS\system32\UStorSrv.exe [139264 2006-02-17] (OTi) [File not signed]
S3 nosGetPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper_3004.dll [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 epp32; C:\Program Files\Emsisoft Anti-Malware\epp32.sys [114200 2015-10-09] (Emsisoft GmbH)
R3 FET5X86V; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [43520 2008-09-22] (VIA Technologies, Inc. )
S3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [43520 2008-09-22] (VIA Technologies, Inc. )
R3 LgBttPort; C:\WINDOWS\System32\DRIVERS\lgbtport.sys [12160 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\WINDOWS\System32\DRIVERS\lgbtbus.sys [10496 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\WINDOWS\System32\DRIVERS\lgvmodem.sys [12928 2009-09-29] (LG Electronics Inc.)
R3 ltmodem5; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [606556 2004-08-17] (LT)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R1 OADevice; C:\WINDOWS\system32\drivers\OADriver.sys [210360 2013-12-06] ()
R1 oahlpXX; C:\WINDOWS\system32\drivers\oahlp32.sys [44984 2013-12-06] ()
R1 OAmon; C:\WINDOWS\system32\drivers\OAmon.sys [34856 2013-12-06] (Emsisoft)
R1 OAnet; C:\WINDOWS\system32\drivers\OAnet.sys [31912 2013-12-06] (Emsisoft)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2007-04-14] (VSO Software) [File not signed]
S3 PLCND532; C:\WINDOWS\System32\Drivers\PLCND532.sys [46848 2008-02-17] (Intellon, Inc.) [File not signed]
R3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed]
S3 usbbus; C:\WINDOWS\System32\DRIVERS\lgusbbus.sys [13056 2013-04-24] (LG Electronics Inc.)
S3 UsbDiag; C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys [20864 2013-04-24] (LG Electronics Inc.)
S3 USBModem; C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys [25216 2013-04-24] (LG Electronics Inc.)
R0 ViaIde; C:\WINDOWS\System32\DRIVERS\viaidexp.sys [6144 2006-05-29] (VIA Technologies, Inc.)
S0 viamraid; C:\WINDOWS\System32\DRIVERS\viamraid.sys [92672 2006-05-29] (VIA Technologies inc,.ltd) [File not signed]
U5 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44184 2012-05-02] ()
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-20 15:46 - 2016-01-20 15:46 - 00016388 _____ C:\Documents and Settings\Admin\Plocha\FRST.txt
2016-01-20 15:43 - 2016-01-20 15:46 - 00000000 ____D C:\FRST
2016-01-20 15:39 - 2016-01-20 15:39 - 01721856 _____ (Farbar) C:\Documents and Settings\Admin\Plocha\FRST.exe
2015-12-30 18:34 - 2015-12-30 18:34 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
2015-12-30 16:48 - 2015-12-30 16:48 - 00000216 _____ C:\Documents and Settings\Admin\Plocha\Age of Empires III Complete Collection.url
2015-12-30 16:34 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2015-12-30 16:34 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2015-12-30 16:34 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2015-12-30 16:34 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2015-12-30 16:34 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 16:34 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 16:34 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 16:34 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 16:34 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 15:10 - 2015-12-30 15:10 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\CEF
2015-12-30 15:10 - 2015-12-30 15:10 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikacĂ
2015-12-30 15:09 - 2015-12-30 15:09 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\Steam
2015-12-30 14:58 - 2016-01-20 15:18 - 00000000 ____D C:\Program Files\Steam
2015-12-30 14:58 - 2015-12-30 14:58 - 00000641 _____ C:\Documents and Settings\All Users\Plocha\Steam.lnk
2015-12-30 14:58 - 2015-12-30 14:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Steam
2015-12-29 19:55 - 2016-01-20 15:42 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-29 19:55 - 2015-12-29 19:55 - 00796864 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-12-29 19:55 - 2015-12-29 19:55 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-12-26 12:47 - 2015-12-26 12:48 - 01247112 _____ (Mojang) C:\Documents and Settings\Admin\Plocha\Minecraft (1).exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-20 15:46 - 2010-02-03 15:08 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-20 15:46 - 2009-08-15 13:38 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\temp
2016-01-20 15:46 - 2007-02-10 16:25 - 00000000 ___RD C:\Documents and Settings\Admin\Plocha
2016-01-20 15:43 - 2005-07-05 16:02 - 00000000 ____D C:\WINDOWS
2016-01-20 15:30 - 2007-02-10 16:26 - 00000228 _____ C:\WINDOWS\Tasks\Master CD_DVD Creator.job
2016-01-20 15:25 - 2012-02-18 16:36 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2016-01-20 15:10 - 2005-07-05 15:52 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2016-01-20 15:09 - 2005-07-05 16:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-19 22:44 - 2014-04-12 12:43 - 00032636 _____ C:\WINDOWS\SchedLgU.Txt
2016-01-19 22:44 - 2007-02-10 16:25 - 00000178 __SHC C:\Documents and Settings\Admin\ntuser.ini
2016-01-19 19:45 - 2010-06-28 14:46 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cb16c843781baa.job
2016-01-19 19:45 - 2007-02-10 16:25 - 00000000 ___HD C:\Documents and Settings\Admin\Local Settings\Data aplikací
2016-01-19 19:27 - 2007-06-02 12:17 - 00000000 ____D C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google
2016-01-19 18:58 - 2007-02-10 16:25 - 00000000 ___RD C:\Documents and Settings\Admin\Dokumenty
2016-01-15 14:55 - 2014-09-13 09:39 - 00001816 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2016-01-14 00:00 - 2007-02-25 13:27 - 141317472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-08 15:00 - 2014-03-07 13:38 - 00000216 _____ C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-01-07 14:23 - 2007-09-03 20:32 - 00000000 ____D C:\Documents and Settings\Admin\Data aplikací\Skype
2015-12-31 10:27 - 2015-10-06 21:54 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Package Cache
2015-12-30 18:34 - 2008-02-04 18:05 - 00000000 ____D C:\Documents and Settings\Admin\Dokumenty\My Games
2015-12-30 18:34 - 2005-07-05 16:08 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2015-12-30 18:31 - 2005-07-05 16:15 - 00000000 ____D C:\WINDOWS\system32\DirectX
2015-12-30 16:34 - 2005-07-05 16:02 - 00000000 ___HD C:\WINDOWS\inf
2015-12-30 14:58 - 2005-07-05 16:09 - 00000000 ___RD C:\Documents and Settings\All Users\Plocha
2015-12-30 14:58 - 2005-07-05 16:09 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-12-29 19:58 - 2010-02-28 11:19 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2015-12-26 12:49 - 2015-07-21 14:26 - 00000751 _____ C:\Documents and Settings\Admin\Plocha\nativelog.txt
2015-12-23 12:02 - 2015-09-30 20:39 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
==================== Files in the root of some directories =======
2014-09-13 08:47 - 2014-09-13 08:47 - 6010880 _____ () C:\Program Files\GUTD.tmp
2007-04-14 16:46 - 2007-04-14 16:46 - 0087608 ____C () C:\Documents and Settings\Admin\Data aplikací\ezpinst.exe
2012-03-15 09:50 - 2012-03-15 09:54 - 0087608 ____C () C:\Documents and Settings\Admin\Data aplikací\inst.exe
2007-04-14 16:46 - 2012-03-15 09:54 - 0007887 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.cat
2007-04-14 16:46 - 2012-03-15 09:54 - 0001144 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.inf
2007-03-25 07:29 - 2012-03-15 09:54 - 0000055 ____C () C:\Documents and Settings\Admin\Data aplikací\pcouffin.log
2007-04-14 16:46 - 2012-03-15 09:54 - 0047360 ____C (VSO Software) C:\Documents and Settings\Admin\Data aplikací\pcouffin.sys
2011-01-13 11:53 - 2015-05-17 12:16 - 0015360 ____C () C:\Documents and Settings\Admin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-02-10 16:25 - 2007-02-10 16:26 - 0000125 _____ () C:\Documents and Settings\Admin\Local Settings\Data aplikací\fusioncache.dat
Some files in TEMP:
====================
C:\Documents and Settings\Admin\Local Settings\temp\drm_dialogs.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7330005.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7360006.dll
C:\Documents and Settings\Admin\Local Settings\temp\drm_dyndata_7370012.dll
C:\Documents and Settings\Admin\Local Settings\temp\InstallPlugin_19_0_0_245.exe
C:\Documents and Settings\Admin\Local Settings\temp\InstallPlugin_20_0_0_267.exe
C:\Documents and Settings\Admin\Local Settings\temp\SkypeSetup.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================