Kontrola
Napsal: 13 bře 2016 06:21
Krásné ráno přeji,
chtěl bych poprosit o kontrolu-
Díky moc.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by zdenek (administrator) on ZDENEK (13-03-2016 06:12:11)
Running from C:\Documents and Settings\zdenek\Plocha\Čištění
Loaded Profiles: zdenek (Available Profiles: zdenek)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: "C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe" -surl="%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
() C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(SafeNet Inc.) C:\WINDOWS\system32\hasplms.exe
(Intel Corporation) C:\WINDOWS\system32\IPROSetMonitor.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [179624 2016-02-18] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [3862440 2016-02-24] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\avastSS.scr
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe -update pepperplugin
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\Av\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-484763869-1767777339-1606980848-1004] => localhost:8080
AutoConfigURL: [S-1-5-21-484763869-1767777339-1606980848-1004] => localhost:8080
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{D101B019-1149-45F7-B947-ECD828E8996C}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={1179D74D-295F-44D8-8724-F7D1C5FDB0E7}&mid=169df462d5bf47ccb21951a3ca7e2c7b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-03-06 17:11:54&v=4.2.6.552&pid=wtu&sg=&sap=hp
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={1179D74D-295F-44D8-8724-F7D1C5FDB0E7}&mid=169df462d5bf47ccb21951a3ca7e2c7b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-03-06 17:11:54&v=4.2.6.552&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2016-03-02] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.6.552\AVG Web TuneUp.dll [2016-03-06] (AVG)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2016-03-02] (IObit)
Toolbar: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2013-05-29] (Společnost Microsoft)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\zdenek\Data aplikací\Mozilla\Firefox\Profiles\zjjpa1zi.default
FF Homepage: hxxps://www.centrum.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-30] ()
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.6\\npsitesafety.dll [No File]
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin -> C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-04-19] ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2016-03-06]
FF Extension: AVG Web TuneUp - C:\Documents and Settings\zdenek\Data aplikací\Mozilla\Firefox\Profiles\zjjpa1zi.default\Extensions\avg@toolbar.xpi [2016-03-06]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-08-22] [not signed]
Chrome:
=======
CHR Profile: C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-18]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-22]
CHR Extension: (Disk Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-22]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-18]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-18]
CHR Extension: (Gmail) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-22]
CHR HKU\S-1-5-21-484763869-1767777339-1606980848-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR StartupUrls: "hxxp://www.centrum.cz/"
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgfws; C:\Program Files\AVG\Av\avgfws.exe [1580352 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [3934184 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [865704 2016-02-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [561104 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4683144 2014-03-11] (SafeNet Inc.)
R2 Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [109728 2011-02-28] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 vToolbarUpdater40.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe [1949768 2016-03-06] (AVG Secure Search)
R2 WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [1215560 2016-03-06] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [425352 2014-03-11] (SafeNet Inc.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2000-01-01] (Creative)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [149936 2015-11-06] (AVG Technologies CZ, s.r.o.)
R3 Avgfwdx; C:\WINDOWS\System32\DRIVERS\avgfwdx.sys [30944 2012-01-12] (AVG Technologies CZ, s.r.o.)
S3 Avgfwfd; C:\WINDOWS\System32\DRIVERS\avgfwdx.sys [30944 2012-01-12] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [244656 2016-01-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [207792 2016-01-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [229296 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [297904 2016-02-03] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [205744 2016-02-15] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [37296 2015-12-04] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [231856 2015-10-08] (AVG Technologies CZ, s.r.o.)
R0 Avgunivx; C:\WINDOWS\System32\DRIVERS\avgunivx.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
S3 DrvAgent32; C:\WINDOWS\system32\Drivers\DrvAgent32.sys [23456 2014-02-02] (Phoenix Technologies) [File not signed]
S3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [171152 2008-08-20] (Intel Corporation)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2016-03-04] ()
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [234888 2014-03-11] (SafeNet Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [35144 2015-07-20] ()
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2000-01-01] (Creative Technology Ltd.)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R3 RtlWlanu; C:\WINDOWS\System32\DRIVERS\rtwlanu.sys [1345936 2013-03-05] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\WINDOWS\System32\DRIVERS\SWDUMon.sys [13464 2016-02-29] ()
S3 VClone; C:\WINDOWS\System32\DRIVERS\VClone.sys [30720 2013-07-24] (Elaborate Bytes AG) [File not signed]
S3 catchme; \??\C:\DOCUME~1\zdenek\LOCALS~1\Temp\catchme.sys [X]
S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-09 07:15 - 2016-03-09 07:15 - 00139328 _____ C:\Documents and Settings\zdenek\Plocha\p. Tesař-signed.pdf
2016-03-09 07:13 - 2016-03-09 07:13 - 00129116 _____ C:\Documents and Settings\zdenek\Plocha\p.Tesar př-signed.pdf
2016-03-09 07:03 - 2016-03-09 07:03 - 00017655 _____ C:\Documents and Settings\zdenek\Plocha\p.Tesar př.pdf
2016-03-08 10:49 - 2016-03-08 10:49 - 00027871 _____ C:\Documents and Settings\zdenek\Plocha\p. Tesař.pdf
2016-03-06 17:12 - 2016-03-06 21:58 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2016-03-06 17:12 - 2016-03-06 17:13 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:13 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search
2016-03-06 16:55 - 2016-03-06 16:55 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\AVG
2016-03-06 16:24 - 2016-03-06 16:24 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\AVG
2016-03-06 16:19 - 2016-03-06 16:19 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\TuneUp Software
2016-03-06 16:19 - 2016-03-06 16:19 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG
2016-03-06 16:14 - 2016-03-06 16:14 - 00000000 ___HD C:\$AVG
2016-03-06 16:05 - 2016-03-13 05:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MFAData
2016-03-06 16:05 - 2016-03-06 16:05 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\MFAData
2016-03-06 16:04 - 2016-03-06 16:04 - 00000617 _____ C:\Documents and Settings\All Users\Plocha\AVG.lnk
2016-03-06 16:04 - 2016-03-06 16:04 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG Zen
2016-03-06 16:00 - 2016-03-06 16:47 - 00000000 ____D C:\Program Files\AVG
2016-03-06 15:07 - 2016-03-06 16:49 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avg
2016-03-06 14:54 - 2016-03-07 20:51 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\AvgSetupLog
2016-03-06 14:54 - 2016-03-06 19:25 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Avg
2016-03-05 07:50 - 2016-03-05 07:51 - 00004856 _____ C:\WINDOWS\system32\00SettingsFile1
2016-03-04 07:52 - 2016-03-06 14:33 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Enigma Software Group
2016-03-04 07:40 - 2016-03-04 07:40 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-03-04 07:30 - 2016-03-04 07:35 - 00000111 _____ C:\WINDOWS\Reimage.ini
2016-03-04 06:55 - 2016-03-04 06:55 - 00262144 _____ C:\WINDOWS\system32\config\elam
2016-03-04 06:49 - 2016-03-10 09:06 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ccb7d377-3c73-0
2016-03-04 06:47 - 2016-03-04 06:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\79db26d1
2016-03-04 06:47 - 2016-03-04 06:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\{32c9f21c-412c-0}
2016-03-04 06:47 - 2016-03-04 06:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\{0082d8e3-012c-1}
2016-03-03 14:42 - 2016-03-03 14:42 - 01129284 _____ C:\Documents and Settings\zdenek\Plocha\Ceník_Gewiss_2016.03_DISTR.zip
2016-03-03 08:06 - 2016-03-13 06:03 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Seznam.cz
2016-03-03 08:06 - 2016-03-08 20:37 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser
2016-03-03 08:06 - 2016-03-03 08:06 - 00001917 _____ C:\Documents and Settings\zdenek\Nabídka Start\Seznam.cz.lnk
2016-03-02 12:53 - 2016-03-07 19:28 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Nová složka (4)
2016-03-02 08:28 - 2016-03-06 15:34 - 00065536 _____ C:\WINDOWS\system32\config\Kaspersk.evt
2016-03-02 07:48 - 2016-03-02 07:48 - 00000881 _____ C:\Documents and Settings\zdenek\Nabídka Start\Uninstall Programs.lnk
2016-03-02 07:48 - 2016-03-02 07:48 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\IObit Uninstaller
2016-03-01 19:49 - 2016-03-01 19:49 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Temp
2016-02-28 06:11 - 2016-02-28 06:17 - 00000000 ____D C:\Program Files\rajce
2016-02-28 06:11 - 2016-02-28 06:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Rajče
2016-02-27 07:53 - 2016-02-27 07:53 - 00001498 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera 12.15 1748.lnk
2016-02-27 07:53 - 2016-02-27 07:53 - 00000000 ____D C:\Program Files\Opera
2016-02-26 21:04 - 2016-03-07 19:36 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Nová složka
2016-02-24 07:55 - 2016-02-24 07:55 - 00000000 ____D C:\Documents and Settings\zdenek\Dokumenty\Ulozto
2016-02-18 09:58 - 2016-02-20 08:52 - 00001819 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome.lnk
2016-02-15 18:02 - 2016-02-15 18:02 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\EasternGraphics
2016-02-15 16:37 - 2016-02-15 16:37 - 00205744 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2016-02-14 16:51 - 2016-02-29 09:44 - 00013464 _____ C:\WINDOWS\system32\Drivers\SWDUMon.sys
2016-02-14 16:51 - 2016-02-14 16:51 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\SlimWare Utilities Inc
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-13 06:12 - 2016-01-02 19:19 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Temp
2016-03-13 06:12 - 2016-01-02 13:56 - 00000000 ____D C:\FRST
2016-03-13 06:12 - 2013-08-09 06:39 - 00000000 ___RD C:\Documents and Settings\zdenek\Plocha\Čištění
2016-03-13 05:23 - 2013-08-07 06:06 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-13 05:23 - 2008-04-14 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2016-03-12 21:40 - 2013-08-07 06:08 - 00000178 ___SH C:\Documents and Settings\zdenek\ntuser.ini
2016-03-12 21:40 - 2013-08-07 06:08 - 00000000 ____D C:\Documents and Settings\zdenek
2016-03-12 21:40 - 2013-08-07 06:06 - 00032638 _____ C:\WINDOWS\SchedLgU.Txt
2016-03-12 21:39 - 2015-12-16 19:58 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\vlc
2016-03-12 06:17 - 2014-05-04 07:05 - 00104960 ___SH C:\Documents and Settings\zdenek\Plocha\Thumbs.db
2016-03-12 05:06 - 2013-08-07 06:08 - 00000000 ___HD C:\Documents and Settings\zdenek\Local Settings\Data aplikací
2016-03-10 18:32 - 2013-07-26 12:22 - 00143872 _____ C:\Documents and Settings\zdenek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-09 12:53 - 2014-03-10 14:39 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\uTorrent
2016-03-09 07:51 - 2013-08-20 15:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 07:34 - 2013-08-10 09:05 - 141270216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 07:15 - 2013-08-07 06:08 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha
2016-03-08 11:07 - 2013-08-09 06:35 - 00000000 ___RD C:\Documents and Settings\zdenek\Plocha\Kancelář
2016-03-08 11:05 - 2015-10-20 12:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AdmWin
2016-03-08 10:42 - 2015-10-20 12:14 - 00000000 ____D C:\AdmWin
2016-03-07 20:52 - 2013-08-07 07:51 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-03-07 08:20 - 2013-08-07 06:08 - 00000000 ___RD C:\Documents and Settings\zdenek\Nabídka Start
2016-03-06 19:43 - 2015-03-14 18:53 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\DriverGenius
2016-03-06 19:43 - 2013-08-10 10:59 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\HpUpdate
2016-03-06 19:43 - 2013-08-07 07:51 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-03-06 19:43 - 2013-07-27 13:35 - 00000000 ____D C:\Documents and Settings\zdenek\.thumbnails
2016-03-06 19:43 - 2013-07-26 06:39 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Skype
2016-03-06 18:19 - 2013-08-07 07:51 - 01184092 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-06 18:19 - 2008-04-14 13:00 - 00489712 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-06 18:19 - 2008-04-14 13:00 - 00098896 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-06 17:39 - 2013-08-09 06:39 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Grafika
2016-03-06 17:12 - 2014-09-25 17:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-03-06 17:10 - 2015-07-19 17:08 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes Anti-Malware
2016-03-06 16:55 - 2013-08-07 06:06 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2016-03-06 16:24 - 2013-08-07 06:08 - 00000000 __RHD C:\Documents and Settings\zdenek\Data aplikací
2016-03-06 16:17 - 2013-08-07 07:43 - 00000000 ___HD C:\WINDOWS\inf
2016-03-06 16:04 - 2015-10-02 08:59 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-03-06 15:34 - 2014-01-24 13:00 - 00167466 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2016-03-06 15:34 - 2013-08-07 07:50 - 00146016 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-06 14:54 - 2013-08-09 06:31 - 00024464 _____ C:\Documents and Settings\zdenek\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2016-03-06 14:38 - 2013-08-17 06:52 - 00000000 ____D C:\Program Files\PROFIT
2016-03-06 14:38 - 2013-08-07 07:51 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start
2016-03-06 14:19 - 2013-08-09 18:32 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-03-05 22:00 - 2014-01-24 13:00 - 00769170 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-484763869-1767777339-1606980848-1004-0.dat
2016-03-05 09:16 - 2013-08-07 07:43 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
2016-03-05 08:12 - 2013-08-10 08:40 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-03-04 17:54 - 2013-08-10 09:47 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2659262$
2016-03-04 06:55 - 2015-12-20 08:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ecd7e2b9-77f3-1
2016-03-04 06:50 - 2015-12-20 08:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ecd7e2b9-0ca1-0
2016-03-02 19:24 - 2015-10-14 07:05 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-02 19:24 - 2015-02-28 11:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2016-03-02 08:25 - 2016-01-02 12:38 - 00000000 ____D C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
2016-03-02 08:20 - 2013-08-07 07:50 - 00000000 ____D C:\Documents and Settings\All Users
2016-03-02 07:48 - 2013-09-25 14:20 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\IObit
2016-03-02 07:48 - 2013-08-07 06:08 - 00000000 ___HD C:\Documents and Settings\zdenek\Šablony
2016-02-29 14:00 - 2014-05-19 06:19 - 00000000 ____D C:\Documents and Settings\zdenek\EasternGraphics
2016-02-29 14:00 - 2014-05-19 06:15 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\EasternGraphics
2016-02-29 14:00 - 2014-05-19 06:14 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\EasternGraphics
2016-02-28 05:14 - 2014-08-24 08:13 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2016-02-28 05:13 - 2013-10-17 10:13 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2016-02-27 09:21 - 2015-12-20 08:37 - 00000079 _____ C:\WINDOWS\Wininit.ini
2016-02-27 09:21 - 2014-09-14 06:47 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2016-02-27 09:21 - 2013-11-14 04:10 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2016-02-27 09:14 - 2014-02-13 12:02 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\IObit
2016-02-27 07:38 - 2013-07-26 06:26 - 00000000 ____D C:\Documents and Settings\zdenek\Dokumenty\Stažené soubory
2016-02-26 07:26 - 2013-08-09 17:48 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Mozilla
2016-02-26 07:26 - 2013-08-09 17:48 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Mozilla
2016-02-24 19:30 - 2013-08-07 07:50 - 00000211 __RSH C:\boot.ini
2016-02-24 19:30 - 2008-04-14 13:00 - 00000649 _____ C:\WINDOWS\win.ini
2016-02-24 19:30 - 2008-04-14 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-02-24 09:38 - 2016-01-02 16:33 - 00000000 ____D C:\AdwCleaner
2016-02-24 07:55 - 2013-08-07 06:08 - 00000000 ___RD C:\Documents and Settings\zdenek\Dokumenty
2016-02-18 09:59 - 2013-07-28 13:41 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google
2016-02-18 08:36 - 2013-07-28 13:41 - 00000000 ____D C:\Program Files\Google
2016-02-15 18:02 - 2014-05-19 06:15 - 00000000 ____D C:\Program Files\EasternGraphics
==================== Files in the root of some directories =======
2013-11-03 08:06 - 2013-11-03 08:25 - 0000000 ____C () C:\Documents and Settings\zdenek\Data aplikací\bitlord_log.txt
2013-07-26 12:22 - 2016-03-10 18:32 - 0143872 _____ () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-07 20:37 - 2015-03-07 20:37 - 0000830 _____ () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\recently-used.xbel
2008-02-05 13:28 - 2008-02-05 13:28 - 0000051 ____C () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\setup.txt
2013-08-10 10:59 - 2013-08-10 10:59 - 0000057 ____C () C:\Documents and Settings\All Users\Data aplikací\Ament.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
chtěl bych poprosit o kontrolu-
Díky moc.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by zdenek (administrator) on ZDENEK (13-03-2016 06:12:11)
Running from C:\Documents and Settings\zdenek\Plocha\Čištění
Loaded Profiles: zdenek (Available Profiles: zdenek)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: "C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe" -surl="%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
() C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(SafeNet Inc.) C:\WINDOWS\system32\hasplms.exe
(Intel Corporation) C:\WINDOWS\system32\IPROSetMonitor.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
() C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser\Seznam.cz.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [179624 2016-02-18] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [3862440 2016-02-24] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\avastSS.scr
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe -update pepperplugin
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\Av\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-484763869-1767777339-1606980848-1004] => localhost:8080
AutoConfigURL: [S-1-5-21-484763869-1767777339-1606980848-1004] => localhost:8080
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{D101B019-1149-45F7-B947-ECD828E8996C}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-484763869-1767777339-1606980848-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={1179D74D-295F-44D8-8724-F7D1C5FDB0E7}&mid=169df462d5bf47ccb21951a3ca7e2c7b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-03-06 17:11:54&v=4.2.6.552&pid=wtu&sg=&sap=hp
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={1179D74D-295F-44D8-8724-F7D1C5FDB0E7}&mid=169df462d5bf47ccb21951a3ca7e2c7b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-03-06 17:11:54&v=4.2.6.552&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2016-03-02] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.6.552\AVG Web TuneUp.dll [2016-03-06] (AVG)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2016-03-02] (IObit)
Toolbar: HKU\S-1-5-21-484763869-1767777339-1606980848-1004 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2013-05-29] (Společnost Microsoft)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\zdenek\Data aplikací\Mozilla\Firefox\Profiles\zjjpa1zi.default
FF Homepage: hxxps://www.centrum.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-30] ()
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.6\\npsitesafety.dll [No File]
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin -> C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-04-19] ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2016-03-06]
FF Extension: AVG Web TuneUp - C:\Documents and Settings\zdenek\Data aplikací\Mozilla\Firefox\Profiles\zjjpa1zi.default\Extensions\avg@toolbar.xpi [2016-03-06]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-08-22] [not signed]
Chrome:
=======
CHR Profile: C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-18]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-22]
CHR Extension: (Disk Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-22]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-18]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-18]
CHR Extension: (Gmail) - C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-22]
CHR HKU\S-1-5-21-484763869-1767777339-1606980848-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR StartupUrls: "hxxp://www.centrum.cz/"
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgfws; C:\Program Files\AVG\Av\avgfws.exe [1580352 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [3934184 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [865704 2016-02-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [561104 2016-02-24] (AVG Technologies CZ, s.r.o.)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4683144 2014-03-11] (SafeNet Inc.)
R2 Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [109728 2011-02-28] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 vToolbarUpdater40.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe [1949768 2016-03-06] (AVG Secure Search)
R2 WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [1215560 2016-03-06] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [425352 2014-03-11] (SafeNet Inc.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2000-01-01] (Creative)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [149936 2015-11-06] (AVG Technologies CZ, s.r.o.)
R3 Avgfwdx; C:\WINDOWS\System32\DRIVERS\avgfwdx.sys [30944 2012-01-12] (AVG Technologies CZ, s.r.o.)
S3 Avgfwfd; C:\WINDOWS\System32\DRIVERS\avgfwdx.sys [30944 2012-01-12] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [244656 2016-01-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [207792 2016-01-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [229296 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [297904 2016-02-03] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [205744 2016-02-15] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [37296 2015-12-04] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [231856 2015-10-08] (AVG Technologies CZ, s.r.o.)
R0 Avgunivx; C:\WINDOWS\System32\DRIVERS\avgunivx.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
S3 DrvAgent32; C:\WINDOWS\system32\Drivers\DrvAgent32.sys [23456 2014-02-02] (Phoenix Technologies) [File not signed]
S3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [171152 2008-08-20] (Intel Corporation)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2016-03-04] ()
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [234888 2014-03-11] (SafeNet Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [35144 2015-07-20] ()
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2000-01-01] (Creative Technology Ltd.)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R3 RtlWlanu; C:\WINDOWS\System32\DRIVERS\rtwlanu.sys [1345936 2013-03-05] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\WINDOWS\System32\DRIVERS\SWDUMon.sys [13464 2016-02-29] ()
S3 VClone; C:\WINDOWS\System32\DRIVERS\VClone.sys [30720 2013-07-24] (Elaborate Bytes AG) [File not signed]
S3 catchme; \??\C:\DOCUME~1\zdenek\LOCALS~1\Temp\catchme.sys [X]
S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-09 07:15 - 2016-03-09 07:15 - 00139328 _____ C:\Documents and Settings\zdenek\Plocha\p. Tesař-signed.pdf
2016-03-09 07:13 - 2016-03-09 07:13 - 00129116 _____ C:\Documents and Settings\zdenek\Plocha\p.Tesar př-signed.pdf
2016-03-09 07:03 - 2016-03-09 07:03 - 00017655 _____ C:\Documents and Settings\zdenek\Plocha\p.Tesar př.pdf
2016-03-08 10:49 - 2016-03-08 10:49 - 00027871 _____ C:\Documents and Settings\zdenek\Plocha\p. Tesař.pdf
2016-03-06 17:12 - 2016-03-06 21:58 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2016-03-06 17:12 - 2016-03-06 17:13 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:13 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-03-06 17:11 - 2016-03-06 17:11 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search
2016-03-06 16:55 - 2016-03-06 16:55 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\AVG
2016-03-06 16:24 - 2016-03-06 16:24 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\AVG
2016-03-06 16:19 - 2016-03-06 16:19 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\TuneUp Software
2016-03-06 16:19 - 2016-03-06 16:19 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG
2016-03-06 16:14 - 2016-03-06 16:14 - 00000000 ___HD C:\$AVG
2016-03-06 16:05 - 2016-03-13 05:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MFAData
2016-03-06 16:05 - 2016-03-06 16:05 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\MFAData
2016-03-06 16:04 - 2016-03-06 16:04 - 00000617 _____ C:\Documents and Settings\All Users\Plocha\AVG.lnk
2016-03-06 16:04 - 2016-03-06 16:04 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG Zen
2016-03-06 16:00 - 2016-03-06 16:47 - 00000000 ____D C:\Program Files\AVG
2016-03-06 15:07 - 2016-03-06 16:49 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avg
2016-03-06 14:54 - 2016-03-07 20:51 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\AvgSetupLog
2016-03-06 14:54 - 2016-03-06 19:25 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Avg
2016-03-05 07:50 - 2016-03-05 07:51 - 00004856 _____ C:\WINDOWS\system32\00SettingsFile1
2016-03-04 07:52 - 2016-03-06 14:33 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Enigma Software Group
2016-03-04 07:40 - 2016-03-04 07:40 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-03-04 07:30 - 2016-03-04 07:35 - 00000111 _____ C:\WINDOWS\Reimage.ini
2016-03-04 06:55 - 2016-03-04 06:55 - 00262144 _____ C:\WINDOWS\system32\config\elam
2016-03-04 06:49 - 2016-03-10 09:06 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ccb7d377-3c73-0
2016-03-04 06:47 - 2016-03-04 06:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\79db26d1
2016-03-04 06:47 - 2016-03-04 06:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\{32c9f21c-412c-0}
2016-03-04 06:47 - 2016-03-04 06:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\{0082d8e3-012c-1}
2016-03-03 14:42 - 2016-03-03 14:42 - 01129284 _____ C:\Documents and Settings\zdenek\Plocha\Ceník_Gewiss_2016.03_DISTR.zip
2016-03-03 08:06 - 2016-03-13 06:03 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Seznam.cz
2016-03-03 08:06 - 2016-03-08 20:37 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Seznam Browser
2016-03-03 08:06 - 2016-03-03 08:06 - 00001917 _____ C:\Documents and Settings\zdenek\Nabídka Start\Seznam.cz.lnk
2016-03-02 12:53 - 2016-03-07 19:28 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Nová složka (4)
2016-03-02 08:28 - 2016-03-06 15:34 - 00065536 _____ C:\WINDOWS\system32\config\Kaspersk.evt
2016-03-02 07:48 - 2016-03-02 07:48 - 00000881 _____ C:\Documents and Settings\zdenek\Nabídka Start\Uninstall Programs.lnk
2016-03-02 07:48 - 2016-03-02 07:48 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\IObit Uninstaller
2016-03-01 19:49 - 2016-03-01 19:49 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Temp
2016-02-28 06:11 - 2016-02-28 06:17 - 00000000 ____D C:\Program Files\rajce
2016-02-28 06:11 - 2016-02-28 06:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Rajče
2016-02-27 07:53 - 2016-02-27 07:53 - 00001498 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera 12.15 1748.lnk
2016-02-27 07:53 - 2016-02-27 07:53 - 00000000 ____D C:\Program Files\Opera
2016-02-26 21:04 - 2016-03-07 19:36 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Nová složka
2016-02-24 07:55 - 2016-02-24 07:55 - 00000000 ____D C:\Documents and Settings\zdenek\Dokumenty\Ulozto
2016-02-18 09:58 - 2016-02-20 08:52 - 00001819 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome.lnk
2016-02-15 18:02 - 2016-02-15 18:02 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\EasternGraphics
2016-02-15 16:37 - 2016-02-15 16:37 - 00205744 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2016-02-14 16:51 - 2016-02-29 09:44 - 00013464 _____ C:\WINDOWS\system32\Drivers\SWDUMon.sys
2016-02-14 16:51 - 2016-02-14 16:51 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\SlimWare Utilities Inc
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-13 06:12 - 2016-01-02 19:19 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Temp
2016-03-13 06:12 - 2016-01-02 13:56 - 00000000 ____D C:\FRST
2016-03-13 06:12 - 2013-08-09 06:39 - 00000000 ___RD C:\Documents and Settings\zdenek\Plocha\Čištění
2016-03-13 05:23 - 2013-08-07 06:06 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-13 05:23 - 2008-04-14 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2016-03-12 21:40 - 2013-08-07 06:08 - 00000178 ___SH C:\Documents and Settings\zdenek\ntuser.ini
2016-03-12 21:40 - 2013-08-07 06:08 - 00000000 ____D C:\Documents and Settings\zdenek
2016-03-12 21:40 - 2013-08-07 06:06 - 00032638 _____ C:\WINDOWS\SchedLgU.Txt
2016-03-12 21:39 - 2015-12-16 19:58 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\vlc
2016-03-12 06:17 - 2014-05-04 07:05 - 00104960 ___SH C:\Documents and Settings\zdenek\Plocha\Thumbs.db
2016-03-12 05:06 - 2013-08-07 06:08 - 00000000 ___HD C:\Documents and Settings\zdenek\Local Settings\Data aplikací
2016-03-10 18:32 - 2013-07-26 12:22 - 00143872 _____ C:\Documents and Settings\zdenek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-09 12:53 - 2014-03-10 14:39 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\uTorrent
2016-03-09 07:51 - 2013-08-20 15:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 07:34 - 2013-08-10 09:05 - 141270216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 07:15 - 2013-08-07 06:08 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha
2016-03-08 11:07 - 2013-08-09 06:35 - 00000000 ___RD C:\Documents and Settings\zdenek\Plocha\Kancelář
2016-03-08 11:05 - 2015-10-20 12:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AdmWin
2016-03-08 10:42 - 2015-10-20 12:14 - 00000000 ____D C:\AdmWin
2016-03-07 20:52 - 2013-08-07 07:51 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-03-07 08:20 - 2013-08-07 06:08 - 00000000 ___RD C:\Documents and Settings\zdenek\Nabídka Start
2016-03-06 19:43 - 2015-03-14 18:53 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\DriverGenius
2016-03-06 19:43 - 2013-08-10 10:59 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\HpUpdate
2016-03-06 19:43 - 2013-08-07 07:51 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-03-06 19:43 - 2013-07-27 13:35 - 00000000 ____D C:\Documents and Settings\zdenek\.thumbnails
2016-03-06 19:43 - 2013-07-26 06:39 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Skype
2016-03-06 18:19 - 2013-08-07 07:51 - 01184092 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-06 18:19 - 2008-04-14 13:00 - 00489712 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-06 18:19 - 2008-04-14 13:00 - 00098896 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-06 17:39 - 2013-08-09 06:39 - 00000000 ____D C:\Documents and Settings\zdenek\Plocha\Grafika
2016-03-06 17:12 - 2014-09-25 17:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-03-06 17:10 - 2015-07-19 17:08 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes Anti-Malware
2016-03-06 16:55 - 2013-08-07 06:06 - 00000000 ___HD C:\Documents and Settings\LocalService\Local Settings\Data aplikací
2016-03-06 16:24 - 2013-08-07 06:08 - 00000000 __RHD C:\Documents and Settings\zdenek\Data aplikací
2016-03-06 16:17 - 2013-08-07 07:43 - 00000000 ___HD C:\WINDOWS\inf
2016-03-06 16:04 - 2015-10-02 08:59 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-03-06 15:34 - 2014-01-24 13:00 - 00167466 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2016-03-06 15:34 - 2013-08-07 07:50 - 00146016 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-06 14:54 - 2013-08-09 06:31 - 00024464 _____ C:\Documents and Settings\zdenek\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2016-03-06 14:38 - 2013-08-17 06:52 - 00000000 ____D C:\Program Files\PROFIT
2016-03-06 14:38 - 2013-08-07 07:51 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start
2016-03-06 14:19 - 2013-08-09 18:32 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-03-05 22:00 - 2014-01-24 13:00 - 00769170 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-484763869-1767777339-1606980848-1004-0.dat
2016-03-05 09:16 - 2013-08-07 07:43 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
2016-03-05 08:12 - 2013-08-10 08:40 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-03-04 17:54 - 2013-08-10 09:47 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2659262$
2016-03-04 06:55 - 2015-12-20 08:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ecd7e2b9-77f3-1
2016-03-04 06:50 - 2015-12-20 08:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ecd7e2b9-0ca1-0
2016-03-02 19:24 - 2015-10-14 07:05 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-02 19:24 - 2015-02-28 11:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2016-03-02 08:25 - 2016-01-02 12:38 - 00000000 ____D C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
2016-03-02 08:20 - 2013-08-07 07:50 - 00000000 ____D C:\Documents and Settings\All Users
2016-03-02 07:48 - 2013-09-25 14:20 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\IObit
2016-03-02 07:48 - 2013-08-07 06:08 - 00000000 ___HD C:\Documents and Settings\zdenek\Šablony
2016-02-29 14:00 - 2014-05-19 06:19 - 00000000 ____D C:\Documents and Settings\zdenek\EasternGraphics
2016-02-29 14:00 - 2014-05-19 06:15 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\EasternGraphics
2016-02-29 14:00 - 2014-05-19 06:14 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\EasternGraphics
2016-02-28 05:14 - 2014-08-24 08:13 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2016-02-28 05:13 - 2013-10-17 10:13 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2016-02-27 09:21 - 2015-12-20 08:37 - 00000079 _____ C:\WINDOWS\Wininit.ini
2016-02-27 09:21 - 2014-09-14 06:47 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2016-02-27 09:21 - 2013-11-14 04:10 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2016-02-27 09:14 - 2014-02-13 12:02 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\IObit
2016-02-27 07:38 - 2013-07-26 06:26 - 00000000 ____D C:\Documents and Settings\zdenek\Dokumenty\Stažené soubory
2016-02-26 07:26 - 2013-08-09 17:48 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Mozilla
2016-02-26 07:26 - 2013-08-09 17:48 - 00000000 ____D C:\Documents and Settings\zdenek\Data aplikací\Mozilla
2016-02-24 19:30 - 2013-08-07 07:50 - 00000211 __RSH C:\boot.ini
2016-02-24 19:30 - 2008-04-14 13:00 - 00000649 _____ C:\WINDOWS\win.ini
2016-02-24 19:30 - 2008-04-14 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-02-24 09:38 - 2016-01-02 16:33 - 00000000 ____D C:\AdwCleaner
2016-02-24 07:55 - 2013-08-07 06:08 - 00000000 ___RD C:\Documents and Settings\zdenek\Dokumenty
2016-02-18 09:59 - 2013-07-28 13:41 - 00000000 ____D C:\Documents and Settings\zdenek\Local Settings\Data aplikací\Google
2016-02-18 08:36 - 2013-07-28 13:41 - 00000000 ____D C:\Program Files\Google
2016-02-15 18:02 - 2014-05-19 06:15 - 00000000 ____D C:\Program Files\EasternGraphics
==================== Files in the root of some directories =======
2013-11-03 08:06 - 2013-11-03 08:25 - 0000000 ____C () C:\Documents and Settings\zdenek\Data aplikací\bitlord_log.txt
2013-07-26 12:22 - 2016-03-10 18:32 - 0143872 _____ () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-07 20:37 - 2015-03-07 20:37 - 0000830 _____ () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\recently-used.xbel
2008-02-05 13:28 - 2008-02-05 13:28 - 0000051 ____C () C:\Documents and Settings\zdenek\Local Settings\Data aplikací\setup.txt
2013-08-10 10:59 - 2013-08-10 10:59 - 0000057 ____C () C:\Documents and Settings\All Users\Data aplikací\Ament.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================