Podivné chování prohlížečů
Napsal: 01 zář 2017 14:33
Dobrý den,
prosím Vás o pomoc. Používám program, který běží v počítači na pozadí a uživatelské rozhraní má řešeno přes webový prohlížeč (IE nebo Chrome). Když ale v tomto prostředí kliknu na nějakou položku nebo nastavení, přehodí mě to na nějakou webovou stránku (pokaždé jinou). Zkoušel jsem počítač proskenovat všemi možnými programy (Eset, Security Essentials, Avast, Spybot, Adaware, Kaspersky, Panda), ale bez výsledku. Přikládám logy z FRST. Děkuji za pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2017
Ran by Uzivatel (administrator) on UZIVATEL-PC (01-09-2017 15:18:58)
Running from C:\Users\Uzivatel\Desktop
Loaded Profiles: Uzivatel (Available Profiles: Uzivatel & Classic .NET AppPool & DefaultAppPool)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\Lely\T4C\AFSSynch\AFSSynchronizer.exe
(DeviceVM, Inc.) C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
(Juniper Networks) C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
() C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\sqlservr.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(DeviceVM, Inc.) C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Neowise) C:\Program Files\RoboTask Lite\RoboTaskLite.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CServiceManager.exe
() C:\Program Files\MoomlAgent\MoomlAgent.exe
(Lely) C:\Program Files\Lely\T4C.Mobile\NetworkConnector\NetworkConnector.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Lely) C:\Program Files\Lely\T4C\Bin\T4CNService.exe
(LELY) C:\Program Files\Lely\T4C\Bin\LFWLogService.exe
() C:\Program Files\Lely\T4C\Bin\NedapCowLocator.exe
() C:\Program Files\Lely\T4C\T4CMobileApi\T4C.Api.Service.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\BackupService.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CCalmSynchroniser.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CSynchroniser.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\LelyPDF.Service.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CServices.exe
(VIT-PCS GmbH) C:\Program Files\FoersterTechnik\KM2\kalbmanager_srv.exe
(forum.viry.cz) C:\Users\Uzivatel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCU] => C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe [346320 2009-08-04] (DeviceVM, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7547424 2009-06-25] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-10-01] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [210432 2016-07-05] (Geek Software GmbH)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\...\Run: [RoboTask Lite] => C:\Program Files\RoboTask Lite\RoboTaskLite.exe [1915720 2013-12-05] (Neowise)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\T4C Service Manager.lnk [2010-12-30]
ShortcutTarget: T4C Service Manager.lnk -> C:\Program Files\Lely\T4C\Bin\T4CServiceManager.exe (Lely Industries N.V.)
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MoomlAgent.lnk [2017-03-15]
ShortcutTarget: MoomlAgent.lnk -> C:\Program Files\MoomlAgent\MoomlAgent.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NetworkConnector.lnk [2014-09-01]
ShortcutTarget: NetworkConnector.lnk -> C:\Program Files\Lely\T4C.Mobile\NetworkConnector\NetworkConnector.exe (Lely)
BootExecute: autocheck autochk * sdnclean.exe
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{2F0D9425-7021-467D-AF20-8293CA1AE176}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8C827E41-1970-4E79-B480-8EAA63B58104}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8C827E41-1970-4E79-B480-8EAA63B58104}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO: No Name -> {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-893007568-957827634-3976518877-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-893007568-957827634-3976518877-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default [2017-09-01]
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\ribyj95t.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ribyj95t.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.seznam.cz/
FF Keyword.URL: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Extension: (Video DownloadHelper) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-05-09]
FF Extension: (Adblock Plus) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF Extension: (Seznam lištička) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-08-30]
FF Extension: (Firefox Screenshots) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\features\{36f754ad-f8c6-4995-b9f0-bf5d1c1d927e}\screenshots@mozilla.org.xpi [2017-08-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-09] ()
FF Plugin: @alawar.com/npapi -> C:\Windows\npapi.dll [2014-01-29] (Alawar)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-893007568-957827634-3976518877-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-24] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-893007568-957827634-3976518877-1000: http://www.exent.com/GameTreatWidget -> C:\Program Files\Free Ride Games\npGameTreatWidget.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://localhost/T4C/Content/Login.aspx?ReturnUrl=%2fT4C%2fdefault.aspx"
CHR Profile: C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default [2017-08-30]
CHR Extension: (Dokumenty Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Disk Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-21]
CHR Extension: (YouTube) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-07]
CHR Extension: (Vyhledávání Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-21]
CHR Extension: (Dokumenty Google offline) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-30]
CHR Extension: (Gmail) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-03]
CHR Extension: (Chrome Media Router) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mibfbmhijjgpkmobcfdlelpccpeafoom] - <no Path/update_url>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AFSSynchronizer; C:\Program Files\Lely\T4C\AFSSynch\AFSSynchronizer.exe [23040 2017-02-23] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [212992 2014-11-21] (AMD) [File not signed]
R2 BCUService; C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe [219360 2009-08-04] (DeviceVM, Inc.)
R2 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [692328 2013-04-15] (Juniper Networks)
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation)
R2 GEST Service; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [68136 2009-07-30] ()
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LDNService; C:\Program Files\Lely\T4C\Bin\T4CNService.exe [94208 2010-08-11] (Lely) [File not signed]
R2 LFWLogService; C:\Program Files\Lely\T4C\Bin\LFWLogService.exe [90112 2010-02-15] (LELY) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R2 MSSQL$T4C3; c:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\sqlservr.exe [43130032 2015-03-30] (Microsoft Corporation)
R2 NedapLDService; C:\Program Files\Lely\T4C\Bin\NedapCowLocator.exe [99840 2017-05-22] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SCRLDService; C:\Program Files\SCR\LDService\SCRLDService.exe [7168 2014-09-01] (Microsoft) [File not signed]
S4 SQLAgent$T4C3; c:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\SQLAGENT.EXE [381104 2015-03-30] (Microsoft Corporation)
R2 T4CApiService; C:\Program Files\Lely\T4C\T4cMobileApi\T4C.Api.Service.exe [135680 2017-05-22] () [File not signed]
R2 T4CBackup; C:\Program Files\Lely\T4C\Bin\BackupService.exe [31232 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CCalmSynch; C:\Program Files\Lely\T4C\Bin\T4CCalmSynchroniser.exe [35840 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CDevSynch; C:\Program Files\Lely\T4C\Bin\T4CSynchroniser.exe [1787904 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CDLM; C:\Program Files\Lely\T4C\Bin\LelyPDF.Service.exe [10752 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CGenerator; C:\Program Files\Lely\T4C\Bin\T4CServices.exe [198144 2017-08-01] (Lely Industries N.V.) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5697296 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [16955392 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [472576 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [16955392 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [26624 2013-04-15] (Juniper Networks)
R3 e1qexpress; C:\Windows\System32\DRIVERS\e1q6032.sys [190464 2009-07-14] (Intel Corporation)
S3 eapihdrv; C:\Users\Uzivatel\AppData\Local\Temp\ehdrv.sys [135760 2017-08-28] (ESET)
R3 gdrv; C:\Windows\gdrv.sys [17488 2017-09-01] (Windows (R) 2000 DDK provider)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [250152 2015-03-30] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-06-13] (Duplex Secure Ltd.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam.sys [11520 2009-02-13] (Western Digital Technologies) [File not signed]
R1 wfcre; C:\Windows\System32\drivers\wfcre.sys [112000 2017-07-04] ()
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-01 15:18 - 2017-09-01 15:19 - 000017246 _____ C:\Users\Uzivatel\Desktop\FRST.txt
2017-09-01 15:17 - 2017-09-01 15:17 - 001792512 _____ (Farbar) C:\Users\Uzivatel\Desktop\FRST.exe
2017-09-01 15:17 - 2017-09-01 15:17 - 000112640 _____ (forum.viry.cz) C:\Users\Uzivatel\Desktop\FRSTLauncher.exe
2017-09-01 11:46 - 2017-09-01 11:46 - 000000000 ___HD C:\OneDriveTemp
2017-08-30 16:25 - 2017-08-30 18:01 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\Panda Security
2017-08-30 16:25 - 2017-08-30 16:25 - 000000000 ____D C:\ProgramData\panda_url_filtering
2017-08-30 16:23 - 2017-08-30 18:01 - 000000000 ____D C:\ProgramData\Panda Security
2017-08-30 16:22 - 2017-08-30 16:22 - 001980152 _____ (Panda Security, S.L.) C:\Users\Uzivatel\Downloads\PANDAFREEAV.exe
2017-08-30 13:38 - 2017-08-30 13:38 - 000709709 _____ C:\Users\Uzivatel\Downloads\Mechwarrior.rar
2017-08-30 09:49 - 2017-08-30 09:49 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\AdAwareDesktop
2017-08-30 09:45 - 2017-08-30 09:45 - 002611632 _____ C:\Users\Uzivatel\Downloads\Adaware_Installer.exe
2017-08-28 20:03 - 2017-08-29 05:40 - 000262144 _____ C:\Windows\system32\config\ELAM
2017-08-28 16:59 - 2017-08-28 16:59 - 002412720 _____ (Kaspersky Lab) C:\Users\Uzivatel\Downloads\kts18.0.0.405aben_12562.exe
2017-08-28 15:03 - 2017-08-28 20:04 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-08-28 15:02 - 2017-08-28 15:02 - 002671136 _____ (Kaspersky Lab) C:\Users\Uzivatel\Downloads\kss16.0.0.1344en_ru_de_fr_es_it_zh-hans_pl_tr_nl_cs_ko_id_pt_ar_vi_hi_zh-hant_fa_10837.exe
2017-08-27 16:12 - 2017-08-27 16:48 - 000002084 _____ C:\Windows\wininit.ini
2017-08-27 15:40 - 2017-08-29 05:39 - 000000000 ____D C:\Program Files\Common Files\AV
2017-08-27 14:49 - 2017-08-27 14:49 - 046525608 _____ (Safer-Networking Ltd. ) C:\Users\Uzivatel\Downloads\spybot-2.4.exe
2017-08-26 15:40 - 2017-08-26 15:40 - 000049806 _____ C:\Windows\ntbtlog.txt
2017-08-26 10:03 - 2017-08-26 10:03 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\CEF
2017-08-26 10:02 - 2017-08-26 10:02 - 000921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2017-08-26 06:06 - 2017-08-26 06:06 - 006654960 _____ (AVAST Software) C:\Users\Uzivatel\Downloads\avast_free_antivirus_setup_online.exe
2017-08-24 18:55 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\e792d596-50c3-0
2017-08-24 18:55 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\e792d596-31b5-1
2017-08-24 18:55 - 2017-08-25 16:49 - 000000000 ____D C:\ProgramData\82ff95ce
2017-08-24 18:55 - 2017-08-25 16:49 - 000000000 ____D C:\ProgramData\{D2DFF142-6574-46E9-469D-D015B619F058}
2017-08-24 18:54 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\{67a045f1-512c-1}
2017-08-24 18:54 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\{48d13e98-412c-0}
2017-08-09 08:52 - 2017-07-29 16:50 - 000074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-08-09 08:52 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\system32\msjetoledb40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-08-09 08:52 - 2017-07-14 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-08-09 08:52 - 2017-07-14 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-08-09 08:52 - 2017-07-14 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-08-09 08:52 - 2017-07-14 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-08-09 08:52 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-08-09 08:52 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-08-09 08:52 - 2017-07-08 17:19 - 000250600 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-08-09 08:52 - 2017-07-08 16:51 - 002402816 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 004001000 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-08-09 08:52 - 2017-07-07 17:15 - 003945192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-08-09 08:52 - 2017-07-07 17:15 - 000296680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-08-09 08:52 - 2017-07-07 17:13 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-08-09 08:52 - 2017-07-07 16:52 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-08-09 08:52 - 2017-07-07 16:52 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-08-09 08:52 - 2017-07-07 16:52 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-08-09 08:52 - 2017-07-07 16:52 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-08-09 08:52 - 2017-07-07 16:51 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-08-09 08:52 - 2017-07-07 16:50 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-08-09 08:52 - 2017-07-07 16:48 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-08-09 08:52 - 2017-07-07 16:48 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-08-09 08:52 - 2017-07-07 16:48 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-08-09 08:52 - 2017-07-07 16:47 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-08-09 08:52 - 2017-07-07 16:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-08-09 08:52 - 2017-07-07 16:47 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-08-09 08:52 - 2017-07-07 16:47 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll
2017-08-07 12:08 - 2017-08-07 12:09 - 122366456 _____ (CHENGDU YIWO Tech Development Co., Ltd ) C:\Users\Uzivatel\Downloads\tb_free.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-01 15:18 - 2016-11-18 15:54 - 000000000 ____D C:\Users\Uzivatel\AppData\LocalLow\Mozilla
2017-09-01 14:01 - 2011-06-09 15:06 - 000000000 ____D C:\ProgramData\AlawarWrapper
2017-09-01 11:54 - 2009-07-14 06:34 - 000018240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-01 11:54 - 2009-07-14 06:34 - 000018240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-01 11:48 - 2010-07-14 16:08 - 000000000 ____D C:\log
2017-09-01 11:47 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\inetsrv
2017-09-01 11:46 - 2014-07-28 17:00 - 000000000 ___RD C:\Users\Uzivatel\OneDrive
2017-09-01 11:45 - 2010-08-25 07:34 - 000017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2017-09-01 11:45 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-01 11:42 - 2011-02-05 11:50 - 000000308 _____ C:\Windows\Brownie.ini
2017-09-01 10:03 - 2013-10-30 15:54 - 000000000 ____D C:\FRST
2017-08-31 22:04 - 2014-08-29 14:49 - 000000000 ____D C:\ZalohaT4C
2017-08-31 21:05 - 2010-11-17 00:00 - 000000000 ____D C:\BackupShare
2017-08-31 09:38 - 2014-03-24 12:45 - 000000110 _____ C:\UESKOT.txt
2017-08-31 04:31 - 2014-04-27 17:35 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\vlc
2017-08-30 18:05 - 2010-08-25 07:34 - 000109280 _____ C:\Users\Uzivatel\AppData\Local\GDIPFONTCACHEV1.DAT
2017-08-30 18:05 - 2009-07-14 06:33 - 000409608 _____ C:\Windows\system32\FNTCACHE.DAT
2017-08-30 18:01 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2017-08-30 17:52 - 2015-09-18 11:09 - 000000000 ____D C:\xxx
2017-08-28 21:22 - 2017-07-22 06:01 - 000000000 ____D C:\ProgramData\6e455ca7-1e33-1
2017-08-28 00:00 - 2015-09-18 11:26 - 000000000 ____D C:\MOOML
2017-08-27 16:12 - 2016-03-02 15:50 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\SlimWare Utilities Inc
2017-08-26 15:41 - 2010-08-25 15:00 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\TeamViewer
2017-08-26 12:02 - 2011-10-26 16:40 - 000000000 ____D C:\ProgramData\AVAST Software
2017-08-26 11:30 - 2012-09-02 11:30 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-08-26 04:34 - 2017-01-29 16:02 - 000000000 ____D C:\Recepty
2017-08-26 04:31 - 2017-06-21 04:30 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-08-25 22:15 - 2014-01-16 16:41 - 000002101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-25 22:15 - 2014-01-16 16:41 - 000002089 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-25 19:45 - 2010-08-25 15:00 - 000000000 ____D C:\Program Files\TeamViewer
2017-08-25 15:05 - 2011-10-20 15:20 - 000000925 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-08-24 18:55 - 2017-07-22 06:01 - 000000000 ____D C:\ProgramData\6e455ca7-26a7-0
2017-08-18 10:08 - 2010-08-25 08:27 - 000000000 ____D C:\LELY FILES
2017-08-17 05:51 - 2011-07-15 04:17 - 000019456 _____ C:\Users\Uzivatel\Desktop\Čísla telat.xls
2017-08-14 14:20 - 2010-08-25 08:38 - 000000000 ____D C:\Program Files\Lely
2017-08-10 05:47 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
2017-08-10 05:18 - 2010-08-25 07:12 - 001915994 _____ C:\Windows\system32\PerfStringBackup.INI
2017-08-10 05:18 - 2009-07-14 10:44 - 000788990 _____ C:\Windows\system32\perfh005.dat
2017-08-10 05:18 - 2009-07-14 10:44 - 000187700 _____ C:\Windows\system32\perfc005.dat
2017-08-10 03:06 - 2013-08-11 03:00 - 000000000 ____D C:\Windows\system32\MRT
2017-08-10 03:02 - 2010-08-27 18:17 - 137505280 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-08-09 15:37 - 2015-02-19 18:14 - 000000000 ____D C:\Program Files\DOSBox-0.74
2017-08-09 05:05 - 2012-05-01 04:04 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-08-09 05:05 - 2011-06-15 09:10 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-08-09 05:05 - 2010-08-25 10:25 - 000000000 ____D C:\Windows\system32\Macromed
2017-08-08 17:52 - 2010-08-30 14:36 - 000000000 ____D C:\Users\Uzivatel\Desktop\Somatic test
2017-08-03 15:01 - 2016-10-08 05:23 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\Farm Mania 2.1
==================== Files in the root of some directories =======
2011-03-28 16:33 - 2011-03-28 16:40 - 000762880 ____H () C:\Users\Uzivatel\AppData\Roaming\base_en.db
2014-02-20 17:41 - 2014-02-22 12:47 - 000306157 _____ () C:\Users\Uzivatel\AppData\Roaming\log.sflog
2017-01-26 13:24 - 2017-05-01 18:05 - 000000600 _____ () C:\Users\Uzivatel\AppData\Local\PUTTY.RND
2013-09-21 05:12 - 2013-09-21 05:12 - 000002237 _____ () C:\Users\Uzivatel\AppData\Local\recently-used.xbel
2011-01-20 18:27 - 2011-06-06 16:14 - 000007597 _____ () C:\Users\Uzivatel\AppData\Local\Resmon.ResmonCfg
2010-08-25 10:22 - 2011-02-05 11:32 - 000006410 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2017-08-30 16:24 - 2017-08-30 16:24 - 058117792 _____ (Panda Security, S.L.) C:\Users\Uzivatel\AppData\Local\Temp\{0BA60353-F664-4D66-B58A-ADCB535E7245}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Uzivatel\Desktop" je 3740 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
prosím Vás o pomoc. Používám program, který běží v počítači na pozadí a uživatelské rozhraní má řešeno přes webový prohlížeč (IE nebo Chrome). Když ale v tomto prostředí kliknu na nějakou položku nebo nastavení, přehodí mě to na nějakou webovou stránku (pokaždé jinou). Zkoušel jsem počítač proskenovat všemi možnými programy (Eset, Security Essentials, Avast, Spybot, Adaware, Kaspersky, Panda), ale bez výsledku. Přikládám logy z FRST. Děkuji za pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2017
Ran by Uzivatel (administrator) on UZIVATEL-PC (01-09-2017 15:18:58)
Running from C:\Users\Uzivatel\Desktop
Loaded Profiles: Uzivatel (Available Profiles: Uzivatel & Classic .NET AppPool & DefaultAppPool)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\Lely\T4C\AFSSynch\AFSSynchronizer.exe
(DeviceVM, Inc.) C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
(Juniper Networks) C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
() C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\sqlservr.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(DeviceVM, Inc.) C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Neowise) C:\Program Files\RoboTask Lite\RoboTaskLite.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CServiceManager.exe
() C:\Program Files\MoomlAgent\MoomlAgent.exe
(Lely) C:\Program Files\Lely\T4C.Mobile\NetworkConnector\NetworkConnector.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Lely) C:\Program Files\Lely\T4C\Bin\T4CNService.exe
(LELY) C:\Program Files\Lely\T4C\Bin\LFWLogService.exe
() C:\Program Files\Lely\T4C\Bin\NedapCowLocator.exe
() C:\Program Files\Lely\T4C\T4CMobileApi\T4C.Api.Service.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\BackupService.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CCalmSynchroniser.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CSynchroniser.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\LelyPDF.Service.exe
(Lely Industries N.V.) C:\Program Files\Lely\T4C\Bin\T4CServices.exe
(VIT-PCS GmbH) C:\Program Files\FoersterTechnik\KM2\kalbmanager_srv.exe
(forum.viry.cz) C:\Users\Uzivatel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCU] => C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe [346320 2009-08-04] (DeviceVM, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7547424 2009-06-25] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-10-01] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [210432 2016-07-05] (Geek Software GmbH)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\...\Run: [RoboTask Lite] => C:\Program Files\RoboTask Lite\RoboTaskLite.exe [1915720 2013-12-05] (Neowise)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-893007568-957827634-3976518877-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\T4C Service Manager.lnk [2010-12-30]
ShortcutTarget: T4C Service Manager.lnk -> C:\Program Files\Lely\T4C\Bin\T4CServiceManager.exe (Lely Industries N.V.)
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MoomlAgent.lnk [2017-03-15]
ShortcutTarget: MoomlAgent.lnk -> C:\Program Files\MoomlAgent\MoomlAgent.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NetworkConnector.lnk [2014-09-01]
ShortcutTarget: NetworkConnector.lnk -> C:\Program Files\Lely\T4C.Mobile\NetworkConnector\NetworkConnector.exe (Lely)
BootExecute: autocheck autochk * sdnclean.exe
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{2F0D9425-7021-467D-AF20-8293CA1AE176}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8C827E41-1970-4E79-B480-8EAA63B58104}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8C827E41-1970-4E79-B480-8EAA63B58104}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO: No Name -> {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-893007568-957827634-3976518877-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-893007568-957827634-3976518877-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default [2017-09-01]
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\ribyj95t.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ribyj95t.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.seznam.cz/
FF Keyword.URL: Mozilla\Firefox\Profiles\ribyj95t.default -> hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Extension: (Video DownloadHelper) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-05-09]
FF Extension: (Adblock Plus) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF Extension: (Seznam lištička) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-08-30]
FF Extension: (Firefox Screenshots) - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ribyj95t.default\features\{36f754ad-f8c6-4995-b9f0-bf5d1c1d927e}\screenshots@mozilla.org.xpi [2017-08-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-09] ()
FF Plugin: @alawar.com/npapi -> C:\Windows\npapi.dll [2014-01-29] (Alawar)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-893007568-957827634-3976518877-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-24] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-893007568-957827634-3976518877-1000: http://www.exent.com/GameTreatWidget -> C:\Program Files\Free Ride Games\npGameTreatWidget.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://localhost/T4C/Content/Login.aspx?ReturnUrl=%2fT4C%2fdefault.aspx"
CHR Profile: C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default [2017-08-30]
CHR Extension: (Dokumenty Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Disk Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-21]
CHR Extension: (YouTube) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-07]
CHR Extension: (Vyhledávání Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-21]
CHR Extension: (Dokumenty Google offline) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-30]
CHR Extension: (Gmail) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-03]
CHR Extension: (Chrome Media Router) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mibfbmhijjgpkmobcfdlelpccpeafoom] - <no Path/update_url>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AFSSynchronizer; C:\Program Files\Lely\T4C\AFSSynch\AFSSynchronizer.exe [23040 2017-02-23] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [212992 2014-11-21] (AMD) [File not signed]
R2 BCUService; C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe [219360 2009-08-04] (DeviceVM, Inc.)
R2 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [692328 2013-04-15] (Juniper Networks)
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation)
R2 GEST Service; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [68136 2009-07-30] ()
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LDNService; C:\Program Files\Lely\T4C\Bin\T4CNService.exe [94208 2010-08-11] (Lely) [File not signed]
R2 LFWLogService; C:\Program Files\Lely\T4C\Bin\LFWLogService.exe [90112 2010-02-15] (LELY) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R2 MSSQL$T4C3; c:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\sqlservr.exe [43130032 2015-03-30] (Microsoft Corporation)
R2 NedapLDService; C:\Program Files\Lely\T4C\Bin\NedapCowLocator.exe [99840 2017-05-22] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SCRLDService; C:\Program Files\SCR\LDService\SCRLDService.exe [7168 2014-09-01] (Microsoft) [File not signed]
S4 SQLAgent$T4C3; c:\Program Files\Microsoft SQL Server\MSSQL10_50.T4C3\MSSQL\Binn\SQLAGENT.EXE [381104 2015-03-30] (Microsoft Corporation)
R2 T4CApiService; C:\Program Files\Lely\T4C\T4cMobileApi\T4C.Api.Service.exe [135680 2017-05-22] () [File not signed]
R2 T4CBackup; C:\Program Files\Lely\T4C\Bin\BackupService.exe [31232 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CCalmSynch; C:\Program Files\Lely\T4C\Bin\T4CCalmSynchroniser.exe [35840 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CDevSynch; C:\Program Files\Lely\T4C\Bin\T4CSynchroniser.exe [1787904 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CDLM; C:\Program Files\Lely\T4C\Bin\LelyPDF.Service.exe [10752 2017-05-22] (Lely Industries N.V.) [File not signed]
R2 T4CGenerator; C:\Program Files\Lely\T4C\Bin\T4CServices.exe [198144 2017-08-01] (Lely Industries N.V.) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5697296 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [16955392 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [472576 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [16955392 2014-11-21] (Advanced Micro Devices, Inc.) [File not signed]
R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [26624 2013-04-15] (Juniper Networks)
R3 e1qexpress; C:\Windows\System32\DRIVERS\e1q6032.sys [190464 2009-07-14] (Intel Corporation)
S3 eapihdrv; C:\Users\Uzivatel\AppData\Local\Temp\ehdrv.sys [135760 2017-08-28] (ESET)
R3 gdrv; C:\Windows\gdrv.sys [17488 2017-09-01] (Windows (R) 2000 DDK provider)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [250152 2015-03-30] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-06-13] (Duplex Secure Ltd.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam.sys [11520 2009-02-13] (Western Digital Technologies) [File not signed]
R1 wfcre; C:\Windows\System32\drivers\wfcre.sys [112000 2017-07-04] ()
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-01 15:18 - 2017-09-01 15:19 - 000017246 _____ C:\Users\Uzivatel\Desktop\FRST.txt
2017-09-01 15:17 - 2017-09-01 15:17 - 001792512 _____ (Farbar) C:\Users\Uzivatel\Desktop\FRST.exe
2017-09-01 15:17 - 2017-09-01 15:17 - 000112640 _____ (forum.viry.cz) C:\Users\Uzivatel\Desktop\FRSTLauncher.exe
2017-09-01 11:46 - 2017-09-01 11:46 - 000000000 ___HD C:\OneDriveTemp
2017-08-30 16:25 - 2017-08-30 18:01 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\Panda Security
2017-08-30 16:25 - 2017-08-30 16:25 - 000000000 ____D C:\ProgramData\panda_url_filtering
2017-08-30 16:23 - 2017-08-30 18:01 - 000000000 ____D C:\ProgramData\Panda Security
2017-08-30 16:22 - 2017-08-30 16:22 - 001980152 _____ (Panda Security, S.L.) C:\Users\Uzivatel\Downloads\PANDAFREEAV.exe
2017-08-30 13:38 - 2017-08-30 13:38 - 000709709 _____ C:\Users\Uzivatel\Downloads\Mechwarrior.rar
2017-08-30 09:49 - 2017-08-30 09:49 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\AdAwareDesktop
2017-08-30 09:45 - 2017-08-30 09:45 - 002611632 _____ C:\Users\Uzivatel\Downloads\Adaware_Installer.exe
2017-08-28 20:03 - 2017-08-29 05:40 - 000262144 _____ C:\Windows\system32\config\ELAM
2017-08-28 16:59 - 2017-08-28 16:59 - 002412720 _____ (Kaspersky Lab) C:\Users\Uzivatel\Downloads\kts18.0.0.405aben_12562.exe
2017-08-28 15:03 - 2017-08-28 20:04 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-08-28 15:02 - 2017-08-28 15:02 - 002671136 _____ (Kaspersky Lab) C:\Users\Uzivatel\Downloads\kss16.0.0.1344en_ru_de_fr_es_it_zh-hans_pl_tr_nl_cs_ko_id_pt_ar_vi_hi_zh-hant_fa_10837.exe
2017-08-27 16:12 - 2017-08-27 16:48 - 000002084 _____ C:\Windows\wininit.ini
2017-08-27 15:40 - 2017-08-29 05:39 - 000000000 ____D C:\Program Files\Common Files\AV
2017-08-27 14:49 - 2017-08-27 14:49 - 046525608 _____ (Safer-Networking Ltd. ) C:\Users\Uzivatel\Downloads\spybot-2.4.exe
2017-08-26 15:40 - 2017-08-26 15:40 - 000049806 _____ C:\Windows\ntbtlog.txt
2017-08-26 10:03 - 2017-08-26 10:03 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\CEF
2017-08-26 10:02 - 2017-08-26 10:02 - 000921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2017-08-26 06:06 - 2017-08-26 06:06 - 006654960 _____ (AVAST Software) C:\Users\Uzivatel\Downloads\avast_free_antivirus_setup_online.exe
2017-08-24 18:55 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\e792d596-50c3-0
2017-08-24 18:55 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\e792d596-31b5-1
2017-08-24 18:55 - 2017-08-25 16:49 - 000000000 ____D C:\ProgramData\82ff95ce
2017-08-24 18:55 - 2017-08-25 16:49 - 000000000 ____D C:\ProgramData\{D2DFF142-6574-46E9-469D-D015B619F058}
2017-08-24 18:54 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\{67a045f1-512c-1}
2017-08-24 18:54 - 2017-08-28 21:22 - 000000000 ____D C:\ProgramData\{48d13e98-412c-0}
2017-08-09 08:52 - 2017-07-29 16:50 - 000074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-08-09 08:52 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\system32\msjetoledb40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll
2017-08-09 08:52 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-08-09 08:52 - 2017-07-14 17:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-08-09 08:52 - 2017-07-14 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-08-09 08:52 - 2017-07-14 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-08-09 08:52 - 2017-07-14 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-08-09 08:52 - 2017-07-14 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-08-09 08:52 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-08-09 08:52 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-08-09 08:52 - 2017-07-08 17:19 - 000250600 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-08-09 08:52 - 2017-07-08 16:51 - 002402816 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 004001000 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-08-09 08:52 - 2017-07-07 17:15 - 003945192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-08-09 08:52 - 2017-07-07 17:15 - 000296680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-08-09 08:52 - 2017-07-07 17:15 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-08-09 08:52 - 2017-07-07 17:13 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-08-09 08:52 - 2017-07-07 17:11 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-08-09 08:52 - 2017-07-07 17:10 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-08-09 08:52 - 2017-07-07 16:52 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-08-09 08:52 - 2017-07-07 16:52 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-08-09 08:52 - 2017-07-07 16:52 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-08-09 08:52 - 2017-07-07 16:52 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-08-09 08:52 - 2017-07-07 16:51 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-08-09 08:52 - 2017-07-07 16:50 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-08-09 08:52 - 2017-07-07 16:48 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-08-09 08:52 - 2017-07-07 16:48 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-08-09 08:52 - 2017-07-07 16:48 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-08-09 08:52 - 2017-07-07 16:47 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-08-09 08:52 - 2017-07-07 16:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-08-09 08:52 - 2017-07-07 16:47 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-08-09 08:52 - 2017-07-07 16:47 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll
2017-08-09 08:52 - 2017-07-01 15:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll
2017-08-07 12:08 - 2017-08-07 12:09 - 122366456 _____ (CHENGDU YIWO Tech Development Co., Ltd ) C:\Users\Uzivatel\Downloads\tb_free.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-01 15:18 - 2016-11-18 15:54 - 000000000 ____D C:\Users\Uzivatel\AppData\LocalLow\Mozilla
2017-09-01 14:01 - 2011-06-09 15:06 - 000000000 ____D C:\ProgramData\AlawarWrapper
2017-09-01 11:54 - 2009-07-14 06:34 - 000018240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-01 11:54 - 2009-07-14 06:34 - 000018240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-01 11:48 - 2010-07-14 16:08 - 000000000 ____D C:\log
2017-09-01 11:47 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\inetsrv
2017-09-01 11:46 - 2014-07-28 17:00 - 000000000 ___RD C:\Users\Uzivatel\OneDrive
2017-09-01 11:45 - 2010-08-25 07:34 - 000017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2017-09-01 11:45 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-01 11:42 - 2011-02-05 11:50 - 000000308 _____ C:\Windows\Brownie.ini
2017-09-01 10:03 - 2013-10-30 15:54 - 000000000 ____D C:\FRST
2017-08-31 22:04 - 2014-08-29 14:49 - 000000000 ____D C:\ZalohaT4C
2017-08-31 21:05 - 2010-11-17 00:00 - 000000000 ____D C:\BackupShare
2017-08-31 09:38 - 2014-03-24 12:45 - 000000110 _____ C:\UESKOT.txt
2017-08-31 04:31 - 2014-04-27 17:35 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\vlc
2017-08-30 18:05 - 2010-08-25 07:34 - 000109280 _____ C:\Users\Uzivatel\AppData\Local\GDIPFONTCACHEV1.DAT
2017-08-30 18:05 - 2009-07-14 06:33 - 000409608 _____ C:\Windows\system32\FNTCACHE.DAT
2017-08-30 18:01 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2017-08-30 17:52 - 2015-09-18 11:09 - 000000000 ____D C:\xxx
2017-08-28 21:22 - 2017-07-22 06:01 - 000000000 ____D C:\ProgramData\6e455ca7-1e33-1
2017-08-28 00:00 - 2015-09-18 11:26 - 000000000 ____D C:\MOOML
2017-08-27 16:12 - 2016-03-02 15:50 - 000000000 ____D C:\Users\Uzivatel\AppData\Local\SlimWare Utilities Inc
2017-08-26 15:41 - 2010-08-25 15:00 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\TeamViewer
2017-08-26 12:02 - 2011-10-26 16:40 - 000000000 ____D C:\ProgramData\AVAST Software
2017-08-26 11:30 - 2012-09-02 11:30 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-08-26 04:34 - 2017-01-29 16:02 - 000000000 ____D C:\Recepty
2017-08-26 04:31 - 2017-06-21 04:30 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-08-25 22:15 - 2014-01-16 16:41 - 000002101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-25 22:15 - 2014-01-16 16:41 - 000002089 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-25 19:45 - 2010-08-25 15:00 - 000000000 ____D C:\Program Files\TeamViewer
2017-08-25 15:05 - 2011-10-20 15:20 - 000000925 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-08-24 18:55 - 2017-07-22 06:01 - 000000000 ____D C:\ProgramData\6e455ca7-26a7-0
2017-08-18 10:08 - 2010-08-25 08:27 - 000000000 ____D C:\LELY FILES
2017-08-17 05:51 - 2011-07-15 04:17 - 000019456 _____ C:\Users\Uzivatel\Desktop\Čísla telat.xls
2017-08-14 14:20 - 2010-08-25 08:38 - 000000000 ____D C:\Program Files\Lely
2017-08-10 05:47 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
2017-08-10 05:18 - 2010-08-25 07:12 - 001915994 _____ C:\Windows\system32\PerfStringBackup.INI
2017-08-10 05:18 - 2009-07-14 10:44 - 000788990 _____ C:\Windows\system32\perfh005.dat
2017-08-10 05:18 - 2009-07-14 10:44 - 000187700 _____ C:\Windows\system32\perfc005.dat
2017-08-10 03:06 - 2013-08-11 03:00 - 000000000 ____D C:\Windows\system32\MRT
2017-08-10 03:02 - 2010-08-27 18:17 - 137505280 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-08-09 15:37 - 2015-02-19 18:14 - 000000000 ____D C:\Program Files\DOSBox-0.74
2017-08-09 05:05 - 2012-05-01 04:04 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-08-09 05:05 - 2011-06-15 09:10 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-08-09 05:05 - 2010-08-25 10:25 - 000000000 ____D C:\Windows\system32\Macromed
2017-08-08 17:52 - 2010-08-30 14:36 - 000000000 ____D C:\Users\Uzivatel\Desktop\Somatic test
2017-08-03 15:01 - 2016-10-08 05:23 - 000000000 ____D C:\Users\Uzivatel\AppData\Roaming\Farm Mania 2.1
==================== Files in the root of some directories =======
2011-03-28 16:33 - 2011-03-28 16:40 - 000762880 ____H () C:\Users\Uzivatel\AppData\Roaming\base_en.db
2014-02-20 17:41 - 2014-02-22 12:47 - 000306157 _____ () C:\Users\Uzivatel\AppData\Roaming\log.sflog
2017-01-26 13:24 - 2017-05-01 18:05 - 000000600 _____ () C:\Users\Uzivatel\AppData\Local\PUTTY.RND
2013-09-21 05:12 - 2013-09-21 05:12 - 000002237 _____ () C:\Users\Uzivatel\AppData\Local\recently-used.xbel
2011-01-20 18:27 - 2011-06-06 16:14 - 000007597 _____ () C:\Users\Uzivatel\AppData\Local\Resmon.ResmonCfg
2010-08-25 10:22 - 2011-02-05 11:32 - 000006410 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2017-08-30 16:24 - 2017-08-30 16:24 - 058117792 _____ (Panda Security, S.L.) C:\Users\Uzivatel\AppData\Local\Temp\{0BA60353-F664-4D66-B58A-ADCB535E7245}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Uzivatel\Desktop" je 3740 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================