kontrola logu - podezřelé chováni PC
Napsal: 17 úno 2016 10:51
Zdravím, vypíná se mi antivir, mozila přestala fungovat.
Prosím o kontrolu logu. (Addition.zip v příloze, je .txt nemá tu na PC žádný komprimační nástroj.)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-02-2016
Ran by Sokol (administrator) on SOKOL-PC (17-02-2016 10:28:06)
Running from C:\Users\Sokol\Desktop
Loaded Profiles: Sokol (Available Profiles: Sokol)
Platform: Microsoft® Windows Vista™ Ultimate (X86) Language: Čeština (Česká republika)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Monet+, a.s.) C:\Windows\System32\xmesrv.exe
(Microsoft Corporation) C:\Windows\System32\wercon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe
(forum.viry.cz) C:\Users\Sokol\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2013-01-10] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-11] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-11] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-21]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 04 C:\Windows\system32\napinsp.dll [50176 2006-11-02] (Společnost Microsoft)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{EFC70F15-4621-4A70-A018-6BFF71EEDE7C}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-11] (AVAST Software)
FireFox:
========
FF ProfilePath: C:\Users\Sokol\AppData\Roaming\Mozilla\Firefox\Profiles\wu9lwtm8.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-11] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3256442033-3976859429-1304900942-1001: @servis24.cz/PKIComponent -> C:\Users\Sokol\AppData\Roaming\CSAS\lib\x86\npPKIComponentNPAPI.dll [2015-02-16] (Česká spořitelna, a.s.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-14] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-31]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-03]
CHR Extension: (Disk Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-17]
CHR Extension: (YouTube) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-17]
CHR Extension: (Dokumenty Google offline) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-17]
CHR Extension: (Komponenta pro aplikaci SERVIS 24) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gincjcoomijeeoddomaaimknmflggfnb [2015-05-05]
CHR Extension: (Avast Online Security) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-16]
CHR Extension: (Gmail) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-11]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-11] (AVAST Software)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [235696 2015-12-02] (McAfee, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2013-01-10] (Microsoft Corporation)
R2 xmengine service; C:\Windows\system32\xmesrv.exe [34696 2013-12-10] (Monet+, a.s.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-11] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [812208 2016-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449384 2016-01-21] (AVAST Software)
S3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-11] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-11] (AVAST Software)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
R3 GemCCID; C:\Windows\System32\Drivers\GemCCID.sys [89600 2009-08-10] (Gemalto)
S3 GEMPC430; C:\Windows\System32\Drivers\gemusb.sys [53568 2001-12-04] (Gemplus)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2013-01-10] (Společnost Microsoft)
R2 SF1CLPT; C:\Windows\system32\SF1CLPT.SYS [54488 2008-01-17] (Sharp Corporation) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-17 10:28 - 2016-02-17 10:28 - 00010187 _____ C:\Users\Sokol\Desktop\FRST.txt
2016-02-17 10:28 - 2016-02-17 10:28 - 00000000 ____D C:\FRST
2016-02-17 10:26 - 2016-02-17 10:26 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Desktop\FRSTLauncher.exe
2016-02-17 10:25 - 2016-02-17 10:25 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Downloads\Nepotvrzeno 507592.crdownload
2016-02-17 10:24 - 2016-02-17 10:24 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Downloads\Nepotvrzeno 383981.crdownload
2016-02-17 10:23 - 2016-02-17 10:24 - 01721344 _____ (Farbar) C:\Users\Sokol\Desktop\FRST.exe
2016-02-17 10:08 - 2016-02-17 10:09 - 06828320 _____ (Piriform Ltd) C:\Users\Sokol\Downloads\ccsetup514.exe
2016-02-17 10:05 - 2016-02-17 10:08 - 42845584 _____ C:\Users\Sokol\Downloads\Firefox_Setup_44.0.exe
2016-02-17 09:00 - 2016-02-17 09:00 - 00000000 ____D C:\70c8c0fb686e0d9914
2016-02-12 09:58 - 2016-02-16 09:14 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-02-03 10:31 - 2016-02-03 12:10 - 00023094 _____ C:\Users\Sokol\Desktop\formulář - žádost dotace.odt
2016-01-29 08:42 - 2015-12-11 12:18 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-17 10:24 - 2013-01-10 10:51 - 00000418 ____H C:\Windows\Tasks\User_Feed_Synchronization-{83C1E5A9-CDBF-4639-9C66-CDC8C548095C}.job
2016-02-17 10:14 - 2013-03-11 15:56 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-17 10:14 - 2006-11-02 14:00 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-17 10:14 - 2006-11-02 13:46 - 00003936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-17 10:14 - 2006-11-02 13:46 - 00003936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-17 10:13 - 2006-11-02 14:00 - 00032558 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-17 10:05 - 2013-03-11 15:56 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-17 09:58 - 2014-09-15 11:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-16 09:14 - 2013-01-10 10:36 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-02-12 08:33 - 2013-03-11 16:03 - 00001943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-12 08:33 - 2013-03-11 16:03 - 00001931 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-11 09:58 - 2014-09-15 11:06 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-02-11 09:58 - 2014-09-15 11:06 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-01-29 08:44 - 2015-12-11 12:20 - 00001789 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-01-21 08:48 - 2013-03-11 15:56 - 00812208 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-01-21 08:48 - 2013-01-09 16:47 - 00449384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
==================== Files in the root of some directories =======
Some files in TEMP:
====================
C:\Users\Sokol\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplgu3uz.dll
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-2.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-3.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-4.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-5.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-6.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Sokol\AppData\Local\Temp\ljM1005MFP-HB-pnp-winv32-czp.exe
C:\Users\Sokol\AppData\Local\Temp\{7FABA064-7C3C-4980-9CCB-5B0FC62AC835}-47.0.2526.111_chrome_installer.exe
C:\Users\Sokol\AppData\Local\Temp\{A5FF4F39-8B8C-4BC1-9E93-E955214DA5EC}-48.0.2564.97_chrome_installer.exe
C:\Users\Sokol\AppData\Local\Temp\{DD82E3C0-BBFD-44AF-9586-7E333C6E0705}-47.0.2526.111_47.0.2526.106_chrome_updater_3stage.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{83C1E5A9-CDBF-4639-9C66-CDC8C548095C}.job => C:\Windows\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Sokol\Desktop" je 165 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Prosím o kontrolu logu. (Addition.zip v příloze, je .txt nemá tu na PC žádný komprimační nástroj.)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-02-2016
Ran by Sokol (administrator) on SOKOL-PC (17-02-2016 10:28:06)
Running from C:\Users\Sokol\Desktop
Loaded Profiles: Sokol (Available Profiles: Sokol)
Platform: Microsoft® Windows Vista™ Ultimate (X86) Language: Čeština (Česká republika)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Monet+, a.s.) C:\Windows\System32\xmesrv.exe
(Microsoft Corporation) C:\Windows\System32\wercon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe
(forum.viry.cz) C:\Users\Sokol\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2013-01-10] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-11] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-11] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-21]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 04 C:\Windows\system32\napinsp.dll [50176 2006-11-02] (Společnost Microsoft)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{EFC70F15-4621-4A70-A018-6BFF71EEDE7C}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-11] (AVAST Software)
FireFox:
========
FF ProfilePath: C:\Users\Sokol\AppData\Roaming\Mozilla\Firefox\Profiles\wu9lwtm8.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-11] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3256442033-3976859429-1304900942-1001: @servis24.cz/PKIComponent -> C:\Users\Sokol\AppData\Roaming\CSAS\lib\x86\npPKIComponentNPAPI.dll [2015-02-16] (Česká spořitelna, a.s.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-14] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-31]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\48.0.2564.109\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-03]
CHR Extension: (Disk Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-17]
CHR Extension: (YouTube) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-17]
CHR Extension: (Dokumenty Google offline) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-17]
CHR Extension: (Komponenta pro aplikaci SERVIS 24) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gincjcoomijeeoddomaaimknmflggfnb [2015-05-05]
CHR Extension: (Avast Online Security) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-16]
CHR Extension: (Gmail) - C:\Users\Sokol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-11]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-11] (AVAST Software)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [235696 2015-12-02] (McAfee, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2013-01-10] (Microsoft Corporation)
R2 xmengine service; C:\Windows\system32\xmesrv.exe [34696 2013-12-10] (Monet+, a.s.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-11] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [812208 2016-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449384 2016-01-21] (AVAST Software)
S3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-11] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-11] (AVAST Software)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
R3 GemCCID; C:\Windows\System32\Drivers\GemCCID.sys [89600 2009-08-10] (Gemalto)
S3 GEMPC430; C:\Windows\System32\Drivers\gemusb.sys [53568 2001-12-04] (Gemplus)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2013-01-10] (Společnost Microsoft)
R2 SF1CLPT; C:\Windows\system32\SF1CLPT.SYS [54488 2008-01-17] (Sharp Corporation) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-17 10:28 - 2016-02-17 10:28 - 00010187 _____ C:\Users\Sokol\Desktop\FRST.txt
2016-02-17 10:28 - 2016-02-17 10:28 - 00000000 ____D C:\FRST
2016-02-17 10:26 - 2016-02-17 10:26 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Desktop\FRSTLauncher.exe
2016-02-17 10:25 - 2016-02-17 10:25 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Downloads\Nepotvrzeno 507592.crdownload
2016-02-17 10:24 - 2016-02-17 10:24 - 00112640 _____ (forum.viry.cz) C:\Users\Sokol\Downloads\Nepotvrzeno 383981.crdownload
2016-02-17 10:23 - 2016-02-17 10:24 - 01721344 _____ (Farbar) C:\Users\Sokol\Desktop\FRST.exe
2016-02-17 10:08 - 2016-02-17 10:09 - 06828320 _____ (Piriform Ltd) C:\Users\Sokol\Downloads\ccsetup514.exe
2016-02-17 10:05 - 2016-02-17 10:08 - 42845584 _____ C:\Users\Sokol\Downloads\Firefox_Setup_44.0.exe
2016-02-17 09:00 - 2016-02-17 09:00 - 00000000 ____D C:\70c8c0fb686e0d9914
2016-02-12 09:58 - 2016-02-16 09:14 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-02-03 10:31 - 2016-02-03 12:10 - 00023094 _____ C:\Users\Sokol\Desktop\formulář - žádost dotace.odt
2016-01-29 08:42 - 2015-12-11 12:18 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-17 10:24 - 2013-01-10 10:51 - 00000418 ____H C:\Windows\Tasks\User_Feed_Synchronization-{83C1E5A9-CDBF-4639-9C66-CDC8C548095C}.job
2016-02-17 10:14 - 2013-03-11 15:56 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-17 10:14 - 2006-11-02 14:00 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-17 10:14 - 2006-11-02 13:46 - 00003936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-17 10:14 - 2006-11-02 13:46 - 00003936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-17 10:13 - 2006-11-02 14:00 - 00032558 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-17 10:05 - 2013-03-11 15:56 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-17 09:58 - 2014-09-15 11:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-16 09:14 - 2013-01-10 10:36 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-02-12 08:33 - 2013-03-11 16:03 - 00001943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-12 08:33 - 2013-03-11 16:03 - 00001931 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-11 09:58 - 2014-09-15 11:06 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-02-11 09:58 - 2014-09-15 11:06 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-01-29 08:44 - 2015-12-11 12:20 - 00001789 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-01-21 08:48 - 2013-03-11 15:56 - 00812208 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-01-21 08:48 - 2013-01-09 16:47 - 00449384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
==================== Files in the root of some directories =======
Some files in TEMP:
====================
C:\Users\Sokol\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplgu3uz.dll
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-2.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-3.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-4.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-5.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer-6.exe
C:\Users\Sokol\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Sokol\AppData\Local\Temp\ljM1005MFP-HB-pnp-winv32-czp.exe
C:\Users\Sokol\AppData\Local\Temp\{7FABA064-7C3C-4980-9CCB-5B0FC62AC835}-47.0.2526.111_chrome_installer.exe
C:\Users\Sokol\AppData\Local\Temp\{A5FF4F39-8B8C-4BC1-9E93-E955214DA5EC}-48.0.2564.97_chrome_installer.exe
C:\Users\Sokol\AppData\Local\Temp\{DD82E3C0-BBFD-44AF-9586-7E333C6E0705}-47.0.2526.111_47.0.2526.106_chrome_updater_3stage.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{83C1E5A9-CDBF-4639-9C66-CDC8C548095C}.job => C:\Windows\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Sokol\Desktop" je 165 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================