Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-08-2016
Ran by Martin (administrator) on MARTIN-F146E (10-08-2016 22:00:28)
Running from C:\Documents and Settings\Martin\Plocha
Loaded Profiles: Martin (Available Profiles: Martin)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-20\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-861567501-1343024091-839522115-1003\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{7A4A1194-824F-4E4F-8D93-EAB9838A0AF4}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-861567501-1343024091-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearchHKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeHKU\S-1-5-21-861567501-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page =
hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearchURLSearchHook: HKU\S-1-5-21-861567501-1343024091-839522115-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\windows\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-861567501-1343024091-839522115-1003 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-861567501-1343024091-839522115-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
Toolbar: HKU\S-1-5-21-861567501-1343024091-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\system32\browseui.dll [2008-04-14] (Společnost Microsoft)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
hxxp://fpdownload.macromedia.com/pub/sh ... wflash.cabFireFox:
========
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [No File]
Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-09]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-09]
CHR Extension: (Disk Google) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-09]
CHR Extension: (YouTube) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-09]
CHR Extension: (Tabulky Google) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-09]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-09]
CHR Extension: (Gmail) - C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-09]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 6to4; C:\windows\System32\6to4svc.dll [100352 2008-04-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ALCXWDM; C:\windows\System32\drivers\ALCXWDM.SYS [4122368 2015-12-04] (Realtek Semiconductor Corp.)
S3 CCDECODE; C:\windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 FET5X86V; C:\windows\System32\DRIVERS\fetnd5bv.sys [48128 2015-12-04] (VIA Technologies, Inc. )
S3 GeneStor; C:\windows\System32\DRIVERS\GeneStor.sys [56832 2016-02-22] (GenesysLogic)
R0 giveio; C:\windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2016-04-18] (REALiX(tm))
S3 NdisIP; C:\windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R1 prodrv06; C:\windows\System32\drivers\prodrv06.sys [80576 2004-10-07] (Protection Technology) [File not signed]
R0 prohlp02; C:\windows\System32\drivers\prohlp02.sys [115744 2004-10-07] (Protection Technology) [File not signed]
R0 prosync1; C:\windows\System32\drivers\prosync1.sys [7040 2004-07-19] (Protection Technology) [File not signed]
R0 sfhlp01; C:\windows\System32\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) [File not signed]
R0 speedfan; C:\windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
S3 tap0901; C:\windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 Tcpip6; C:\windows\System32\DRIVERS\tcpip6.sys [225664 2008-04-14] (Microsoft Corporation)
U3 TrueSight; C:\WINDOWS\system32\drivers\TrueSight.sys [24688 2016-08-09] ()
R3 w29n51; C:\windows\System32\DRIVERS\w29n51.sys [2216064 2015-12-04] (Intel® Corporation)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2016-02-16] (Huawei Technologies Co., Ltd.)
U5 ScsiPort; C:\windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 WinUSB; system32\DRIVERS\WinUSB.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-10 22:00 - 2016-08-10 22:00 - 00007936 _____ C:\Documents and Settings\Martin\Plocha\FRST.txt
2016-08-10 22:00 - 2016-08-10 22:00 - 00000000 ____D C:\FRST
2016-08-10 21:58 - 2016-08-10 21:58 - 01743872 _____ (Farbar) C:\Documents and Settings\Martin\Plocha\FRST.exe
2016-08-10 11:11 - 2016-08-10 11:11 - 00000937 _____ C:\DelFix.txt
2016-08-10 07:39 - 2016-08-10 22:00 - 00000000 ____D C:\Documents and Settings\Martin\Local Settings\temp
2016-08-10 07:39 - 2016-08-10 07:39 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2016-08-10 07:39 - 2016-08-10 07:39 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\temp
2016-08-10 07:39 - 2016-08-10 07:39 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp
2016-08-09 21:04 - 2016-08-09 20:49 - 00024064 _____ C:\windows\zoek-delete.exe
2016-08-07 20:45 - 2016-08-07 20:45 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_GeneStor_01009.Wdf
2016-08-07 13:30 - 2016-08-07 13:30 - 00001819 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome.lnk
2016-08-07 13:30 - 2016-08-07 13:30 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2016-08-05 21:56 - 2016-08-05 21:56 - 00796352 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2016-08-05 21:56 - 2016-08-05 21:56 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2016-08-05 21:56 - 2016-08-05 21:56 - 00000958 _____ C:\windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-08-05 21:56 - 2016-08-05 21:56 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-08-02 21:55 - 2016-08-02 21:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\IObit
2016-08-02 20:12 - 2016-08-02 20:12 - 00050688 _____ (Atribune.org) C:\Documents and Settings\Martin\Plocha\ATF-Cleaner.exe
2016-07-27 21:43 - 2016-07-27 21:59 - 00000000 ____D C:\Documents and Settings\Martin\Local Settings\Data aplikací\NPE
2016-07-27 21:43 - 2016-07-27 21:44 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Norton
2016-07-24 16:24 - 2016-07-24 16:24 - 00001111 _____ C:\Documents and Settings\Martin\Plocha\Medal of Honor Widescreen & Custom Resolution Utility.lnk
2016-07-24 16:24 - 2016-07-24 16:24 - 00000677 _____ C:\Documents and Settings\Martin\Plocha\Medal of Honor Breakthrough.lnk
2016-07-24 16:24 - 2016-07-24 16:24 - 00000656 _____ C:\Documents and Settings\Martin\Plocha\Medal of Honor Spearhead.lnk
2016-07-24 16:24 - 2016-07-24 16:24 - 00000622 _____ C:\Documents and Settings\Martin\Plocha\Medal of Honor Allied Assault.lnk
2016-07-24 16:24 - 2016-07-24 16:24 - 00000000 ____D C:\Documents and Settings\Martin\Nabídka Start\Programy\MOH Revival
2016-07-24 16:05 - 2016-04-04 23:34 - 00000000 ____D C:\Documents and Settings\Martin\Dokumenty\MOHAA REVIVAL
2016-07-24 14:01 - 2016-07-24 14:02 - 00000000 ____D C:\Documents and Settings\Martin\Dokumenty\Mafia 2 CZ
2016-07-24 12:34 - 2016-07-24 12:34 - 00000747 _____ C:\Documents and Settings\Martin\Plocha\Counter-Strike 1.6.lnk
2016-07-24 12:34 - 2016-07-24 12:34 - 00000000 ____D C:\Documents and Settings\Martin\Nabídka Start\Programy\Counter-Strike 1.6
2016-07-24 12:30 - 2016-07-24 12:34 - 00000000 ____D C:\Program Files\Counter-Strike 1.6
2016-07-20 19:25 - 2016-07-20 19:25 - 00000682 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2016-07-20 19:25 - 2016-07-20 19:25 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-10 22:00 - 2015-12-04 20:59 - 00000000 ____D C:\Documents and Settings\Martin\Plocha
2016-08-10 17:33 - 2015-12-04 20:59 - 00000178 ___SH C:\Documents and Settings\Martin\ntuser.ini
2016-08-10 17:16 - 2015-12-05 02:02 - 00011184 _____ C:\Documents and Settings\Martin\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2016-08-10 11:09 - 2015-12-04 21:42 - 00091088 _____ C:\windows\system32\FNTCACHE.DAT
2016-08-10 11:07 - 2016-03-24 17:52 - 00000000 ___SD C:\Documents and Settings\Martin\UserData
2016-08-10 11:07 - 2015-12-04 20:59 - 00000000 ____D C:\Documents and Settings\Martin
2016-08-10 11:01 - 2015-12-11 01:23 - 00000000 ____D C:\windows\erdnt
2016-08-10 07:36 - 2001-10-25 14:00 - 00000227 ____N C:\windows\system.ini
2016-08-10 07:35 - 2015-12-04 21:42 - 00262144 _____ C:\windows\system32\config\SECURITY.bak
2016-08-10 07:35 - 2015-12-04 21:42 - 00262144 _____ C:\windows\system32\config\SAM.bak
2016-08-10 07:35 - 2015-12-04 21:41 - 15466496 _____ C:\windows\system32\config\software.bak
2016-08-10 07:35 - 2015-12-04 21:41 - 04980736 _____ C:\windows\system32\config\system.bak
2016-08-10 07:35 - 2015-12-04 21:41 - 00262144 _____ C:\windows\system32\config\default.bak
2016-08-10 07:34 - 2015-12-15 23:37 - 00000000 ____D C:\Program Files\Skype
2016-08-10 07:28 - 2015-12-04 20:59 - 00000000 ____D C:\Documents and Settings\Martin\Data aplikací
2016-08-10 07:26 - 2015-12-04 20:59 - 00000000 ____D C:\Documents and Settings\Martin\Dokumenty
2016-08-09 21:01 - 2015-12-04 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací
2016-08-09 20:51 - 2015-12-04 20:59 - 00000000 ___HD C:\Documents and Settings\Martin\Local Settings\Data aplikací
2016-08-09 20:25 - 2015-12-06 00:36 - 00024688 _____ C:\windows\system32\Drivers\TrueSight.sys
2016-08-09 18:59 - 2001-10-25 14:00 - 00002206 _____ C:\windows\system32\wpa.dbl
2016-08-07 21:03 - 2016-02-06 18:41 - 00000000 ____D C:\Documents and Settings\All Users\Dokumenty\filmy
2016-08-07 21:00 - 2016-05-04 17:29 - 00000000 ____D C:\Documents and Settings\Martin\Data aplikací\BSplayer
2016-08-07 15:07 - 2016-04-17 06:08 - 00539550 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-861567501-1343024091-839522115-1003-0.dat
2016-08-07 15:07 - 2016-04-17 06:08 - 00080750 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2016-08-07 14:04 - 2016-03-24 17:50 - 00000000 ___RD C:\Documents and Settings\Martin\Dokumenty\Filmy
2016-08-07 13:30 - 2015-12-04 21:51 - 00000000 ____D C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google
2016-08-07 13:30 - 2015-12-04 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-08-07 13:30 - 2015-12-04 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-08-07 13:29 - 2015-12-04 21:49 - 00000000 ____D C:\Program Files\Google
2016-08-07 13:14 - 2015-12-04 21:57 - 00000000 ____D C:\Documents and Settings\Martin\Data aplikací\uTorrent
2016-08-07 11:37 - 2015-12-04 20:59 - 00000000 ____D C:\Documents and Settings\Martin\Nabídka Start\Programy
2016-08-05 21:56 - 2015-12-04 20:51 - 00000000 ____D C:\windows\system32\Macromed
2016-08-05 18:22 - 2015-12-07 02:50 - 00114176 _____ C:\Documents and Settings\Martin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-08-02 21:19 - 2016-06-02 09:03 - 00000000 ____D C:\Program Files\SpeedFan
2016-07-31 15:21 - 2016-03-16 23:35 - 00000000 ___HD C:\windows\system32\GroupPolicy
2016-07-31 13:39 - 2015-12-04 21:38 - 00000000 ___RD C:\windows\Web
2016-07-30 11:48 - 2016-06-03 22:20 - 00000000 ____D C:\Documents and Settings\Martin\Data aplikací\Seznam.cz
2016-07-29 20:36 - 2015-12-04 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2016-07-24 16:38 - 2015-12-04 21:44 - 01088860 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-24 16:38 - 2001-10-25 14:00 - 00452984 _____ C:\windows\system32\perfh005.dat
2016-07-24 16:38 - 2001-10-25 14:00 - 00089592 _____ C:\windows\system32\perfc005.dat
2016-07-24 16:30 - 2015-12-04 21:38 - 00000000 ____D C:\windows\system32\mui
2016-07-24 16:25 - 2015-12-04 21:38 - 00000000 ____D C:\windows\inf
2016-07-20 19:25 - 2016-04-03 13:25 - 00000000 ____D C:\Program Files\CCleaner
==================== Files in the root of some directories =======
2015-12-07 02:50 - 2016-08-05 18:22 - 0114176 _____ () C:\Documents and Settings\Martin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-04-18 23:28 - 2016-04-18 23:28 - 0000036 _____ () C:\Documents and Settings\Martin\Local Settings\Data aplikací\housecall.guid.cache
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================