Prosím o kontrolu logu - občasné zasekávání
Napsal: 26 srp 2019 12:02
Zdravím,
dostal se mi do rukou 2v1 staříček Acer IconiaTAB s Windows 7 Home Premium 32 bit, který dříve sloužil přítelkyni, nyní si na něm syn pouští youtube a pohádky.
Podařilo se mi stroj částečně vyčistit pomocí MalwareBytes, ale nedaří se mi na něm zprovoznit antivir (buď selže již instalace/první spuštění - modrá smrt, zásek - nebo při skenování havěti). Zkoušel jsem avast, eset free, původně tam byl symantec, ale již skončila platnost licence.
Zároveň bych se rád zeptal - s ohledem na omezený výkon stroje (CPU AMD C50 1GHz, 2GB RAM a 32GB SSD disk) - jaké security řešení pro tento stroj použít? Zajímavý se mi v tomto směru jevil eset online...
Předem děkuji
Petr
FRST (addition přiloženo jako soubor):
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-08-2019
Ran by Lucka (administrator) on LUCKA-PC (acer ICONIA Tab W500) (26-08-2019 12:34:54)
Running from C:\Users\Lucka\Desktop
Loaded Profiles: Lucka (Available Profiles: Lucka)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\HIDMon\HIDMON.exe
() [File not signed] C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(Acer Incorporated -> Acer) C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\Acer Ring.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files\Bluetooth Suite\AdminService.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Atheros Communications Inc. -> Atheros Communications) [File not signed] C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Communications Inc. -> Atheros) [File not signed] C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
(CyberLink -> CyberLink Corp.) C:\Program Files\Acer\clear.fi\MVP\clear.fiAgent.exe
(Dritek System Inc. -> ) C:\Program Files\Acer\Device Control\ADevCtrl.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Device Control\AdWmiSvc.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Skype Software Sarl -> Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Skype Software Sarl -> Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-13] (Advanced Micro Devices, Inc.) [File not signed]
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10025576 2011-01-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1530472 2011-01-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [ADevCtrl] => C:\Program Files\Acer\Device Control\ADevCtrl.exe [239696 2011-02-22] (Dritek System Inc. -> )
HKLM\...\Run: [AcerRingLauncher] => C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\AcerRingLauncher.exe [15248 2011-03-05] (Acer Incorporated -> Acer)
HKLM\...\Run: [OOTag] => C:\Program Files\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Acer Incorporated -> Microsoft)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [1070160 2011-02-11] (Dritek System Inc. -> Dritek System Inc.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [490656 2011-01-06] (Atheros Communications Inc. -> Atheros Communications) [File not signed]
HKLM\...\Run: [AthBtTray] => C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240 2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715368 2011-02-22] (Acer Incorporated -> Acer Incorporated)
HKLM\...\Run: [xLaunchHIDMon] => C:\Program Files\HIDMon\HIDMon.exe [114688 2011-02-11] () [File not signed]
HKLM\...\Run: [AutoScreenRotationBlocker] => C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe [114768 2011-02-21] (Dritek System Inc. -> Dritek System Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\...\Run: [Google Update] => C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\GoogleUpdateCore.exe [410920 2019-08-26] (Google Inc -> Google LLC)
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk [2011-03-07]
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated -> Acer Incorporated)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01D951A4-CDCB-4316-9897-7AC040111EA1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} C:\Program Files\Windows Live\SOXE\wlsoxe.dll [179584 2010-09-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B495595-19CA-41E1-8D55-0A32CBEE08DB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3473166551-1568802319-3614615059-1000UA => C:\Users\Lucka\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-12-12] (Google Inc -> Google Inc.)
Task: {449DABD0-0B4B-4F66-A176-683D6C4D1C49} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-08-26] (Adobe Inc. -> Adobe)
Task: {4BC1E29C-BC24-43DE-BFAA-999A8C58F3F4} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe
Task: {61DBA6B8-CBBE-48A5-9B95-870393A8A374} - System32\Tasks\clear.fi => C:\Program Files\Acer\clear.fi\MVP\clear.fi.exe [264760 2011-02-18] (CyberLink -> Acer Incorporated)
Task: {65306B7F-D2D1-4DD4-9FDB-7F492A962A50} - System32\Tasks\{2BE83876-D6BB-4B18-9677-FC4661CB933D} => "C:\Program Files\Internet Explorer\iexplore.exe" hxxp://www.skype.com/go/downloading?source=lig ... tError=404
Task: {70997E82-7302-4DB3-9955-D6536BBAEECE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {758DB2F2-4233-47CB-979D-E23AD634E34A} - System32\Tasks\clear.fiAgent => C:\Program Files\Acer\clear.fi\MVP\clear.fiAgent.exe [120104 2011-02-18] (CyberLink -> CyberLink Corp.)
Task: {956C09F6-E93A-4AE9-9AEA-9C38A1949362} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A2A5D9F6-00A2-4409-9779-C17C7E59C831} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1693064 2019-08-26] (AVAST Software s.r.o. -> AVAST Software)
Task: {C4DBF60C-9F0A-4121-97D4-FFFD0F1FDAF5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
Task: {E51E1EB0-6A3F-4F3B-A8AD-F7C9DDB46945} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe
Task: {F3E7A35B-3092-4A87-8391-738AFBB60D12} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3473166551-1568802319-3614615059-1000Core => C:\Users\Lucka\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-12-12] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{3D27BA52-F3CF-49B2-9848-6789AE231AAE}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Internet Explorer:
==================
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://seznam.cz/
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3473166551-1568802319-3614615059-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3473166551-1568802319-3614615059-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files\Bluetooth Suite\IEPlugIn.dll [2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20] (Skype Technologies SA -> Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20] (Skype Technologies SA -> Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) [File not signed]
FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin HKU\S-1-5-21-3473166551-1568802319-3614615059-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-08-26] (Google Inc -> Google LLC)
FF Plugin HKU\S-1-5-21-3473166551-1568802319-3614615059-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-08-26] (Google Inc -> Google LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/?clid=12454
CHR NewTab: Default -> Not-active:"chrome-extension://epjncljanmdaajainajcdpfhepmgcjga/product.html"
CHR DefaultSearchURL: Default -> hxxps://search.seznam.cz/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSuggestURL: Default -> hxxps://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms}
CHR Profile: C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default [2019-08-26]
CHR Extension: (EasyPDFCombine) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\epjncljanmdaajainajcdpfhepmgcjga [2019-08-26]
CHR Extension: (Skype) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12]
CHR Extension: (Chrome Media Router) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-26]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-01-03]
StartMenuInternet: Google Chrome.JEOC5YKK6MOFWA5FHE5IMS2UEY - C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [176128 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros Communications Inc. -> Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [56480 2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363616 2014-01-03] (Skype Software Sarl -> Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748640 2014-01-03] (Skype Software Sarl -> Microsoft Corporation)
R2 DsiDeviceControlService; C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe [66128 2011-02-22] (Dritek System Inc. -> Dritek System Inc.)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [739944 2011-02-22] (Acer Incorporated -> Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated -> Acer Incorporated)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5394136 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated -> Acer Incorporated)
R2 SnxUsbDockingKB2267Srv; C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe [86016 2011-02-04] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [7566848 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [238592 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 androidusb; C:\Windows\System32\Drivers\ssadadb.sys [30312 2011-05-13] (MCCI Internal Testing Software -> Google Inc)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [1884160 2010-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [101392 2010-11-17] (ATI Technologies, Inc -> Advanced Micro Devices)
R3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [81408 2010-12-31] (Microsoft Windows Hardware Compatibility Publisher -> ASIX Electronics Corp.)
R1 BST; C:\Windows\System32\DRIVERS\bma150.sys [15936 2011-01-10] (ROBERT BOSCH TAIWAN CO., LTD. -> Bosch Sensortec GmbH)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [128552 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 HPFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [9344 2007-07-06] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett Packard)
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (Microsoft Windows Hardware Compatibility Publisher -> MCCI)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [173512 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [190624 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [64296 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [241760 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [86768 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 usbfilter; C:\Windows\System32\DRIVERS\usbfilter.sys [35968 2010-11-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-08-26 12:34 - 2019-08-26 12:37 - 000022035 _____ C:\Users\Lucka\Desktop\FRST.txt
2019-08-26 12:34 - 2019-08-26 12:34 - 000000000 ____D C:\Users\Lucka\Desktop\FRST-OlderVersion
2019-08-26 12:33 - 2019-08-26 12:34 - 000000000 ____D C:\Users\Lucka\Desktop\FRST old
2019-08-26 11:25 - 2019-08-26 11:25 - 000064296 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000241760 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000190624 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000173512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000086768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-26 11:23 - 2019-08-26 11:23 - 000001988 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-26 11:23 - 2019-08-26 11:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-26 11:23 - 2019-01-08 16:32 - 000128552 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-08-26 12:34 - 2019-04-29 20:17 - 000000000 ____D C:\FRST
2019-08-26 12:34 - 2019-04-29 19:46 - 001448960 _____ (Farbar) C:\Users\Lucka\Desktop\FRST.exe
2019-08-26 12:29 - 2014-01-03 22:18 - 000000000 ____D C:\Users\Lucka\AppData\Local\Mobogenie
2019-08-26 12:18 - 2013-03-20 12:22 - 000000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2019-08-26 11:34 - 2013-04-01 10:14 - 000002409 _____ C:\Users\Lucka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-26 11:34 - 2013-04-01 10:14 - 000002372 _____ C:\Users\Lucka\Desktop\Google Chrome.lnk
2019-08-26 11:20 - 2009-07-14 06:34 - 000009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-08-26 11:20 - 2009-07-14 06:34 - 000009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-08-26 11:19 - 2013-04-01 12:36 - 000842296 _____ (Adobe) C:\Windows\system32\FlashPlayerApp.exe
2019-08-26 11:19 - 2013-04-01 12:36 - 000175160 _____ (Adobe) C:\Windows\system32\FlashPlayerCPLApp.cpl
2019-08-26 11:19 - 2011-03-07 17:31 - 000000000 ____D C:\Windows\system32\Macromed
2019-08-26 11:14 - 2013-03-20 20:55 - 000668792 _____ C:\Windows\system32\perfh005.dat
2019-08-26 11:14 - 2013-03-20 20:55 - 000141420 _____ C:\Windows\system32\perfc005.dat
2019-08-26 11:14 - 2011-03-07 16:41 - 001583226 _____ C:\Windows\system32\PerfStringBackup.INI
2019-08-26 11:14 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2019-08-26 11:09 - 2019-04-28 23:00 - 000000000 ____D C:\ProgramData\AVAST Software
2019-08-26 11:09 - 2013-03-20 12:22 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-26 11:09 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-26 11:07 - 2019-05-01 16:01 - 000373722 _____ C:\Windows\ntbtlog.txt
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-04-28 21:46
==================== End of FRST.txt ============================
dostal se mi do rukou 2v1 staříček Acer IconiaTAB s Windows 7 Home Premium 32 bit, který dříve sloužil přítelkyni, nyní si na něm syn pouští youtube a pohádky.
Podařilo se mi stroj částečně vyčistit pomocí MalwareBytes, ale nedaří se mi na něm zprovoznit antivir (buď selže již instalace/první spuštění - modrá smrt, zásek - nebo při skenování havěti). Zkoušel jsem avast, eset free, původně tam byl symantec, ale již skončila platnost licence.
Zároveň bych se rád zeptal - s ohledem na omezený výkon stroje (CPU AMD C50 1GHz, 2GB RAM a 32GB SSD disk) - jaké security řešení pro tento stroj použít? Zajímavý se mi v tomto směru jevil eset online...
Předem děkuji
Petr
FRST (addition přiloženo jako soubor):
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-08-2019
Ran by Lucka (administrator) on LUCKA-PC (acer ICONIA Tab W500) (26-08-2019 12:34:54)
Running from C:\Users\Lucka\Desktop
Loaded Profiles: Lucka (Available Profiles: Lucka)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\HIDMon\HIDMON.exe
() [File not signed] C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(Acer Incorporated -> Acer) C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\Acer Ring.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files\Bluetooth Suite\AdminService.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Atheros Communications Inc. -> Atheros Communications) [File not signed] C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Communications Inc. -> Atheros) [File not signed] C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
(CyberLink -> CyberLink Corp.) C:\Program Files\Acer\clear.fi\MVP\clear.fiAgent.exe
(Dritek System Inc. -> ) C:\Program Files\Acer\Device Control\ADevCtrl.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Device Control\AdWmiSvc.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\SwReporter\40.200.201.3\software_reporter_tool.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Skype Software Sarl -> Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Skype Software Sarl -> Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-13] (Advanced Micro Devices, Inc.) [File not signed]
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10025576 2011-01-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1530472 2011-01-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [ADevCtrl] => C:\Program Files\Acer\Device Control\ADevCtrl.exe [239696 2011-02-22] (Dritek System Inc. -> )
HKLM\...\Run: [AcerRingLauncher] => C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\AcerRingLauncher.exe [15248 2011-03-05] (Acer Incorporated -> Acer)
HKLM\...\Run: [OOTag] => C:\Program Files\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Acer Incorporated -> Microsoft)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [1070160 2011-02-11] (Dritek System Inc. -> Dritek System Inc.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [490656 2011-01-06] (Atheros Communications Inc. -> Atheros Communications) [File not signed]
HKLM\...\Run: [AthBtTray] => C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240 2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715368 2011-02-22] (Acer Incorporated -> Acer Incorporated)
HKLM\...\Run: [xLaunchHIDMon] => C:\Program Files\HIDMon\HIDMon.exe [114688 2011-02-11] () [File not signed]
HKLM\...\Run: [AutoScreenRotationBlocker] => C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe [114768 2011-02-21] (Dritek System Inc. -> Dritek System Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\...\Run: [Google Update] => C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\GoogleUpdateCore.exe [410920 2019-08-26] (Google Inc -> Google LLC)
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk [2011-03-07]
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated -> Acer Incorporated)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01D951A4-CDCB-4316-9897-7AC040111EA1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} C:\Program Files\Windows Live\SOXE\wlsoxe.dll [179584 2010-09-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B495595-19CA-41E1-8D55-0A32CBEE08DB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3473166551-1568802319-3614615059-1000UA => C:\Users\Lucka\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-12-12] (Google Inc -> Google Inc.)
Task: {449DABD0-0B4B-4F66-A176-683D6C4D1C49} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-08-26] (Adobe Inc. -> Adobe)
Task: {4BC1E29C-BC24-43DE-BFAA-999A8C58F3F4} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe
Task: {61DBA6B8-CBBE-48A5-9B95-870393A8A374} - System32\Tasks\clear.fi => C:\Program Files\Acer\clear.fi\MVP\clear.fi.exe [264760 2011-02-18] (CyberLink -> Acer Incorporated)
Task: {65306B7F-D2D1-4DD4-9FDB-7F492A962A50} - System32\Tasks\{2BE83876-D6BB-4B18-9677-FC4661CB933D} => "C:\Program Files\Internet Explorer\iexplore.exe" hxxp://www.skype.com/go/downloading?source=lig ... tError=404
Task: {70997E82-7302-4DB3-9955-D6536BBAEECE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {758DB2F2-4233-47CB-979D-E23AD634E34A} - System32\Tasks\clear.fiAgent => C:\Program Files\Acer\clear.fi\MVP\clear.fiAgent.exe [120104 2011-02-18] (CyberLink -> CyberLink Corp.)
Task: {956C09F6-E93A-4AE9-9AEA-9C38A1949362} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A2A5D9F6-00A2-4409-9779-C17C7E59C831} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1693064 2019-08-26] (AVAST Software s.r.o. -> AVAST Software)
Task: {C4DBF60C-9F0A-4121-97D4-FFFD0F1FDAF5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
Task: {E51E1EB0-6A3F-4F3B-A8AD-F7C9DDB46945} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe
Task: {F3E7A35B-3092-4A87-8391-738AFBB60D12} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3473166551-1568802319-3614615059-1000Core => C:\Users\Lucka\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-12-12] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{3D27BA52-F3CF-49B2-9848-6789AE231AAE}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Internet Explorer:
==================
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://seznam.cz/
HKU\S-1-5-21-3473166551-1568802319-3614615059-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3473166551-1568802319-3614615059-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3473166551-1568802319-3614615059-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files\Bluetooth Suite\IEPlugIn.dll [2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20] (Skype Technologies SA -> Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20] (Skype Technologies SA -> Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) [File not signed]
FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin HKU\S-1-5-21-3473166551-1568802319-3614615059-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-08-26] (Google Inc -> Google LLC)
FF Plugin HKU\S-1-5-21-3473166551-1568802319-3614615059-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Lucka\AppData\Local\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-08-26] (Google Inc -> Google LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/?clid=12454
CHR NewTab: Default -> Not-active:"chrome-extension://epjncljanmdaajainajcdpfhepmgcjga/product.html"
CHR DefaultSearchURL: Default -> hxxps://search.seznam.cz/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSuggestURL: Default -> hxxps://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms}
CHR Profile: C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default [2019-08-26]
CHR Extension: (EasyPDFCombine) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\epjncljanmdaajainajcdpfhepmgcjga [2019-08-26]
CHR Extension: (Skype) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12]
CHR Extension: (Chrome Media Router) - C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-26]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-01-03]
StartMenuInternet: Google Chrome.JEOC5YKK6MOFWA5FHE5IMS2UEY - C:\Users\Lucka\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [176128 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros Communications Inc. -> Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [56480 2011-01-06] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363616 2014-01-03] (Skype Software Sarl -> Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748640 2014-01-03] (Skype Software Sarl -> Microsoft Corporation)
R2 DsiDeviceControlService; C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe [66128 2011-02-22] (Dritek System Inc. -> Dritek System Inc.)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [739944 2011-02-22] (Acer Incorporated -> Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated -> Acer Incorporated)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5394136 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated -> Acer Incorporated)
R2 SnxUsbDockingKB2267Srv; C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe [86016 2011-02-04] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [7566848 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [238592 2011-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 androidusb; C:\Windows\System32\Drivers\ssadadb.sys [30312 2011-05-13] (MCCI Internal Testing Software -> Google Inc)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [1884160 2010-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [101392 2010-11-17] (ATI Technologies, Inc -> Advanced Micro Devices)
R3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [81408 2010-12-31] (Microsoft Windows Hardware Compatibility Publisher -> ASIX Electronics Corp.)
R1 BST; C:\Windows\System32\DRIVERS\bma150.sys [15936 2011-01-10] (ROBERT BOSCH TAIWAN CO., LTD. -> Bosch Sensortec GmbH)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [128552 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 HPFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [9344 2007-07-06] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett Packard)
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (Microsoft Windows Hardware Compatibility Publisher -> MCCI)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [173512 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [190624 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [64296 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [241760 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [86768 2019-08-26] (Malwarebytes Corporation -> Malwarebytes)
R3 usbfilter; C:\Windows\System32\DRIVERS\usbfilter.sys [35968 2010-11-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-08-26 12:34 - 2019-08-26 12:37 - 000022035 _____ C:\Users\Lucka\Desktop\FRST.txt
2019-08-26 12:34 - 2019-08-26 12:34 - 000000000 ____D C:\Users\Lucka\Desktop\FRST-OlderVersion
2019-08-26 12:33 - 2019-08-26 12:34 - 000000000 ____D C:\Users\Lucka\Desktop\FRST old
2019-08-26 11:25 - 2019-08-26 11:25 - 000064296 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000241760 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000190624 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000173512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-26 11:24 - 2019-08-26 11:24 - 000086768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-26 11:23 - 2019-08-26 11:23 - 000001988 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-26 11:23 - 2019-08-26 11:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-26 11:23 - 2019-01-08 16:32 - 000128552 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-08-26 12:34 - 2019-04-29 20:17 - 000000000 ____D C:\FRST
2019-08-26 12:34 - 2019-04-29 19:46 - 001448960 _____ (Farbar) C:\Users\Lucka\Desktop\FRST.exe
2019-08-26 12:29 - 2014-01-03 22:18 - 000000000 ____D C:\Users\Lucka\AppData\Local\Mobogenie
2019-08-26 12:18 - 2013-03-20 12:22 - 000000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2019-08-26 11:34 - 2013-04-01 10:14 - 000002409 _____ C:\Users\Lucka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-26 11:34 - 2013-04-01 10:14 - 000002372 _____ C:\Users\Lucka\Desktop\Google Chrome.lnk
2019-08-26 11:20 - 2009-07-14 06:34 - 000009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-08-26 11:20 - 2009-07-14 06:34 - 000009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-08-26 11:19 - 2013-04-01 12:36 - 000842296 _____ (Adobe) C:\Windows\system32\FlashPlayerApp.exe
2019-08-26 11:19 - 2013-04-01 12:36 - 000175160 _____ (Adobe) C:\Windows\system32\FlashPlayerCPLApp.cpl
2019-08-26 11:19 - 2011-03-07 17:31 - 000000000 ____D C:\Windows\system32\Macromed
2019-08-26 11:14 - 2013-03-20 20:55 - 000668792 _____ C:\Windows\system32\perfh005.dat
2019-08-26 11:14 - 2013-03-20 20:55 - 000141420 _____ C:\Windows\system32\perfc005.dat
2019-08-26 11:14 - 2011-03-07 16:41 - 001583226 _____ C:\Windows\system32\PerfStringBackup.INI
2019-08-26 11:14 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2019-08-26 11:09 - 2019-04-28 23:00 - 000000000 ____D C:\ProgramData\AVAST Software
2019-08-26 11:09 - 2013-03-20 12:22 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-26 11:09 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-26 11:07 - 2019-05-01 16:01 - 000373722 _____ C:\Windows\ntbtlog.txt
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-04-28 21:46
==================== End of FRST.txt ============================