Zdravím,prikladám log FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-12-2016
Ran by cukrik (administrator) on L (18-12-2016 17:40:16)
Running from C:\Documents and Settings\cukrik\Desktop
Loaded Profiles: cukrik (Available Profiles: cukrik)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare\ASCService.exe
(Broadcom Corporation.) C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Freemake) C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Micro-Star International Co., Ltd.) C:\Program Files\System Control Manager\MSIService.exe
(O2Micro International) C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Logitech Inc. ) C:\PROGRA~1\MOUSEW~1\system\EM_EXEC.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Musicmatch, Inc.) C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
(Musicmatch, Inc.) C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-16] (AVAST Software)
HKLM\...\Run: [EM_EXEC] => C:\Program Files\MouseWare\system\EM_EXEC.EXE [28672 2002-05-01] (Logitech Inc. )
HKLM\...\Run: [MimBoot] => C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe [11776 2006-01-19] (Musicmatch, Inc.)
HKLM\...\Run: [MGSysCtrl] => C:\Program Files\System Control Manager\MGSysCtrl.exe [2224128 2009-11-06] (Micro-Star International Co., Ltd.)
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [94208 2005-10-28] (Nero AG)
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\Run: [Advanced SystemCare 10] => C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe [3078432 2016-10-18] (IObit)
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\MountPoints2: {426871ca-fff9-11e1-a9b0-0015af6275d4} - F:\RunSetup.exe
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\MountPoints2: {426871cc-fff9-11e1-a9b0-0015af6275d4} - F:\RunSetup.exe
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\MountPoints2: {5ff1331a-54b0-11e2-aa32-0015af6275d4} - F:\seamlessKeyLauncher.exe
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\...\MountPoints2: {d6e6dea6-ea20-11e2-aa4d-0015af6275d4} - F:\autorun.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-12-16] (AVAST Software)
Startup: C:\Documents and Settings\cukrik\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [2012-06-13]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.2
Tcpip\..\Interfaces\{110DC65D-4E25-450E-84F0-48D6E642085A}: [DhcpNameServer] 192.168.39.223
Tcpip\..\Interfaces\{4D242437-6B15-44B3-A060-80D722865E11}: [DhcpNameServer] 10.0.0.2
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.google.com/?trackid=sp-006
HKU\S-1-5-21-725345543-1715567821-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://
www.google.com/search?trackid=sp-006&q={searchTerms}
URLSearchHook: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 - (No Name) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No File
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://
www.oursurfing.com/web/?utm_source=b&ut ... earchTerms}
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {AA7F4FA6-B7DF-4F3D-A40F-0D947CA4AC18} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {BB098C9D-72F4-41F7-A014-FD3DCE601838} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {C16F70DA-F6F1-4CF1-97BD-965C65910D41} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {DB812CA0-1667-46C7-A27A-A262365F0B00} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {E485CD06-3729-4799-92AB-D8BFAAE20D72} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL =
SearchScopes: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23] (Adobe Systems Incorporated)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO: No Name -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-12-16] (AVAST Software)
BHO: IObit Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2016-08-03] (IObit)
BHO: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
Toolbar: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
Toolbar: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> No Name - {5347542D-5341-5400-76A7-7A786E7484D7} - No File
Toolbar: HKU\S-1-5-21-725345543-1715567821-1417001333-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\cukrik\Application Data\Mozilla\Firefox\Profiles\bcj6f1rf.default-1450971022973 [2016-12-18]
FF Homepage: C:\Documents and Settings\cukrik\Application Data\Mozilla\Firefox\Profiles\bcj6f1rf.default-1450971022973 -> google.sk
FF HKLM\...\Firefox\Extensions: [
fmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
fmdownloader@gmail.com => not found
FF HKLM\...\Firefox\Extensions: [
ytfmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
ytfmdownloader@gmail.com
FF Extension: (Freemake Youtube Download Button) - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
ytfmdownloader@gmail.com [2013-06-27] [not signed]
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-16]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM\...\Firefox\Extensions: [
defsearchp@gmail.com] - C:\Documents and Settings\cukrik\Application Data\Mozilla\Firefox\Profiles\pou6g0hc.default\extensions\
defsearchp@gmail.com => not found
FF HKLM\...\Firefox\Extensions: [
deskCutv2@gmail.com] - C:\Documents and Settings\cukrik\Application Data\Mozilla\Firefox\Profiles\pou6g0hc.default\extensions\
deskCutv2@gmail.com => not found
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2016-03-18] [not signed]
FF HKLM\...\Firefox\Extensions: [
sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-16]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext => not found
FF HKLM\...\Thunderbird\Extensions: [
eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-28] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [No File]
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
Chrome:
=======
CHR HomePage: Default -> hxxp://google.sk/
CHR StartupUrls: Default -> "hxxp://google.sk/"
CHR Profile: C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default [2016-12-16]
CHR Extension: (Freemake Video Downloader) - C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2016-03-16]
CHR Extension: (Freemake Youtube Download Button) - C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2016-03-16]
CHR Extension: (Avast SafePrice) - C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-12-16]
CHR Extension: (RealDownloader) - C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2016-03-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\cukrik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-16]
CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-06-27]
CHR HKLM\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2013-06-27]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
R2 AdvancedSystemCareService10; C:\Program Files\IObit\Advanced SystemCare\ASCService.exe [462624 2016-10-14] (IObit)
S3 Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [807800 2013-12-09] (Spigot, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-16] (AVAST Software)
R2 btwdins; C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe [342624 2008-04-14] (Broadcom Corporation.)
R2 Freemake Improver; C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-06-25] (Freemake)
S2 IObitUnSvr; C:\Program Files\IObit\IObit Uninstaller\IUService.exe [359200 2016-09-28] (IObit)
R2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.)
R2 o2flash; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [65536 2007-02-12] (O2Micro International)
R2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2011-12-12] (PC Tools)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5613328 2015-07-29] (TeamViewer GmbH)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [2142336 2013-07-18] (Atheros Communications, Inc.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [34008 2016-12-16] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2016-12-16] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [92256 2016-12-16] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-12-16] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [60424 2016-12-16] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [735488 2016-12-16] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [433768 2016-12-16] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [184592 2016-12-16] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [66688 2016-12-16] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [224752 2016-12-16] (AVAST Software)
S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [534440 2008-04-15] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37160 2008-02-04] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [990632 2008-04-15] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156392 2007-09-20] (Broadcom Corporation.)
S3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [57384 2008-03-10] (Broadcom Corporation.)
S3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37032 2008-02-04] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [47272 2008-03-27] (Broadcom Corporation.)
R3 l8042pr2; C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys [52224 2002-04-15] (Logitech)
R3 LKbdFlt2; C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys [5840 2002-04-15] (Logitech)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 nm; C:\WINDOWS\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
S3 SER2AT; C:\WINDOWS\System32\DRIVERS\SER2AT.sys [51200 2010-09-29] (ATEN)
S3 TF1D091010; C:\WINDOWS\System32\DRIVERS\TF1D091010.sys [99968 2008-02-02] (TechFaith Wireless Technology Limited.)
S3 cpuz138; \??\C:\DOCUME~1\cukrik\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S4 InCDFs; system32\drivers\InCDFs.sys [X]
S1 InCDPass; system32\drivers\InCDPass.sys [X]
S1 InCDRm; system32\drivers\InCDRm.sys [X]
S4 IntelIde; no ImagePath
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [359640 2014-01-03] (Realsil Semiconductor Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-18 17:40 - 2016-12-18 17:40 - 00021031 _____ C:\Documents and Settings\cukrik\Desktop\FRST.txt
2016-12-18 17:39 - 2016-12-18 17:40 - 00000000 ____D C:\FRST
2016-12-18 16:32 - 2016-12-18 16:32 - 01762304 _____ (Farbar) C:\Documents and Settings\cukrik\Desktop\FRST.exe
2016-12-16 12:18 - 2016-12-16 12:18 - 00000000 ____D C:\Documents and Settings\cukrik\Local Settings\Application Data\CEF
2016-12-16 11:06 - 2016-12-16 11:06 - 00921280 _____ (Microsoft Corporation) C:\WINDOWS\ucrtbase.dll
2016-12-16 11:06 - 2016-12-16 11:06 - 00319760 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-12-16 11:06 - 2016-12-16 11:06 - 00053208 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-12-16 10:44 - 2016-12-16 10:44 - 00001689 _____ C:\Documents and Settings\All Users\Desktop\Avast Free Antivirus.lnk
2016-12-16 10:15 - 2016-12-18 14:45 - 00000000 ____D C:\Program Files\Guard-ICQ
2016-12-16 10:15 - 2016-12-16 10:15 - 00000000 ____D C:\Program Files\Application Updater
2016-12-16 10:15 - 2016-12-16 10:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IHProtectUpDate
2016-12-16 10:15 - 2016-12-16 10:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Ask
2016-12-16 10:15 - 2016-12-16 10:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\APN
2016-12-16 10:14 - 2016-12-16 10:14 - 00000000 ____D C:\Program Files\YTD Toolbar
2016-12-16 10:14 - 2016-12-16 10:14 - 00000000 ____D C:\Program Files\Common Files\Spigot
2016-12-14 11:06 - 2016-12-16 10:13 - 00000000 ____D C:\Documents and Settings\cukrik\Desktop\Staré údaje Firefoxu
2016-12-12 09:49 - 2016-12-16 10:15 - 00000000 ____D C:\AdwCleaner
2016-12-09 09:28 - 2016-12-09 09:28 - 00000165 ____H C:\Documents and Settings\cukrik\Desktop\~$rôzne kontakty n.xlsx
2016-12-01 14:14 - 2016-12-01 14:14 - 00001825 _____ C:\Documents and Settings\Default User\Desktop\Google Chrome.lnk
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Program Files\Opera
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Application Data\Temp
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\cukrik\Application Data\ProductData
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\cukrik\AppData\LocalLow\IObit
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\IObit Uninstaller
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
2016-12-01 09:21 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{74E9F814-C737-42CC-B721-DBBC4059367A}
2016-11-30 07:23 - 2016-11-30 07:23 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Application Data\Google
2016-11-29 11:11 - 2016-12-12 10:47 - 00000000 ____D C:\WINDOWS\Tasks\IObitDisabled
2016-11-29 10:59 - 2016-12-01 11:24 - 37486592 _____ C:\WINDOWS\system32\config\software.iobit
2016-11-29 10:59 - 2016-12-01 11:24 - 00278528 _____ C:\WINDOWS\system32\config\default.iobit
2016-11-29 10:59 - 2016-12-01 11:24 - 00028672 _____ C:\WINDOWS\system32\config\SAM.iobit
2016-11-29 10:59 - 2016-12-01 11:23 - 00057344 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2016-11-29 10:34 - 2016-12-15 06:17 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ProductData
2016-11-29 10:34 - 2016-11-29 10:34 - 00001795 _____ C:\Documents and Settings\All Users\Start Menu\Programs\IObit Uninstaller.lnk
2016-11-29 10:34 - 2016-11-29 10:34 - 00001789 _____ C:\Documents and Settings\All Users\Desktop\IObit Uninstaller.lnk
2016-11-29 10:32 - 2016-12-01 09:21 - 00000000 ____D C:\Program Files\Common Files\IObit
2016-11-29 10:29 - 2016-12-03 19:30 - 00001806 _____ C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 10.lnk
2016-11-29 10:27 - 2016-12-01 09:21 - 00000000 ____D C:\Documents and Settings\cukrik\Application Data\IObit
2016-11-29 10:26 - 2016-12-16 10:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
2016-11-29 10:26 - 2016-12-01 09:21 - 00000000 ____D C:\Program Files\IObit
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-18 17:40 - 2012-01-14 16:37 - 00000000 ____D C:\Documents and Settings\cukrik\Local Settings\Temp
2016-12-18 16:33 - 2015-07-26 14:12 - 00000000 ____D C:\Documents and Settings\cukrik\My Documents\Preberanie
2016-12-18 15:12 - 2012-01-14 16:35 - 00032560 _____ C:\WINDOWS\SchedLgU.Txt
2016-12-18 15:12 - 2012-01-14 16:35 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-12-18 14:57 - 2012-01-14 19:02 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-12-18 14:53 - 2014-09-09 17:12 - 00000430 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-12-18 14:51 - 2016-05-13 05:01 - 00000446 _____ C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1463112084.job
2016-12-18 14:51 - 2015-08-25 12:33 - 00000280 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-725345543-1715567821-1417001333-1003.job
2016-12-18 14:51 - 2015-07-26 15:21 - 00000316 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-12-18 14:50 - 2012-01-14 17:13 - 00000211 ___SH C:\boot.ini
2016-12-18 14:50 - 2012-01-14 16:37 - 00000178 ___SH C:\Documents and Settings\cukrik\ntuser.ini
2016-12-18 14:50 - 2012-01-14 16:37 - 00000000 ____D C:\Documents and Settings\cukrik
2016-12-18 14:50 - 2007-07-27 13:00 - 00000582 _____ C:\WINDOWS\win.ini
2016-12-18 14:50 - 2007-07-27 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-12-18 14:49 - 2016-01-16 11:04 - 00000000 ____D C:\WINDOWS\pss
2016-12-18 14:44 - 2015-08-07 11:12 - 01089374 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-18-0.dat
2016-12-18 14:44 - 2015-08-07 11:12 - 00272678 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2016-12-18 13:56 - 2012-01-14 18:45 - 00000000 ____D C:\Program Files\Real
2016-12-18 13:46 - 2012-01-14 18:45 - 00000000 ____D C:\Documents and Settings\cukrik\Application Data\Real
2016-12-18 13:45 - 2012-01-14 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real
2016-12-18 13:42 - 2013-12-24 17:04 - 00000288 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-725345543-1715567821-1417001333-1003.job
2016-12-18 13:40 - 2012-01-14 17:45 - 00057344 _____ C:\Documents and Settings\cukrik\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-12-18 13:31 - 2013-12-11 18:50 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-18 13:31 - 2013-12-11 18:50 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-18 13:00 - 2015-08-07 13:56 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-12-18 13:00 - 2007-07-27 13:00 - 00002278 _____ C:\WINDOWS\system32\wpa.dbl
2016-12-16 12:27 - 2016-10-21 10:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-12-16 11:08 - 2015-07-26 15:21 - 00735488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-12-16 11:08 - 2015-07-26 15:21 - 00433768 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2016-12-16 11:08 - 2015-07-26 15:21 - 00224752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00184592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00092256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00066688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00060424 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-12-16 11:06 - 2015-07-26 15:21 - 00034008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-12-16 11:05 - 2016-03-23 13:40 - 00035096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-12-16 10:43 - 2012-01-14 17:08 - 00000000 ___HD C:\WINDOWS\inf
2016-12-16 10:17 - 2012-01-14 16:35 - 00000000 __SHD C:\Documents and Settings\LocalService
2016-12-16 10:17 - 2012-01-14 16:34 - 00000000 __SHD C:\Documents and Settings\NetworkService
2016-12-16 10:17 - 2012-01-14 16:25 - 00000000 ____D C:\WINDOWS\Registration
2016-12-16 10:12 - 2012-01-14 16:27 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-12-16 09:54 - 2012-01-14 18:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ICQ
2016-12-16 09:28 - 2012-01-14 18:46 - 00000288 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-725345543-1715567821-1417001333-1003.job
2016-12-16 09:28 - 2012-01-14 18:46 - 00000280 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-725345543-1715567821-1417001333-1003.job
2016-12-15 09:55 - 2012-09-13 21:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
2016-12-14 12:35 - 2016-08-01 12:14 - 00094129 _____ C:\Documents and Settings\cukrik\Desktop\rôzne kontakty n.xlsx
2016-12-06 07:55 - 2012-01-14 17:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2016-12-03 20:25 - 2012-01-14 16:29 - 00001507 _____ C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
2016-12-02 07:41 - 2016-06-16 10:28 - 00000000 _____ C:\WINDOWS\system32\last.dump
2016-12-01 12:39 - 2016-10-04 12:46 - 00000000 ____D C:\Documents and Settings\cukrik\Application Data\Solvusoft
2016-12-01 09:21 - 2016-06-16 10:49 - 00000000 ___RD C:\Program Files\Skype
2016-11-29 13:37 - 2015-08-07 13:56 - 00000730 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2016-11-29 13:24 - 2012-01-14 19:03 - 00000000 ____D C:\Documents and Settings\cukrik\Application Data\Skype
2016-11-29 13:10 - 2012-01-14 19:03 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2016-11-29 07:26 - 2015-08-08 10:09 - 00000000 ____D C:\Documents and Settings\cukrik\Local Settings\Application Data\MalwareProtectionLive
2016-11-28 07:04 - 2012-01-14 17:07 - 00000000 ____D C:\Documents and Settings\cukrik\Local Settings\Application Data\Adobe
2016-11-28 07:03 - 2012-04-13 14:27 - 00796352 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-11-28 07:03 - 2012-01-14 18:19 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-11-25 07:02 - 2012-01-14 17:16 - 00608248 ____C C:\WINDOWS\system32\PerfStringBackup.INI
==================== Files in the root of some directories =======
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 _____ () C:\Documents and Settings\cukrik\Application Data\Guides
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 _____ () C:\Documents and Settings\cukrik\Application Data\Guitars
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 _____ () C:\Documents and Settings\cukrik\Application Data\Hybrid Chords
2012-01-14 17:45 - 2016-12-18 13:40 - 0057344 _____ () C:\Documents and Settings\cukrik\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-01-02 08:52 - 2013-01-02 08:52 - 0000564 _____ () C:\Documents and Settings\cukrik\Local Settings\Application Data\FSCache.dat
2012-12-24 22:02 - 2012-12-24 22:02 - 0000000 _____ () C:\Documents and Settings\All Users\Application Data\Folder Actions Handlers
2012-12-24 22:02 - 2012-12-24 22:02 - 0000000 _____ () C:\Documents and Settings\All Users\Application Data\Hybrid Basic
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
2012-10-31 15:37 - 2012-12-24 22:02 - 0000000 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
2012-10-31 15:36 - 2012-12-24 22:02 - 0000000 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe
[2008-04-14 04:42] - [2012-01-23 20:48] - 0507904 ____A (Microsoft Corporation) 679A7259741F6A09994F02CE261B5F2E
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\dnsapi.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit