Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23.09.2018
Ran by Peter (administrator) on LEGO (23-09-2018 19:59:48)
Running from C:\Documents and Settings\Peter\Dokumenty\Preberanie
Loaded Profiles: Peter (Available Profiles: Oleg & Peter)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: "C:\Program Files\Opera\Opera.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
() C:\Program Files\CDBurnerXP\NMSAccessU.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Jiří Pokorný) C:\MrTimer\MT.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Program Files\Multimedia Mouse Driver\V5\MouseDrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Documents and Settings\Peter\Dokumenty\Preberanie\adwcleaner_6.044(1).exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
(Microsoft Corporation) C:\PROGRA~1\MICROS~2\OFFICE11\OIS.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16126464 2007-03-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [DTHAR_MrTimer] => c:\MrTimer\MT.exe [457216 2018-04-01] (Jiří Pokorný)
HKLM\...\Run: [WireLessMouse] => C:\Program Files\Multimedia Mouse Driver\V5\StartAutorun.exe [94208 2005-11-30] ()
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04] (SUPERAntiSpyware.com)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2011-07-28] (ATI Technologies Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKU\S-1-5-21-1417001333-1425521274-839522115-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-1417001333-1425521274-839522115-1004\...\Run: [GUDelayStartup] => C:\Program Files\Glary Utilities 5\StartupManager.exe [43984 2016-07-25] (Glarysoft Ltd)
HKU\S-1-5-21-1417001333-1425521274-839522115-1004\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-19] (SuperAdBlocker.com)
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-1417001333-1425521274-839522115-1004] => 62.209.225.107:8080
AutoConfigURL: [S-1-5-21-1417001333-1425521274-839522115-1004] => 62.209.225.107:8080
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [147456 2008-08-29] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C7189156-12AD-4E9E-AFE2-D0CADC5ECB14}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1417001333-1425521274-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1417001333-1425521274-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.sk/
URLSearchHook: HKLM -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKU\S-1-5-21-1417001333-1425521274-839522115-1004 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL =
SearchScopes: HKU\S-1-5-21-1417001333-1425521274-839522115-1004 -> {5E52A13F-68E8-4C61-9311-CA74A8EE5A1B} URL = hxxp://
www.google.co.uk/search?hl=en&q={search ... 1I7ADFA_cs
SearchScopes: HKU\S-1-5-21-1417001333-1425521274-839522115-1004 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll [2006-11-07] (TechSmith Corporation)
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll [2008-03-25] (Sun Microsystems, Inc.)
BHO: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: No Name -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> No File
Toolbar: HKLM - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll [2006-11-07] (TechSmith Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1195759640170
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default [2018-09-23]
FF Homepage: C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default -> google.sk/
FF Extension: (Avira Browser Safety) - C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default\Extensions\
abs@avira.com.xpi [2018-09-08]
FF Extension: (Домашняя страница Mail.Ru) - C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default\Extensions\
homepage@mail.ru.xpi [2018-07-30] [Legacy]
FF Extension: (Поиск@Mail.Ru) - C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default\Extensions\
search@mail.ru.xpi [2018-07-30] [Legacy]
FF Extension: (LastPass: Free Password Manager) - C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default\Extensions\
support@lastpass.com.xpi [2018-09-22]
FF Extension: (Визуальные закладки @Mail.Ru) - C:\Documents and Settings\Peter\Data aplikací\Mozilla\Firefox\Profiles\3IHGLblr.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.xpi [2018-07-30] [Legacy]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-02] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll [2017-01-07] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2008-10-01] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.3088 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2007-12-21] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.11.3006 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2007-12-21] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin:
yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Yahoo!\Common\npyaxmpb.dll [2006-11-03] (Yahoo! Inc.)
FF Plugin HKU\.DEFAULT: ditec.sk/DSigXadesFb -> C:\Program Files\Ditec\DSigXades\npDitec.Zep.DSigXadesFb.dll [2015-04-09] (Ditec,a.s.)
FF Plugin HKU\S-1-5-21-1417001333-1425521274-839522115-1004: ditec.sk/DSigXadesFb -> C:\Program Files\Ditec\DSigXades\npDitec.Zep.DSigXadesFb.dll [2015-04-09] (Ditec,a.s.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> inline.go.mail.ru/homepage?inline_comp=hp&inline_hp_cnt=11956636
CHR StartupUrls: Default -> "hxxp://google.sk/"
CHR Profile: C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default [2018-09-23]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-09-15]
CHR Extension: (Avira Browser Safety) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2018-05-27]
CHR Extension: (Ads Removal) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen [2014-03-01]
CHR Extension: (Dokumenty Google v režime offline) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-31]
CHR Extension: (AdBlock) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-09-22]
CHR Extension: (LastPass: Free Password Manager) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-09-09]
CHR Extension: (VXG Media Player) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hncknjnnbahamgpjoafdebabmoamcnni [2018-09-09]
CHR Extension: (IP Address and Domain Information) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhgkegeccnckoiliokondpaaalbhafoa [2018-08-12]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-07-10]
CHR Extension: (Tipli do prehliadača) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\mpijoellhiljjmeeloljbehhhjkpijpb [2018-03-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Peter\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [fppjhfcgnalgfiimdflmikpifodndljf] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gbnhehnpnbiioheicppmmmjaekcdfigc] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1417001333-1425521274-839522115-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - <no Path/update_url>
CHR HKU\S-1-5-21-1417001333-1425521274-839522115-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-31] (SUPERAntiSpyware.com)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [270936 2017-01-07] (Adobe Systems Incorporated) [File not signed]
S4 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-10-01] (Apple Inc.)
S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [520192 2007-06-06] () [File not signed]
R2 FoxitReaderService; C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2017-10-29] (Foxit Software Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4753104 2018-05-09] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2007-10-12] ()
S4 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [987704 2010-12-21] (Secunia)
S4 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [399416 2010-12-21] (Secunia)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [43008 2006-06-19] (Advanced Micro Devices)
R2 Angelnt; C:\WINDOWS\System32\Drivers\ANGELNT.SYS [51072 2012-12-26] (Identcode Ltd.) [File not signed]
R0 BootDefragDriver; C:\WINDOWS\System32\drivers\BootDefragDriver.sys [14784 2014-07-18] (Glarysoft Ltd)
S3 CA561; C:\WINDOWS\System32\Drivers\SPCA561.SYS [119798 2003-08-15] (SP) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 cpuz132; C:\Program Files\CPUID\PC Wizard 2009\pcwiz32.sys [12672 2009-03-07] (Windows (R) Codename Longhorn DDK provider) [File not signed]
S4 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [55968 2016-06-28] (ESET)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [128736 2018-04-26] (Malwarebytes)
R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54752 2009-08-05] (Microsoft Corporation)
S3 GemCCID; C:\WINDOWS\System32\DRIVERS\GemCCID.sys [98816 2013-02-22] (Gemalto)
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [17472 2015-05-02] (Glarysoft Ltd)
R1 GUSBootStartup; C:\WINDOWS\System32\drivers\GUSBootStartup.sys [17472 2016-07-31] (Glarysoft Ltd)
R3 HdAudAddService; C:\WINDOWS\System32\drivers\AtiHdAud.sys [84992 2006-12-28] (ATI Research Inc.)
S3 k750bus; C:\WINDOWS\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI)
S3 k750mdfl; C:\WINDOWS\System32\DRIVERS\k750mdfl.sys [6576 2005-02-11] (MCCI)
S3 k750mdm; C:\WINDOWS\System32\DRIVERS\k750mdm.sys [89872 2005-02-11] (MCCI)
S3 k750mgmt; C:\WINDOWS\System32\DRIVERS\k750mgmt.sys [81728 2005-02-11] (MCCI)
S3 k750obex; C:\WINDOWS\System32\DRIVERS\k750obex.sys [79488 2005-02-11] (MCCI)
S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [40160 2018-08-24] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [220896 2018-09-23] (Malwarebytes)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [50704 2010-01-27] (CACE Technologies, Inc.)
S3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SASENUM; C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [12872 2010-02-20] ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [31744 2008-04-14] (Microsoft Corporation)
S3 catchme; no ImagePath
U2 CertPropSvc; no ImagePath
S3 ESETCleanersDriver; \??\C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [X]
S3 GMSIPCI; no ImagePath
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
S3 NTACCESS; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SetupNTGLM7X; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-09-23 19:58 - 2018-09-23 19:59 - 000000000 ____D C:\FRST
2018-09-23 17:15 - 2018-09-23 17:15 - 000001917 _____ C:\WINDOWS\imsins.BAK
2018-09-23 13:14 - 2018-09-23 13:14 - 000013159 _____ C:\Documents and Settings\All Users\Data aplikací\agent.1537701262.bdinstall.bin
2018-09-23 12:31 - 2018-09-23 13:06 - 000065536 _____ C:\WINDOWS\system32\config\COMODO I.evt
2018-09-23 12:28 - 2018-09-23 13:08 - 000000000 ____D C:\Program Files\COMODO
2018-09-23 12:27 - 2018-09-23 13:08 - 000000000 ____D C:\Documents and Settings\All Users\Data aplikací\Comodo
2018-09-22 02:02 - 2018-09-22 20:45 - 000065536 _____ C:\WINDOWS\system32\config\Kaspersk.evt
2018-09-22 01:54 - 2018-09-22 01:55 - 000000000 ____D C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
2018-09-17 07:00 - 2018-09-17 07:06 - 000000000 ____D C:\Documents and Settings\Peter\Plocha\BALKON
2018-09-02 08:42 - 2018-09-02 08:42 - 012577994 _____ C:\Documents and Settings\Peter\Plocha\www.zjykedu.net_attachment_cms_item_2016_11_16_11_3351af62f3cb19d7.pdf
2018-08-26 07:38 - 2018-08-26 07:38 - 000000000 ____D C:\Program Files\SuperScan
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-09-23 20:01 - 2011-08-07 06:49 - 000000000 ____D C:\Documents and Settings\Peter\Local Settings\temp
2018-09-23 19:59 - 2018-08-13 07:14 - 000000000 ____D C:\Documents and Settings\Peter\Dokumenty\Preberanie
2018-09-23 18:45 - 2018-07-07 11:25 - 000301568 _____ C:\Documents and Settings\Peter\Plocha\telefony.xls
2018-09-23 18:45 - 2008-02-14 13:50 - 000000000 ____D C:\Documents and Settings\Peter\Plocha
2018-09-23 15:23 - 2011-12-04 21:01 - 000000000 ____D C:\Documents and Settings\Peter\Data aplikací\vlc
2018-09-23 15:15 - 2016-07-31 14:59 - 000000000 ____D C:\AdwCleaner
2018-09-23 14:52 - 2014-09-01 09:22 - 000000316 _____ C:\WINDOWS\Tasks\GlaryInitialize 5.job
2018-09-23 14:51 - 2018-08-13 07:17 - 000220896 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2018-09-23 14:51 - 2008-02-14 13:50 - 000000000 ___HD C:\Documents and Settings\Peter\Šablony
2018-09-23 14:51 - 2007-11-22 20:34 - 000000006 ___HC C:\WINDOWS\Tasks\SA.DAT
2018-09-23 14:50 - 2008-02-14 13:50 - 000000272 __SHC C:\Documents and Settings\Peter\ntuser.ini
2018-09-23 14:50 - 2007-11-22 20:38 - 000032606 _____ C:\WINDOWS\SchedLgU.Txt
2018-09-23 14:49 - 2009-06-17 20:57 - 000000000 ____D C:\Documents and Settings\All Users\Data aplikací\ICQ
2018-09-23 14:49 - 2007-11-22 21:23 - 000000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2018-09-23 14:49 - 2007-11-22 21:22 - 000000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2018-09-23 13:29 - 2014-07-06 02:30 - 000000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2018-09-23 13:29 - 2010-02-09 01:13 - 000000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2018-09-23 13:24 - 2014-09-01 09:21 - 000000000 ____D C:\Program Files\Glary Utilities 5
2018-09-23 13:10 - 2007-11-22 21:23 - 000000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2018-09-23 13:10 - 2007-11-22 21:23 - 000000000 ____D C:\Documents and Settings\All Users\Plocha
2018-09-23 13:10 - 2007-11-22 21:17 - 000000000 ___HD C:\WINDOWS\inf
2018-09-23 12:37 - 2018-04-01 13:12 - 000000934 _____ C:\Documents and Settings\Peter\Plocha\Start Tor Browser.lnk
2018-09-23 07:00 - 2008-02-14 13:50 - 000000000 ___HD C:\Documents and Settings\Peter\Local Settings\Data aplikací
2018-09-22 20:45 - 2015-05-31 11:56 - 001371232 ____C C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1417001333-1425521274-839522115-1004-0.dat
2018-09-22 20:45 - 2014-08-30 23:13 - 000422990 ____C C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2018-09-22 20:45 - 2008-02-14 13:50 - 000000000 ____D C:\Documents and Settings\Peter
2018-09-22 20:45 - 2007-11-22 20:39 - 000000272 __SHC C:\Documents and Settings\Oleg\ntuser.ini
2018-09-22 20:35 - 2007-11-22 21:22 - 000000000 ____D C:\Documents and Settings\All Users
2018-09-22 20:32 - 2011-07-17 18:58 - 000000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2018-09-22 18:42 - 2011-08-07 06:49 - 000000000 ____D C:\Documents and Settings\Oleg\Local Settings\temp
2018-09-22 02:15 - 2007-11-22 22:03 - 000000000 ____D C:\WINDOWS\system32\ReinstallBackups
2018-09-22 01:47 - 2007-11-23 01:22 - 000000000 ____D C:\Program Files\Eset
2018-09-22 01:10 - 2001-10-25 14:00 - 000002206 ____C C:\WINDOWS\system32\wpa.dbl
2018-09-16 04:26 - 2018-04-15 01:26 - 000000000 ____D C:\Documents and Settings\Peter\Plocha\NEW
2018-09-08 02:12 - 2017-12-24 14:44 - 003146240 _____ C:\Documents and Settings\Peter\Plocha\byt dom garaz.xls
2018-08-25 09:41 - 2018-08-13 05:30 - 000000732 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Angry IP Scanner.lnk
2018-08-25 09:41 - 2018-08-13 05:30 - 000000000 ____D C:\Program Files\Angry IP Scanner
2018-08-24 17:17 - 2018-08-13 07:17 - 000040160 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
==================== Files in the root of some directories =======
2012-01-01 13:56 - 2010-01-26 12:11 - 000444283 ____C () C:\Program Files\Common Files\WinPcapNmap.exe
2013-03-24 12:37 - 2013-03-24 12:39 - 000000004 ____C () C:\Documents and Settings\Peter\Data aplikací\skype.ini
2013-05-19 18:59 - 2013-05-19 18:59 - 000000024 __SHC () C:\Documents and Settings\Peter\Data aplikací\System3192SettingsDB.dat
2013-05-19 18:59 - 2013-05-19 18:59 - 000000024 __SHC () C:\Documents and Settings\Peter\Data aplikací\Win4665 Config DB.dlx
2011-07-31 06:58 - 2011-07-31 07:01 - 000013342 __SHC () C:\Documents and Settings\Peter\Local Settings\Data aplikací\52c1p0356p6sh1mid75lk43j05sm85
2009-11-15 16:42 - 2018-07-30 09:40 - 000032768 ____C () C:\Documents and Settings\Peter\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-07-31 16:45 - 2016-07-31 16:45 - 000012745 _____ () C:\Documents and Settings\All Users\Data aplikací\1469976325.bdinstall.bin
2016-07-31 16:51 - 2016-07-31 16:51 - 000211736 _____ () C:\Documents and Settings\All Users\Data aplikací\1469976573.bdinstall.bin
2016-07-31 17:00 - 2016-07-31 17:00 - 000037177 _____ () C:\Documents and Settings\All Users\Data aplikací\1469977242.bdinstall.bin
2016-07-31 17:01 - 2016-07-31 17:01 - 000058359 _____ () C:\Documents and Settings\All Users\Data aplikací\1469977245.bdinstall.bin
2016-07-31 17:02 - 2016-07-31 17:02 - 000031930 _____ () C:\Documents and Settings\All Users\Data aplikací\1469977299.bdinstall.bin
2016-07-31 17:04 - 2016-07-31 17:04 - 000095775 _____ () C:\Documents and Settings\All Users\Data aplikací\1469977430.bdinstall.bin
2011-07-31 06:58 - 2011-07-31 07:01 - 000013342 __SHC () C:\Documents and Settings\All Users\Data aplikací\52c1p0356p6sh1mid75lk43j05sm85
2018-09-23 13:14 - 2018-09-23 13:14 - 000013159 _____ () C:\Documents and Settings\All Users\Data aplikací\agent.1537701262.bdinstall.bin
2007-11-23 02:13 - 2007-11-23 02:13 - 000000032 ____C () C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
2013-09-08 16:56 - 2013-09-08 18:31 - 000000000 ____C () C:\Documents and Settings\All Users\Data aplikací\r8rrmqbn.ctrl
2013-09-08 16:56 - 2013-09-08 19:04 - 095025368 ___CT () C:\Documents and Settings\All Users\Data aplikací\r8rrmqbn.pff
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================