FRST 1. log (FRST.txt)Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by HP (administrator) on HP-NB on 21-04-2015 22:16:09
Running from C:\Users\HP\Desktop
Loaded Profiles: HP (Available profiles: HP)
Platform: Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Agere Systems) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-14] (Avast Software s.r.o.)
HKLM\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\041507ba-6806-44c4-8cb4-e2376fcf1af7.exe [183232 2015-04-21] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll [2007-09-13] (Intel Corporation)
HKU\S-1-5-21-2901653510-423565564-4026880338-1000\...\MountPoints2: {e635e490-7784-11e2-b555-001f29ab65cd} - F:\LaunchU3.exe -a
HKU\S-1-5-18\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31344744 2015-02-26] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-01-16]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-14] (Avast Software s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2901653510-423565564-4026880338-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-14] (Avast Software s.r.o.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
FireFox:
========
FF ProfilePath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\y7vc3d37.default
FF DefaultSearchEngine: Seznam
FF SearchEngineOrder.3: Bing
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\y7vc3d37.default\searchplugins\seznam-avast.xml [2014-10-21]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml [2013-07-06]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-09-16]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2008-08-26] (Agere Systems)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-14] (Avast Software s.r.o.)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [107448 2015-04-14] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-14] (Avast Software)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-04-14] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-04-14] (Avast Software s.r.o.)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-04-14] (Avast Software s.r.o.)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12112 2015-04-14] (ALWIL Software)
R0 aswNdis2; C:\Windows\system32\Drivers\aswNdis2.sys [253728 2015-04-14] (Avast Software s.r.o.)
R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-04-14] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-04-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-04-14] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-04-14] (Avast Software s.r.o.)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-04-14] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-04-14] ()
R2 BrPar; C:\Windows\System32\drivers\BrPar.sys [19537 2000-07-24] (Brother Industries Ltd.) [File not signed]
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1083880 2009-04-11] (Společnost Microsoft)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-14] (Avast Software)
S3 cpuz135; \??\C:\Users\HP\AppData\Local\Temp\cpuz135\cpuz135_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 22:16 - 2015-04-21 22:16 - 00009199 _____ () C:\Users\HP\Desktop\FRST.txt
2015-04-21 22:15 - 2015-04-21 22:16 - 00000000 ____D () C:\FRST
2015-04-21 22:14 - 2015-04-21 22:14 - 01139200 _____ (Farbar) C:\Users\HP\Desktop\FRST.exe
2015-04-20 21:39 - 2015-04-20 21:39 - 00005164 _____ () C:\Users\HP\Desktop\hijackthis.log
2015-04-19 12:25 - 2015-04-19 12:25 - 00847441 _____ () C:\Users\HP\Downloads\k. zákon.htm
2015-04-19 12:25 - 2015-04-19 12:25 - 00000000 ____D () C:\Users\HP\Downloads\k. zákon_soubory
2015-04-17 17:46 - 2015-04-17 16:59 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-04-17 17:01 - 2015-04-17 17:52 - 00007738 _____ () C:\zoek-results.log
2015-04-17 16:58 - 2015-04-17 17:42 - 00000000 ____D () C:\zoek_backup
2015-04-17 16:53 - 2015-04-17 16:53 - 01305600 _____ () C:\Users\HP\Desktop\zoek.exe
2015-04-15 20:23 - 2015-04-17 16:41 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2015-04-15 20:22 - 2015-04-15 20:28 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-04-15 20:21 - 2015-04-15 20:22 - 16866392 _____ () C:\Users\HP\Desktop\RogueKiller.exe
2015-04-15 20:15 - 2015-04-15 20:15 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-HP-NB-Windows-Vista-(TM)-Business-(32-bit).dat
2015-04-15 20:15 - 2015-04-15 20:15 - 00000000 ____D () C:\RegBackup
2015-04-15 20:14 - 2015-04-15 20:14 - 02687136 _____ (Thisisu) C:\Users\HP\Desktop\JRT.exe
2015-04-15 19:40 - 2015-04-17 16:21 - 00001665 _____ () C:\Users\HP\Desktop\postup.txt
2015-04-15 10:13 - 2015-04-15 19:41 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-15 10:12 - 2015-04-15 10:12 - 00000859 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-15 10:12 - 2015-04-15 10:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-15 10:12 - 2015-04-15 10:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-15 10:12 - 2015-04-15 10:12 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-15 10:12 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-15 10:12 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-15 10:12 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-15 10:11 - 2015-04-15 10:11 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\HP\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-15 10:05 - 2015-04-15 20:05 - 00000000 ____D () C:\AdwCleaner
2015-04-15 10:04 - 2015-04-15 10:04 - 02217984 _____ () C:\Users\HP\Desktop\adwcleaner_4.201.exe
2015-04-15 10:00 - 2015-04-15 10:00 - 00000000 _____ () C:\Users\HP\AppData\Local\AtStart.txt
2015-04-15 09:55 - 2015-04-15 09:56 - 00448512 _____ (OldTimer Tools) C:\Users\HP\Desktop\TFC.exe
2015-04-15 09:50 - 2015-04-15 09:50 - 00050688 _____ (Atribune.org) C:\Users\HP\Desktop\ATF-Cleaner.exe
2015-04-15 07:26 - 2015-04-15 07:26 - 00388608 _____ (Trend Micro Inc.) C:\Users\HP\Desktop\HijackThis.exe
2015-04-15 06:41 - 2015-04-15 06:42 - 00000000 ____D () C:\Windows\system32\vbox
2015-04-14 22:46 - 2015-04-14 22:46 - 00001849 _____ () C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-04-14 22:46 - 2015-04-14 22:46 - 00001789 _____ () C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-04-14 22:43 - 2015-04-14 22:37 - 00026096 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswKbd.sys
2015-04-14 22:43 - 2015-04-14 22:30 - 00253728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswNdis2.sys
2015-04-14 22:42 - 2015-04-14 22:39 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-14 22:39 - 2015-04-14 22:40 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-14 22:30 - 2015-04-14 22:30 - 00012112 _____ (ALWIL Software) C:\Windows\system32\Drivers\aswNdis.sys
2015-04-04 20:05 - 2015-04-15 09:55 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-22 19:20 - 2015-03-22 19:20 - 00000052 _____ () C:\Users\HP\Desktop\deletelink.txt
2015-03-22 18:40 - 2015-03-22 18:51 - 639614785 _____ () C:\Users\HP\Desktop\a.rar
2015-03-22 18:37 - 2015-03-22 18:39 - 00000000 ____D () C:\Users\HP\Desktop\fotkyfotak
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 21:46 - 2009-04-11 14:36 - 01343066 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 21:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 21:40 - 2006-11-02 14:47 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 21:40 - 2006-11-02 14:47 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-20 22:35 - 2013-01-16 18:31 - 00001076 _____ () C:\Windows\bthservsdp.dat
2015-04-20 22:35 - 2006-11-02 15:01 - 00032622 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-20 22:30 - 2013-04-12 20:52 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-17 17:52 - 2006-11-02 15:00 - 00337478 _____ () C:\Windows\PFRO.log
2015-04-16 06:29 - 2009-04-13 11:21 - 01393902 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 10:00 - 2013-01-16 18:13 - 00000000 _____ () C:\Users\HP\AppData\Local\QSwitch.txt
2015-04-15 10:00 - 2013-01-16 18:13 - 00000000 _____ () C:\Users\HP\AppData\Local\DSwitch.txt
2015-04-15 09:48 - 2013-01-16 18:52 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-04-15 09:44 - 2013-01-16 17:58 - 00054608 _____ () C:\Users\HP\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-15 09:42 - 2006-11-02 14:47 - 00247760 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-15 07:31 - 2013-02-28 21:22 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Seznam.cz
2015-04-15 06:39 - 2013-01-16 18:31 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 06:39 - 2013-01-16 18:31 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-14 22:42 - 2014-10-15 19:48 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00057888 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswTdi.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00055200 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr.sys
2015-04-14 22:42 - 2013-09-16 16:28 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-14 22:37 - 2013-09-16 16:28 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-03-22 19:13 - 2013-02-28 21:22 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Skype
2015-03-22 19:12 - 2015-01-28 20:45 - 00000000 ___RD () C:\Program Files\Skype
2015-03-22 19:12 - 2013-02-28 21:21 - 00000000 ____D () C:\ProgramData\Skype
2015-03-22 18:42 - 2013-01-17 20:59 - 00050688 _____ () C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Files in the root of some directories =======
2013-01-16 19:39 - 2013-01-16 19:39 - 0023888 _____ () C:\Users\HP\AppData\Roaming\UserTile.png
2015-04-15 10:00 - 2015-04-15 10:00 - 0000000 _____ () C:\Users\HP\AppData\Local\AtStart.txt
2013-01-17 20:59 - 2015-03-22 18:42 - 0050688 _____ () C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-01-16 18:13 - 2015-04-15 10:00 - 0000000 _____ () C:\Users\HP\AppData\Local\DSwitch.txt
2013-05-11 17:40 - 2013-05-11 17:40 - 0000000 _____ () C:\Users\HP\AppData\Local\FnF4.txt
2013-01-16 18:13 - 2015-04-15 10:00 - 0000000 _____ () C:\Users\HP\AppData\Local\QSwitch.txt
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-21 21:46
==================== End Of Log ============================
FRST 2. log (Addition.txt)Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-04-2015
Ran by HP at 2015-04-21 22:17:12
Running from C:\Users\HP\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - LSI Corporation)
Avast Internet Security (HKLM\...\avast) (Version: 10.2.2215 - AVAST Software)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11b Network Adapter) (Version: 5.10.38.26 - Broadcom Corporation)
Brother HL-2030 (HKLM\...\{EFE91F72-4E57-424D-8674-FAAA05FFC9CC}) (Version: 1.00 - Brother)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
HP Integrated Module with Bluetooth wireless technology (HKLM\...\{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}) (Version: 6.0.1.3700 - HP)
HP PCMCIA Smart Card Reader (HKLM\...\{24B3DF86-75B9-4DBD-AC39-C0C041583E6F}) (Version: 1.01.0001 - HP)
HP PCMCIA Smart Card Reader (HKLM\...\{CDA1ADA3-BBB4-4250-B272-AC21C78C3968}) (Version: 1.03 - HP)
HP Quick Launch Buttons (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - )
Malwarebytes Anti-Malware verze 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 37.0.1 (x86 cs) (HKLM\...\Mozilla Firefox 37.0.1 (x86 cs)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
OpenOffice.org 3.4 (HKLM\...\{F0C0221D-1DCD-487A-A3D1-E0C5B954F1DC}) (Version: 3.4.9590 - OpenOffice.org)
QLBCASL (Version: 6.40.17.2 - Hewlett-Packard) Hidden
Skype™ 7.2 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
The KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.7.0.109 - KMP Media co., Ltd)
WinRAR 5.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
30-03-2015 14:34:17 Windows Update
04-04-2015 19:11:48 Windows Update
12-04-2015 07:25:41 Windows Update
14-04-2015 22:16:45 avast! antivirus system restore point
16-04-2015 06:22:07 Windows Update
17-04-2015 17:01:26 zoek.exe restore point
19-04-2015 10:34:07 Naplánovaný kontrolní bod
20-04-2015 17:07:14 Naplánovaný kontrolní bod
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 12:23 - 2015-04-17 17:06 - 00000781 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {85AC7BBC-AED9-417D-82E9-E830B40C40C3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {8A4AEB9C-4A3D-414C-B18A-47DC38104B57} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2008-01-21] (Společnost Microsoft)
Task: {9D76891A-51A7-4AD2-8279-2F835A934504} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: {FA921AA5-1CF8-44C3-BF4C-CBE43386129D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-14] (Avast Software s.r.o.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) ==============
2006-12-20 13:18 - 2006-12-20 13:18 - 00126976 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2015-04-14 22:39 - 2015-04-14 22:39 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-14 22:39 - 2015-04-14 22:39 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-04-20 15:21 - 2015-04-20 15:21 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15041901\algo.dll
2015-04-21 21:42 - 2015-04-21 21:42 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15042101\algo.dll
2015-03-17 18:14 - 2015-04-14 22:41 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2006-12-20 13:00 - 2006-12-20 13:00 - 00389120 _____ () C:\Windows\system32\btwhidcs.DLL
2007-09-13 23:11 - 2007-09-13 23:11 - 00249856 _____ () C:\Windows\system32\igfxTMM.dll
2009-07-01 16:44 - 2009-07-01 16:44 - 00632888 _____ () C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2901653510-423565564-4026880338-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HP\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
DNS Servers: 213.46.172.37 - 213.46.172.36
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-2901653510-423565564-4026880338-500 - Administrator - Disabled)
Guest (S-1-5-21-2901653510-423565564-4026880338-501 - Limited - Disabled)
HP (S-1-5-21-2901653510-423565564-4026880338-1000 - Administrator - Enabled) => C:\Users\HP
==================== Faulty Device Manager Devices =============
Name: Fingerprint Sensor
Description: Fingerprint Sensor
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (04/21/2015 09:40:16 PM) (Source: Microsoft-Windows-ResourcePublication) (EventID: 1002) (User: NT AUTHORITY)
Description: Provider\Microsoft.Base.Publication/Publication/Computer
Error: (04/20/2015 10:22:26 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: Místní adaptér Bluetooth selhal. Důvod selhaní nebylo možno určit a adaptér nebude používán. Ovladač vysílače byl vyjmut z paměti.
Error: (04/20/2015 05:22:58 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}
Error: (04/20/2015 05:22:55 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {6295DF2D-35EE-11D1-8707-00C04FD93327}
Error: (04/20/2015 03:20:44 PM) (Source: Microsoft-Windows-ResourcePublication) (EventID: 1002) (User: NT AUTHORITY)
Description: Provider\Microsoft.Base.Publication/Publication/Computer
Error: (04/19/2015 07:24:17 AM) (Source: Microsoft-Windows-ResourcePublication) (EventID: 1002) (User: NT AUTHORITY)
Description: Provider\Microsoft.Base.Publication/Publication/Computer
Error: (04/18/2015 10:56:25 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: Místní adaptér Bluetooth selhal. Důvod selhaní nebylo možno určit a adaptér nebude používán. Ovladač vysílače byl vyjmut z paměti.
Error: (04/17/2015 05:52:40 PM) (Source: Microsoft-Windows-ResourcePublication) (EventID: 1002) (User: NT AUTHORITY)
Description: Provider\Microsoft.Base.Publication/Publication/Computer
Error: (04/17/2015 05:42:11 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (04/17/2015 05:42:07 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2015-04-21 22:17:06.458
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:06.395
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:06.348
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:06.286
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:06.068
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:06.021
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:05.958
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:17:05.912
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:16:39.922
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-04-21 22:16:39.844
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU 560 @ 2.13GHz
Percentage of memory in use: 65%
Total physical RAM: 1014.52 MB
Available physical RAM: 350.69 MB
Total Pagefile: 2295.37 MB
Available Pagefile: 1450.54 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.41 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:74.53 GB) (Free:23.06 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 74.5 GB) (Disk ID: 5CA61DE0)
Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================