Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Velke mnozstvi odeslane posty - prosim o kontrolu logu PC2

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Velke mnozstvi odeslane posty - prosim o kontrolu logu PC2

#1 Příspěvek od Miguelow »

Dobry den,
UPC napsalo ze mi blokuje port 25, vecer bezeli jen dva stroje, oba logy jsou na fore, prosim o prohlidku:

Logfile of random's system information tool 1.06 (written by random/random)
Run by MajklB at 2010-04-29 09:26:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (12%) free of 30 GB
Total RAM: 1022 MB (32% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:55, on 29.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_UranusWatchDog.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_WebServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_ConfigurationServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_StreamingServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_RecordingServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_QueryServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_EventServer.exe
C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_BackupServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
H:\Antivir_spec\RSIT\RSIT.exe
C:\Program Files\trend micro\MajklB.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-515967899-1647877149-725345543-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'ST7501PGSQL')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Download All by ASUS Download - C:\Program Files\ASUS\WL-500gP Wireless Router Utilities\ASDownloadAll.htm
O8 - Extra context menu item: Download using ASUS Download - C:\Program Files\ASUS\WL-500gP Wireless Router Utilities\ASDownload.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1FBDF235-C5A9-4F21-BD79-9EC0DCF8AC29} (CV781Object Object) - http://192.168.1.175/AVC_AX_DVR.cab
O16 - DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} (Moonlight MPEG-4 Video Decoder) - http://192.168.1.140/activex/decoder/mpeg4_dec.cab
O16 - DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} (RtspVaPgCtrlNew Class) - http://192.168.1.108/RtspVaPgDec.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://192.168.1.176/activex/AMC.cab
O16 - DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} (pmjpegcam Class) - http://cam.balloonfacility.com/JpegInst.cab
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Program Files\Vivotek Inc\ST7501\pgsql\bin\pg_ctl.exe
O23 - Service: ST7501 Uranus Watch Dog - Unknown owner - C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_UranusWatchDog.exe

--
End of file - 8248 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-1647877149-725345543-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-1647877149-725345543-1003.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F754E009-4675-47CB-8136-DE396B710C3F}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-15 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-09-11 2054360]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"P17Helper"=Rundll32 P17.dll,P17Helper []
"CloneCDTray"=C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2004-12-27 57344]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-03-18 202256]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-03-16 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-03-16 13670504]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-04-29 09:26:46 ----D---- C:\Program Files\trend micro
2010-04-29 09:26:45 ----D---- C:\rsit
2010-04-27 17:33:19 ----D---- C:\WINDOWS\system32\Logs
2010-04-26 10:59:00 ----D---- C:\Program Files\Defraggler
2010-04-21 13:22:39 ----RD---- C:\Documents and Settings\MajklB\Data aplikací\Brother
2010-04-21 13:22:04 ----A---- C:\WINDOWS\BRWMARK.INI
2010-04-21 13:22:04 ----A---- C:\WINDOWS\BRPP2KA.INI
2010-04-21 13:22:03 ----A---- C:\WINDOWS\system32\brss01a.ini
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\bsplmf01.exe
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\bsplmf01.dll
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\BrWia05a.dll
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\BrUSi05a.dll
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\brsvc01a.exe
2010-04-21 13:20:28 ----A---- C:\WINDOWS\system32\brss01a.exe
2010-04-21 11:27:43 ----D---- C:\Program Files\Microsoft SQL Server
2010-04-21 11:27:28 ----D---- C:\Program Files\NUUO
2010-04-21 09:36:49 ----D---- C:\Recording
2010-04-21 09:36:42 ----D---- C:\Program Files\Vivotek Inc
2010-04-21 09:17:40 ----D---- C:\BlueIris
2010-04-21 09:15:03 ----D---- C:\Program Files\Blue Iris
2010-04-16 08:53:15 ----D---- C:\Documents and Settings\MajklB\Data aplikací\MFP and Storage Server
2010-04-16 08:51:37 ----D---- C:\Program Files\TP-LINK
2010-04-15 15:32:46 ----A---- C:\WINDOWS\system32\javaws.exe
2010-04-15 15:32:46 ----A---- C:\WINDOWS\system32\javaw.exe
2010-04-15 15:32:46 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-04-15 15:32:45 ----A---- C:\WINDOWS\system32\java.exe
2010-04-15 08:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 08:16:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 08:16:38 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-04-15 08:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-04-15 08:13:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 08:12:54 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-15 08:12:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-15 08:11:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-14 08:32:06 ----D---- C:\log
2010-04-14 08:27:52 ----A---- C:\ST7501_Install_Log.txt
2010-04-12 09:41:58 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-04-12 09:41:56 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-04-12 09:41:31 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2010-04-12 09:41:31 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2010-04-12 09:41:27 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2010-04-12 09:41:25 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2010-04-12 09:41:22 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-04-12 09:41:17 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-04-12 09:41:13 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-04-12 09:41:10 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-04-12 09:41:08 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-04-12 09:41:05 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-04-12 09:41:04 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-04-12 09:41:01 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-04-12 09:41:01 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-04-12 09:40:59 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-04-12 09:40:57 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-04-12 09:40:57 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-04-12 09:40:55 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-04-12 09:40:53 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-04-12 09:36:07 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-04-12 09:36:06 ----D---- C:\Documents and Settings\MajklB\Data aplikací\Thinstall
2010-04-09 13:24:09 ----A---- C:\WINDOWS\system32\CNMLM93.DLL
2010-04-09 13:24:06 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2010-04-09 13:23:53 ----A---- C:\WINDOWS\system32\CNC610O.DLL
2010-04-09 13:23:53 ----A---- C:\WINDOWS\system32\CNC610L.DLL
2010-04-09 13:23:53 ----A---- C:\WINDOWS\system32\CNC610I.DLL
2010-04-09 13:23:53 ----A---- C:\WINDOWS\system32\CNC610C.DLL
2010-04-09 13:23:48 ----HD---- C:\Program Files\CanonBJ
2010-04-08 16:14:28 ----D---- C:\Program Files\AOR
2010-04-08 08:52:15 ----A---- C:\WINDOWS\system32\enres16.dll
2010-04-08 08:50:36 ----RA---- C:\WINDOWS\system32\mixres32.dll
2010-04-08 08:50:36 ----RA---- C:\WINDOWS\system32\audpci40.dll
2010-04-08 08:50:35 ----RA---- C:\WINDOWS\system32\ensres32.dll
2010-04-08 08:50:35 ----RA---- C:\WINDOWS\system32\ensmix32.exe
2010-04-08 08:50:28 ----A---- C:\WINDOWS\uninst.exe
2010-04-01 13:28:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-01 10:36:27 ----A---- C:\WINDOWS\system32\ZipDLL.dll
2010-04-01 10:36:27 ----A---- C:\WINDOWS\system32\UNZDLL.dll
2010-04-01 10:36:27 ----A---- C:\WINDOWS\system32\ASUSW32N50.dll
2010-04-01 10:36:27 ----A---- C:\WINDOWS\system32\ASIW32N50.dll
2010-04-01 10:36:22 ----D---- C:\Program Files\ASUS

======List of files/folders modified in the last 1 months======

2010-06-16 02:49:16 ----A---- C:\WINDOWS\system32\MKCoInstaller.dll
2010-04-29 09:26:46 ----RD---- C:\Program Files
2010-04-29 09:22:28 ----D---- C:\WINDOWS\Minidump
2010-04-29 09:22:27 ----D---- C:\WINDOWS\temp
2010-04-29 09:22:27 ----D---- C:\WINDOWS\Prefetch
2010-04-29 09:21:32 ----D---- C:\WINDOWS\system32\Restore
2010-04-29 09:21:30 ----D---- C:\WINDOWS
2010-04-29 09:21:22 ----D---- C:\WINDOWS\system32
2010-04-29 09:21:22 ----D---- C:\Program Files\Common Files
2010-04-29 09:21:11 ----A---- C:\WINDOWS\wincmd.ini
2010-04-29 09:19:21 ----D---- C:\Documents and Settings\MajklB\Data aplikací\Skype
2010-04-28 16:44:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-28 08:41:51 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-27 16:59:10 ----A---- C:\WINDOWS\system.ini
2010-04-27 16:58:38 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-04-27 16:57:35 ----D---- C:\WINDOWS\system32\drivers
2010-04-27 16:57:35 ----D---- C:\WINDOWS\AppPatch
2010-04-27 16:52:39 ----SHD---- C:\System Volume Information
2010-04-27 12:26:04 ----SHD---- C:\WINDOWS\Installer
2010-04-27 12:26:04 ----D---- C:\Config.Msi
2010-04-27 12:25:52 ----SD---- C:\Documents and Settings\MajklB\Data aplikací\Microsoft
2010-04-26 14:28:30 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-21 14:29:36 ----RSD---- C:\WINDOWS\assembly
2010-04-21 14:28:56 ----D---- C:\Program Files\Microsoft.NET
2010-04-21 14:27:43 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-04-21 14:24:26 ----D---- C:\WINDOWS\Registration
2010-04-21 14:22:39 ----A---- C:\WINDOWS\ODBC.INI
2010-04-21 13:21:46 ----HD---- C:\WINDOWS\inf
2010-04-21 13:21:35 ----D---- C:\WINDOWS\twain_32
2010-04-21 11:39:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-21 11:33:56 ----D---- C:\WINDOWS\Microsoft.NET
2010-04-21 11:28:45 ----D---- C:\WINDOWS\system32\config
2010-04-21 09:37:31 ----D---- C:\Documents and Settings
2010-04-21 09:15:14 ----A---- C:\WINDOWS\win.ini
2010-04-21 09:15:04 ----RSD---- C:\WINDOWS\Fonts
2010-04-20 10:56:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-15 08:17:02 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-15 08:16:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 08:16:51 ----A---- C:\WINDOWS\imsins.BAK
2010-04-15 08:12:20 ----D---- C:\WINDOWS\ie8updates
2010-04-14 14:13:43 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-04-12 14:11:49 ----D---- C:\WINDOWS\Help
2010-04-12 09:43:47 ----D---- C:\Program Files\NVIDIA Corporation
2010-04-12 09:41:33 ----D---- C:\WINDOWS\system32\DirectX
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-02 10:33:54 ----D---- C:\Program Files\Mozilla Firefox
2010-03-31 09:04:19 ----D---- C:\Program Files\Internet Explorer
2010-03-31 08:13:14 ----SD---- C:\WINDOWS\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-09-11 55768]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2005-04-21 10624]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R2 MLPTDR_Q;MLPTDR_Q; \??\C:\WINDOWS\system32\MLPTDR_Q.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2005-04-21 27520]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-03-16 10232352]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2008-04-07 105088]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
S3 avujenkk;avujenkk; C:\WINDOWS\system32\drivers\avujenkk.sys []
S3 Axtmvflt;Axesstel USB Filter Service; C:\WINDOWS\system32\DRIVERS\Axtmvflt.sys [2007-06-27 3456]
S3 Axtmvmdm;Axesstel USB Modem; C:\WINDOWS\system32\DRIVERS\Axtmvmdm.sys [2007-06-27 40064]
S3 Axtmvprt;Axesstel Diagnostic Port; C:\WINDOWS\System32\Drivers\Axtmvprt.sys [2007-06-27 38784]
S3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2004-10-15 15295]
S3 EST_BusEnum;Network USB Device Bus; C:\WINDOWS\system32\DRIVERS\GenBus.sys []
S3 GT680x;BearPaw 2448CS Plus Usb Scanner; C:\WINDOWS\System32\Drivers\Gt680x.sys []
S3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys []
S3 teamviewervpn;TeamViewer VPN Adapter; C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 wlmel51b;BUFFALO WLI-USB-L11 Driver; C:\WINDOWS\system32\DRIVERS\wlmel51b.sys [2002-11-14 179712]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-12 57344]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-15 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-03-16 154216]
R2 pgsql-8.2;PostgreSQL Database Server 8.2; C:\Program Files\Vivotek Inc\ST7501\pgsql\bin\pg_ctl.exe [2007-09-17 79948]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ST7501 Uranus Watch Dog;ST7501 Uranus Watch Dog; C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_UranusWatchDog.exe [2009-03-25 376192]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-09-11 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13493
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#2 Příspěvek od Caroprd111 »

Zdravím :)


Obrázek Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#3 Příspěvek od Miguelow »

dekuji za odpoved, logy se mi sem nevesli, posilam v priloze.
Přílohy
OTL.ZIP
(22.93 KiB) Staženo 72 x

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13493
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#4 Příspěvek od Caroprd111 »

Rozdělte prosím logy do více příspěvků.
Obrázek

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#5 Příspěvek od Miguelow »

zde OTL.TXT:

OTL logfile created on: 29.4.2010 15:25:20 - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\MajklB\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 022,00 Mb Total Physical Memory | 257,00 Mb Available Physical Memory | 25,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 60,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 2,22 Gb Free Space | 7,57% Space Free | Partition Type: NTFS
Drive D: | 82,49 Gb Total Space | 13,29 Gb Free Space | 16,11% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 3,75 Gb Total Space | 2,79 Gb Free Space | 74,39% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: ABTEST-PC2
Current User Name: MajklB
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.04.27 21:03:54 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MajklB\Plocha\OTL.exe
PRC - [2010.04.02 10:33:42 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.18 13:25:10 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009.09.11 07:24:32 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009.09.11 07:23:46 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009.03.25 14:46:48 | 000,999,296 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_BackupServer.exe
PRC - [2009.03.25 14:46:46 | 000,739,200 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_ConfigurationServer.exe
PRC - [2009.03.25 14:46:46 | 000,532,352 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_WebServer.exe
PRC - [2009.03.25 14:46:44 | 000,758,144 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_QueryServer.exe
PRC - [2009.03.25 14:46:44 | 000,588,672 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_EventServer.exe
PRC - [2009.03.25 14:46:42 | 001,172,352 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_RecordingServer.exe
PRC - [2009.03.25 14:46:40 | 000,891,776 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_StreamingServer.exe
PRC - [2009.03.25 14:46:38 | 000,376,192 | ---- | M] () -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_UranusWatchDog.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.12.06 22:03:41 | 000,660,768 | ---- | M] (ABBYY (BIT Software)) -- C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
PRC - [2007.09.17 09:09:52 | 000,079,948 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\Vivotek Inc\ST7501\pgsql\bin\pg_ctl.exe
PRC - [2007.09.17 09:09:32 | 003,602,516 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\Vivotek Inc\ST7501\pgsql\bin\postgres.exe
PRC - [2007.06.06 07:00:00 | 001,074,896 | ---- | M] (C. Ghisler & Co.) -- C:\Program Files\totalcmd\TOTALCMD.EXE
PRC - [2003.04.09 19:21:38 | 000,147,456 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
PRC - [2003.04.09 19:11:12 | 000,028,672 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PRC - [2003.04.09 18:59:24 | 000,311,296 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
PRC - [2003.04.09 18:49:36 | 000,286,720 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
PRC - [2001.12.13 02:01:00 | 000,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brss01a.exe


========== Modules (SafeList) ==========

MOD - [2010.04.27 21:03:54 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MajklB\Plocha\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - [2009.09.11 07:33:18 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.09.11 07:24:32 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009.03.25 14:46:38 | 000,376,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Vivotek Inc\ST7501\Server\ST7501_UranusWatchDog.exe -- (ST7501 Uranus Watch Dog)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2007.12.06 22:03:41 | 000,660,768 | ---- | M] (ABBYY (BIT Software)) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Professional.9.0)
SRV - [2007.09.17 09:09:52 | 000,079,948 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files\Vivotek Inc\ST7501\pgsql\bin\pg_ctl.exe -- (pgsql-8.2)
SRV - [2002.04.12 02:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) [Auto | Stopped] -- C:\WINDOWS\system32\brsvc01a.exe -- (Brother XP spl Service)


========== Driver Services (SafeList) ==========

DRV - [2010.03.16 08:51:59 | 010,232,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010.02.22 15:28:58 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.09.11 07:26:24 | 000,055,768 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2009.09.11 07:26:20 | 000,135,048 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2009.09.11 07:23:50 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.09.11 07:17:16 | 000,116,008 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2009.06.19 09:10:40 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2008.04.14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.07 16:06:48 | 000,105,088 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008.01.25 11:12:34 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2007.06.27 19:31:22 | 000,040,064 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvmdm.sys -- (Axtmvmdm)
DRV - [2007.06.27 19:31:22 | 000,038,784 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvprt.sys -- (Axtmvprt)
DRV - [2007.06.27 19:31:22 | 000,003,456 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvflt.sys -- (Axtmvflt)
DRV - [2007.06.15 11:47:26 | 001,127,936 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\P17.sys -- (P17)
DRV - [2005.04.21 15:21:22 | 000,027,520 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2005.04.21 13:40:36 | 000,010,624 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2005.03.03 19:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.02.23 17:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.01.10 19:15:30 | 000,106,496 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2005.01.10 19:15:24 | 000,138,752 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2004.12.03 12:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2004.10.15 05:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2003.07.22 02:44:18 | 000,018,848 | ---- | M] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\MLPTDR_Q.SYS -- (MLPTDR_Q)
DRV - [2002.11.14 21:17:06 | 000,179,712 | ---- | M] (MELCO) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wlmel51b.sys -- (wlmel51b)
DRV - [2002.09.16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2002.09.09 19:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.seznam.cz"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.02 10:33:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.16 08:44:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009.10.13 14:34:19 | 000,000,000 | ---D | M]

[2009.04.30 09:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Mozilla\Extensions
[2010.04.29 09:07:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Mozilla\Firefox\Profiles\vov0sy5m.default\extensions
[2009.07.02 10:10:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\MajklB\Data aplikací\Mozilla\Firefox\Profiles\vov0sy5m.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.29 09:07:00 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.04.15 15:32:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.15 15:32:30 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.12 10:48:09 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.03.12 10:48:09 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.03.12 10:48:09 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.03.12 10:48:09 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.03.12 10:48:09 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2003.04.16 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download All by ASUS Download - C:\Program Files\ASUS\WL-500gP Wireless Router Utilities\ASDownloadAll.htm ()
O8 - Extra context menu item: Download using ASUS Download - C:\Program Files\ASUS\WL-500gP Wireless Router Utilities\ASDownload.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1FBDF235-C5A9-4F21-BD79-9EC0DCF8AC29} http://192.168.1.175/AVC_AX_DVR.cab (CV781Object Object)
O16 - DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} http://192.168.1.140/activex/decoder/mpeg4_dec.cab (Moonlight MPEG-4 Video Decoder)
O16 - DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} http://192.168.1.108/RtspVaPgDec.cab (RtspVaPgCtrlNew Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://192.168.1.176/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} http://cam.balloonfacility.com/JpegInst.cab (pmjpegcam Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.29 10:04:42 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009.10.29 10:04:43 | 000,000,000 | ---D | M] - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /k:f *) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010.01.18 16:13:15 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\audpci40.dll (Creative Technology Ltd.)
Drivers32: midi4 - C:\WINDOWS\System32\audpci40.dll (Creative Technology Ltd.)
Drivers32: mixer4 - C:\WINDOWS\System32\audpci40.dll (Creative Technology Ltd.)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.mjpg - C:\WINDOWS\System32\mcmjpg32.dll (MainConcept)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\Mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MP43 - C:\WINDOWS\System32\Mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\Mpg4c32.dll (Microsoft Corporation)
Drivers32: wave4 - C:\WINDOWS\System32\audpci40.dll (Creative Technology Ltd.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)

========== Files/Folders - Created Within 30 Days ==========

[2010.04.29 15:24:51 | 000,563,712 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MajklB\Plocha\OTL.exe
[2010.04.29 09:26:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.29 09:26:45 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.27 17:33:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Logs
[2010.04.27 12:26:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Local Settings\Data aplikací\assembly
[2010.04.27 12:25:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Dokumenty\Add-in Express
[2010.04.26 10:59:00 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2010.04.26 10:57:51 | 004,165,768 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\MajklB\Plocha\dfsetup118.exe
[2010.04.23 09:34:47 | 074,287,632 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\MajklB\Plocha\VirtualBox-3.1.6-59338-Win.exe
[2010.04.22 14:57:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\test
[2010.04.21 13:22:39 | 000,000,000 | R--D | C] -- C:\Documents and Settings\MajklB\Data aplikací\Brother
[2010.04.21 13:20:28 | 000,258,048 | ---- | C] (Brother Industries, Ltd) -- C:\WINDOWS\System32\bsplmf01.dll
[2010.04.21 13:20:28 | 000,131,072 | ---- | C] (Brother Industries,ltd) -- C:\WINDOWS\System32\bsplmf01.exe
[2010.04.21 13:20:28 | 000,121,856 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\BrWia05a.dll
[2010.04.21 13:20:28 | 000,057,344 | ---- | C] (brother Industries Ltd) -- C:\WINDOWS\System32\brsvc01a.exe
[2010.04.21 13:20:28 | 000,045,056 | ---- | C] (brother Industries Ltd) -- C:\WINDOWS\System32\brss01a.exe
[2010.04.21 13:20:28 | 000,037,888 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\BrUSi05a.dll
[2010.04.21 13:20:28 | 000,015,295 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\drivers\BrScnUsb.sys
[2010.04.21 13:20:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\yyy
[2010.04.21 13:20:01 | 005,193,726 | ---- | C] (A.I.SOFT,INC.) -- C:\Documents and Settings\MajklB\Plocha\brother dpc-115c.EXE
[2010.04.21 11:27:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2010.04.21 11:27:28 | 000,000,000 | ---D | C] -- C:\Program Files\NUUO
[2010.04.21 11:25:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\CMS_1_3_3_3
[2010.04.21 09:36:49 | 000,000,000 | ---D | C] -- C:\Recording
[2010.04.21 09:36:42 | 000,000,000 | ---D | C] -- C:\Program Files\Vivotek Inc
[2010.04.21 09:17:40 | 000,000,000 | ---D | C] -- C:\BlueIris
[2010.04.21 09:15:03 | 000,000,000 | ---D | C] -- C:\Program Files\Blue Iris
[2010.04.16 13:13:53 | 002,686,232 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\MajklB\Plocha\vcredist_x86.exe
[2010.04.16 08:53:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Data aplikací\MFP and Storage Server
[2010.04.16 08:51:37 | 000,000,000 | ---D | C] -- C:\Program Files\TP-LINK
[2010.04.15 15:32:46 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.04.15 15:32:46 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.04.15 15:32:46 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.04.15 15:32:46 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.04.15 15:32:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.04.15 08:46:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\ROMAN
[2010.04.14 08:32:06 | 000,000,000 | ---D | C] -- C:\log
[2010.04.12 09:41:58 | 000,061,440 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2010.04.12 09:41:56 | 011,640,832 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcompiler.dll
[2010.04.12 09:41:31 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_6.dll
[2010.04.12 09:41:31 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_4.dll
[2010.04.12 09:41:27 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_6.dll
[2010.04.12 09:41:25 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_7.dll
[2010.04.12 09:41:22 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_5.dll
[2010.04.12 09:41:17 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_5.dll
[2010.04.12 09:41:13 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_42.dll
[2010.04.12 09:41:10 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dcsx_42.dll
[2010.04.12 09:41:08 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx11_42.dll
[2010.04.12 09:41:05 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_42.dll
[2010.04.12 09:41:04 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_42.dll
[2010.04.12 09:41:01 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_41.dll
[2010.04.12 09:41:01 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_41.dll
[2010.04.12 09:40:59 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_41.dll
[2010.04.12 09:40:57 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_4.dll
[2010.04.12 09:40:57 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_3.dll
[2010.04.12 09:40:55 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_4.dll
[2010.04.12 09:40:53 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_6.dll
[2010.04.12 09:36:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.04.12 09:36:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Data aplikací\Thinstall
[2010.04.09 13:24:09 | 000,215,040 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMLM93.DLL
[2010.04.09 13:24:06 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2010.04.09 13:23:53 | 001,400,832 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC610C.DLL
[2010.04.09 13:23:53 | 000,200,704 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC610L.DLL
[2010.04.09 13:23:53 | 000,188,416 | ---- | C] (Canon Inc.) -- C:\WINDOWS\System32\CNC610O.DLL
[2010.04.09 13:23:53 | 000,098,304 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC610I.DLL
[2010.04.09 13:23:48 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ
[2010.04.08 16:14:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\Oprava Outlooku
[2010.04.08 16:14:28 | 000,000,000 | ---D | C] -- C:\Program Files\AOR
[2010.04.08 08:52:15 | 000,008,656 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\enres16.dll
[2010.04.08 08:50:36 | 000,280,576 | R--- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\mixres32.dll
[2010.04.08 08:50:36 | 000,050,688 | R--- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\audpci40.dll
[2010.04.08 08:50:35 | 000,229,888 | R--- | C] (ENSONIQ Corp.) -- C:\WINDOWS\System32\ensmix32.exe
[2010.04.08 08:50:35 | 000,010,752 | R--- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\ensres32.dll
[2010.04.08 08:50:32 | 000,274,624 | R--- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\eapci40.sys
[2010.04.08 08:50:28 | 000,299,008 | ---- | C] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe
[2010.04.08 08:50:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\WINDOWS
[2010.04.01 13:28:58 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.01 13:28:55 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.01 13:28:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.01 12:03:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Pavark
[2010.04.01 10:37:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\FW_WL500gP_1977
[2010.04.01 10:36:27 | 000,061,440 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASUSW32N50.dll
[2010.04.01 10:36:27 | 000,061,440 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASIW32N50.dll
[2010.04.01 10:36:27 | 000,016,302 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASINDIS5.sys
[2010.04.01 10:36:27 | 000,016,269 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASNDIS5.sys
[2010.04.01 10:36:22 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS
[2010.04.01 10:35:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MajklB\Plocha\UT_WL500gP_3500
[2002.04.11 10:41:06 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.11.27 01:58:44 | 000,172,032 | ---- | M] () -- C:\WINDOWS\System32\SpotSaver.scr
[2010.11.27 01:48:18 | 000,135,168 | ---- | M] () -- C:\WINDOWS\System32\ParaSaver.scr
[2010.11.27 01:41:08 | 000,176,128 | ---- | M] () -- C:\WINDOWS\System32\PuzzSaver.scr
[2010.06.16 02:49:16 | 000,303,186 | ---- | M] () -- C:\WINDOWS\System32\MKCoInstaller.dll
[2010.04.29 15:17:23 | 000,004,134 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.04.29 08:19:17 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.04.29 08:15:29 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010.04.29 08:15:20 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.29 08:15:17 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-1647877149-725345543-1003.job
[2010.04.29 08:13:01 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.29 08:12:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.28 16:44:53 | 004,718,592 | -H-- | M] () -- C:\Documents and Settings\MajklB\NTUSER.DAT
[2010.04.28 13:27:17 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F754E009-4675-47CB-8136-DE396B710C3F}.job
[2010.04.28 12:05:01 | 000,000,474 | ---- | M] () -- C:\Documents and Settings\MajklB\Plocha\hi.m3u
[2010.04.28 08:13:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-1647877149-725345543-1003.job
[2010.04.27 21:03:54 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MajklB\Plocha\OTL.exe
[2010.04.27 16:59:10 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.27 16:48:21 | 003,920,068 | R--- | M] () -- C:\Documents and Settings\MajklB\Plocha\ComboFix.exe
[2010.04.27 12:32:22 | 000,001,904 | ---- | M] () -- C:\Documents and Settings\MajklB\Data aplikací\dskonektor.config
[2010.04.26 10:59:02 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\MajklB\Plocha\Defraggler.lnk
[2010.04.26 10:58:42 | 004,165,768 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\MajklB\Plocha\dfsetup118.exe
[2010.04.23 15:50:49 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\MajklB\ntuser.ini
[2010.04.23 09:35:23 | 074,287,632 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\MajklB\Plocha\VirtualBox-3.1.6-59338-Win.exe
[2010.04.23 08:35:19 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010.04.21 14:27:27 | 000,435,396 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.21 14:27:27 | 000,432,278 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.04.21 14:27:27 | 000,079,242 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.04.21 14:27:27 | 000,068,292 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.21 14:22:39 | 000,000,487 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010.04.21 13:22:04 | 000,000,419 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2010.04.21 13:22:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\BRPP2KA.INI
[2010.04.21 13:22:03 | 000,000,030 | ---- | M] () -- C:\WINDOWS\System32\brss01a.ini
[2010.04.21 13:22:02 | 000,000,184 | ---- | M] () -- C:\WINDOWS\System32\brsvc01a.bsi
[2010.04.21 13:20:17 | 005,193,726 | ---- | M] (A.I.SOFT,INC.) -- C:\Documents and Settings\MajklB\Plocha\brother dpc-115c.EXE
[2010.04.21 11:39:55 | 001,030,676 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.21 11:34:16 | 000,029,872 | ---- | M] () -- C:\Documents and Settings\MajklB\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.04.21 09:43:13 | 000,143,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.21 09:38:27 | 000,001,933 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Playback.lnk
[2010.04.21 09:38:12 | 000,001,961 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\LiveClient.lnk
[2010.04.21 09:15:14 | 000,000,670 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.04.16 13:13:55 | 002,686,232 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\MajklB\Plocha\vcredist_x86.exe
[2010.04.16 12:48:59 | 002,940,846 | ---- | M] () -- C:\Documents and Settings\MajklB\Plocha\x64.zip
[2010.04.16 08:44:04 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010.04.15 15:32:29 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.04.15 15:32:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.04.15 15:32:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.04.15 15:32:28 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.04.15 15:32:27 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.04.15 08:16:51 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.14 14:13:43 | 000,000,302 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2010.04.12 09:44:38 | 002,113,118 | -H-- | M] () -- C:\Documents and Settings\MajklB\Local Settings\Data aplikací\IconCache.db
[2010.04.12 09:37:38 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.04.08 16:14:31 | 000,000,568 | ---- | M] () -- C:\Documents and Settings\MajklB\Plocha\AOR.lnk
[2010.04.02 12:05:08 | 002,085,153 | ---- | M] () -- C:\Chipset_Intel_8.3.0.1013_Vistax86.zip
[2010.04.01 13:29:01 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.04.01 09:46:50 | 003,665,920 | ---- | M] () -- C:\Documents and Settings\MajklB\Plocha\WL500gp-1.9.2.7-10-USB-1.71.trx
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#6 Příspěvek od Miguelow »

zde OTL.TXT cast2:

========== Files Created - No Company Name ==========

[2010.04.28 12:05:01 | 000,000,474 | ---- | C] () -- C:\Documents and Settings\MajklB\Plocha\hi.m3u
[2010.04.27 16:48:20 | 003,920,068 | R--- | C] () -- C:\Documents and Settings\MajklB\Plocha\ComboFix.exe
[2010.04.27 12:28:16 | 000,001,904 | ---- | C] () -- C:\Documents and Settings\MajklB\Data aplikací\dskonektor.config
[2010.04.26 10:59:02 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\MajklB\Plocha\Defraggler.lnk
[2010.04.21 13:22:04 | 000,000,419 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010.04.21 13:22:04 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2010.04.21 13:22:03 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2010.04.21 13:22:02 | 000,000,184 | ---- | C] () -- C:\WINDOWS\System32\brsvc01a.bsi
[2010.04.21 09:38:27 | 000,001,933 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Playback.lnk
[2010.04.21 09:38:12 | 000,001,961 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\LiveClient.lnk
[2010.04.16 12:48:43 | 002,940,846 | ---- | C] () -- C:\Documents and Settings\MajklB\Plocha\x64.zip
[2010.04.12 09:41:59 | 000,009,046 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2010.04.08 16:14:31 | 000,000,568 | ---- | C] () -- C:\Documents and Settings\MajklB\Plocha\AOR.lnk
[2010.04.08 08:50:33 | 002,259,067 | R--- | C] () -- C:\WINDOWS\System32\2mg4.ecw
[2010.04.08 08:50:31 | 000,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.I~I
[2010.04.02 12:05:08 | 002,085,153 | ---- | C] () -- C:\Chipset_Intel_8.3.0.1013_Vistax86.zip
[2010.04.01 13:29:01 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.04.01 10:36:28 | 000,041,984 | ---- | C] () -- C:\WINDOWS\System32\ZipSFX.bin
[2010.04.01 10:36:27 | 000,163,192 | ---- | C] () -- C:\WINDOWS\System32\ResDlls.res
[2010.04.01 10:36:27 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\ZipDLL.dll
[2010.04.01 10:36:27 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\UNZDLL.dll
[2010.04.01 10:36:27 | 000,015,577 | ---- | C] () -- C:\WINDOWS\System32\ASNDIS3.vxd
[2010.04.01 10:36:27 | 000,015,577 | ---- | C] () -- C:\WINDOWS\System32\ASINDIS3.vxd
[2010.04.01 09:45:34 | 003,665,920 | ---- | C] () -- C:\Documents and Settings\MajklB\Plocha\WL500gp-1.9.2.7-10-USB-1.71.trx
[2010.03.11 16:12:04 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010.03.01 09:48:14 | 000,005,663 | ---- | C] () -- C:\WINDOWS\System32\ludap17.ini
[2010.03.01 09:48:14 | 000,000,075 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2010.02.22 15:28:58 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.01.18 11:42:52 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVSyd.DLL
[2010.01.18 11:42:43 | 000,000,599 | ---- | C] () -- C:\WINDOWS\System32\CNCMP51.INI
[2010.01.08 10:23:57 | 000,000,081 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2010.01.05 16:30:56 | 000,000,332 | ---- | C] () -- C:\WINDOWS\System32\CNCMFP21.INI
[2009.09.17 15:42:53 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009.09.03 14:19:06 | 000,022,723 | R--- | C] () -- C:\WINDOWS\System32\xrxs1l3.dll
[2009.08.03 00:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2009.07.14 17:15:00 | 000,178,432 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009.07.03 14:56:07 | 000,000,302 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2009.06.26 13:48:31 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.06.02 16:24:49 | 000,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2009.05.22 10:12:54 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[2009.05.22 10:12:54 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
[2009.05.22 10:12:50 | 000,303,186 | ---- | C] () -- C:\WINDOWS\System32\MKCoInstaller.dll
[2009.05.22 10:12:50 | 000,000,059 | ---- | C] () -- C:\WINDOWS\System32\KScannerSetting.ini
[2009.05.19 10:32:06 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\hpgt34.dll
[2009.05.18 10:25:47 | 000,000,065 | ---- | C] () -- C:\WINDOWS\FxLoader.INI
[2009.04.30 11:53:15 | 000,000,487 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009.04.29 12:21:21 | 000,004,134 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.05.03 20:38:42 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\P17.dll
[2003.10.02 19:48:18 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2003.07.13 22:53:56 | 000,011,521 | ---- | C] () -- C:\WINDOWS\MSUMLT_Q.INI
[2003.04.16 14:00:00 | 000,000,662 | ---- | C] () -- C:\WINDOWS\System32\syscms32.dll
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003.03.09 22:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll

========== LOP Check ==========

[2010.02.23 10:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2010.01.18 14:32:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.02.22 15:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.06.23 13:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EPSON
[2009.10.13 14:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.10.29 11:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SecTaskMan
[2010.04.12 14:02:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.01.07 10:30:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.06.02 09:24:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\MajklB\Data aplikací\.#
[2010.02.22 15:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Autodesk
[2010.02.22 15:32:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\DAEMON Tools Lite
[2009.04.29 12:49:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ESET
[2010.02.17 09:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ICQ
[2010.04.16 08:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\MFP and Storage Server
[2009.10.09 15:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\NEC Projector User Supportware
[2009.05.26 08:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\TeamViewer
[2010.04.12 09:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Thinstall
[2009.06.02 16:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\TrojanHunter
[2010.04.28 13:27:17 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{F754E009-4675-47CB-8136-DE396B710C3F}.job

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)

< c:\windows\*.* /U >
[3 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2009.06.02 09:24:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\MajklB\Data aplikací\.#
[2010.02.10 14:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ABBYY
[2009.05.21 12:12:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Adobe
[2010.03.18 13:08:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Apple Computer
[2009.05.18 08:44:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ATI
[2010.02.22 15:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Autodesk
[2010.04.21 13:22:39 | 000,000,000 | R--D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Brother
[2010.02.22 15:32:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\DAEMON Tools Lite
[2009.04.29 12:49:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ESET
[2009.10.29 11:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Help
[2009.11.26 12:56:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Hewlett-Packard
[2010.02.17 09:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\ICQ
[2009.04.23 17:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Identities
[2009.05.13 10:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Macromedia
[2009.06.23 13:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Malwarebytes
[2010.04.16 08:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\MFP and Storage Server
[2010.04.27 12:25:52 | 000,000,000 | --SD | M] -- C:\Documents and Settings\MajklB\Data aplikací\Microsoft
[2009.04.30 09:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Mozilla
[2009.10.09 15:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\NEC Projector User Supportware
[2009.06.01 11:29:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Nero
[2010.03.18 13:27:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Real
[2010.04.29 15:22:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Skype
[2010.03.16 09:55:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Sun
[2009.05.26 08:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\TeamViewer
[2010.04.12 09:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\Thinstall
[2009.06.02 16:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\TrojanHunter
[2009.06.02 15:55:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MajklB\Data aplikací\WinRAR

< %APPDATA%\*.exe /s >
[2010.04.12 09:36:09 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\MajklB\Data aplikací\Thinstall\BurnInTest v5.3 Pro\10000002900002i\imapi.exe


< MD5 for: AGP440.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2003.04.16 14:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\ATAPI.SYS
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: CDROM.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\CDROM.SYS
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2003.04.16 14:00:00 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2003.04.16 14:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) MD5=031E7FF41B13B658CAE7D6C98086F76A -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2003.04.16 14:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=E8508E7F865490D8AE71D00C8DF4D227 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2003.04.16 14:00:00 | 001,004,544 | ---- | M] (Microsoft Corporation) MD5=11D80755545CFB5EB9659EE88440EAE2 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\pebuilder3110a\BartPE\I386\EXPLORER.EXE
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe

< MD5 for: HAL.DLL >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2003.04.16 14:00:00 | 000,129,920 | ---- | M] (Microsoft Corporation) MD5=308709E92843DFF3A5CDCA069F6F5C61 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 14:00:00 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2003.04.16 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\isapnp.sys
[2008.04.14 14:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\ISAPNP.SYS
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2003.04.16 14:00:00 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\LSASS.EXE
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\NDIS.SYS
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2003.04.16 14:00:00 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\NETLOGON.DLL
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[2003.04.16 14:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=CF03E300B5CEEFFEFBE6F67532BD0EF1 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 14:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\SCECLI.DLL
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[2003.04.16 14:00:00 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

< MD5 for: SMSS.EXE >
[2003.04.16 14:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\SMSS.EXE
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2003.04.16 14:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=329945887A0C684C38A4845330BC9100 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\SVCHOST.EXE
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2003.04.16 14:00:00 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.04.14 14:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\TCPIP.SYS
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\USERINIT.EXE
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2003.04.16 14:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B26871B5CE92F9D95AE6E62119799EB9 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\WINLOGON.EXE
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
[2003.04.16 14:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe

< MD5 for: WS2_32.DLL >
[2003.04.16 14:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=748494B94A871A828C64D1D5C738D2B7 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 14:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\WS2_32.DLL
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.02.22 15:28:58 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2009.04.23 14:46:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009.04.23 14:46:18 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009.04.23 14:46:18 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2010.06.16 02:49:16 | 000,303,186 | ---- | M] () -- C:\WINDOWS\system32\MKCoInstaller.dll
[2010.04.29 08:15:29 | 000,276,202 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2010.11.27 01:48:18 | 000,135,168 | ---- | M] () -- C:\WINDOWS\system32\ParaSaver.scr
[2010.11.27 01:41:08 | 000,176,128 | ---- | M] () -- C:\WINDOWS\system32\PuzzSaver.scr
[2010.11.27 01:58:44 | 000,172,032 | ---- | M] () -- C:\WINDOWS\system32\SpotSaver.scr
[2010.04.29 08:15:20 | 000,002,422 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:8C35AEA7
< End of report >

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#7 Příspěvek od Miguelow »

Extras.txt:

OTL Extras logfile created on: 29.4.2010 15:25:20 - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\MajklB\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 022,00 Mb Total Physical Memory | 257,00 Mb Available Physical Memory | 25,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 60,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 2,22 Gb Free Space | 7,57% Space Free | Partition Type: NTFS
Drive D: | 82,49 Gb Total Space | 13,29 Gb Free Space | 16,11% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 3,75 Gb Total Space | 2,79 Gb Free Space | 74,39% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: ABTEST-PC2
Current User Name: MajklB
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application -- (TeamViewer GmbH)
"C:\Program Files\totalcmd\TOTALCMD.EXE" = C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP610_series" = Canon MP610 series
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1F701DBD-1660-4108-B10A-FB435EA63BF0}" = PostgreSQL 8.2
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{269DBC9C-CAFC-472d-B1F1-0D327C2FFA76}" = Canon MF3200 Series
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{58F8C6D9-5B55-486A-A322-4E8D87670031}" = Canon MP Drivers
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6767DFEE-8909-453A-B553-C7693912B2EB}" = Canon MF Toolbox 4.9.1.1.mf09
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{71881D40-FA79-4F76-9517-F085E3CF4936}" = ASUS Wireless Router WL-500gP Utilities
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91130405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.2 - Czech
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AD0980E6-433B-4A4E-B436-DA617510DBA0}" = MS Outlook - konektor do datové schránky - Základní verze ZDARMA
"{B45FABE7-D101-4D99-A671-E16DA40AF7F0}" = Microsoft Games for Windows - LIVE
"{B578C85A-A84C-4230-A177-C5B2AF565B8C}" = Microsoft Games for Windows - LIVE Redistributable
"{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}" = Adobe Flash Player 9 ActiveX
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3A13A35-63AC-427a-92E6-960C1D01FABB}" = Poradce pro upgrade na systém Windows 7
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E2B8BC2B-DA7A-423C-9E3E-DC68835099E6}" = Axesstel Manager
"{E6108095-EABE-470A-8AE6-ABFDDA7AB58B}" = MPIO Utility
"{ED97CF1F-196D-405D-B1D2-BB6306FE8D6C}" = ESET Smart Security
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F9000000-0001-0000-0000-074957833700}" = ABBYY FineReader 9.0 Professional Edition
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Outlook Repair v2.5" = Advanced Outlook Repair v2.5
"Avira UnErase Personal" = Avira UnErase Personal
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"Capoeira Fighter 3: Ultimate World Tournament" = Capoeira Fighter 3: Ultimate World Tournament
"CloneCD" = CloneCD
"Defraggler" = Defraggler
"Device Control" = Device Control
"Disk Investigator" = Disk Investigator 1.5
"EAXSet" = Creative EAX Settings
"FlashBoot_is1" = FlashBoot 1.3.0.124
"HD Tune_is1" = HD Tune 2.55
"HijackThis" = HijackThis 2.0.2
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{E2B8BC2B-DA7A-423C-9E3E-DC68835099E6}" = Axesstel Manager
"IrfanView" = IrfanView (remove only)
"KONICA MINOLTA PagePro 1350W" = KONICA MINOLTA PagePro 1350W
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MobilityDotNET" = DH Mobility Modder.NET
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Nero8Lite_is1" = Nero 8 Micro 8.2.8.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PE Builder_is1" = PE Builder 3.1.10a
"Plus500" = Plus500
"ProcessScanner_is1" = Uniblue ProcessScanner
"RealPlayer 12.0" = RealPlayer
"Recuva" = Recuva
"Repair Tool for Outlook Express_is1" = Repair Tool for Outlook Express v.2.0.0
"Security Task Manager" = Security Task Manager 1.7h
"SPEAKER" = Creative Speaker Settings
"ST7501" = VIVOTEK ST7501
"TeamViewer 4" = TeamViewer 4
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"Unlocker" = Unlocker 1.8.7
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21.4.2010 5:29:41 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:29:51 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:01 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:11 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:21 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:31 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:41 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:30:51 | Computer Name = ABTEST-PC2 | Source = CMServer | ID = 1012
Description =

Error - 21.4.2010 5:37:01 | Computer Name = ABTEST-PC2 | Source = MsiInstaller | ID = 11931
Description = Product: MSXML 6.0 Parser -- Error 1931. The Windows Installer service
cannot update the system file C:\WINDOWS\system32\msxml6r.dll because the file
is protected by Windows. You may need to update your operating system for this
program to work correctly. Package version: 6.0.3883.0, OS Protected version: 6.0.3883.0

Error - 29.4.2010 8:42:00 | Computer Name = ABTEST-PC2 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace explorer.exe, verze 6.0.2900.5512, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

[ System Events ]
Error - 27.4.2010 11:33:55 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 30013
Description = Přidělování DHCP bylo automaticky vypnuto u adresy IP 192.168.1.101,
protože
tato adresa nespadá do oboru 192.168.0.0/255.255.255.0, ze kterého jsou přidělovány
adresy klientům DHCP. Chcete-li přidělování DHCP u této adresy IP zapnout, změňte
obor tak, aby tuto adresu IP zahrnoval, nebo změňte adresu IP tak, aby spadala do
oboru.

Error - 28.4.2010 7:32:59 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 31008
Description = Agentu serveru proxy služby DNS se nepodařilo načíst místní seznam
serverů pro překlad adres IP z registru. Uvedený údaj je kód chyby.

Error - 29.4.2010 2:13:44 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 30013
Description = Přidělování DHCP bylo automaticky vypnuto u adresy IP 192.168.1.101,
protože
tato adresa nespadá do oboru 192.168.0.0/255.255.255.0, ze kterého jsou přidělovány
adresy klientům DHCP. Chcete-li přidělování DHCP u této adresy IP zapnout, změňte
obor tak, aby tuto adresu IP zahrnoval, nebo změňte adresu IP tak, aby spadala do
oboru.

Error - 29.4.2010 3:26:56 | Computer Name = ABTEST-PC2 | Source = Service Control Manager | ID = 7016
Description = Služba BrSplService ohlásila neplatný současný stav 0.

Error - 29.4.2010 7:13:03 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 31008
Description = Agentu serveru proxy služby DNS se nepodařilo načíst místní seznam
serverů pro překlad adres IP z registru. Uvedený údaj je kód chyby.

Error - 29.4.2010 8:13:03 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 31008
Description = Agentu serveru proxy služby DNS se nepodařilo načíst místní seznam
serverů pro překlad adres IP z registru. Uvedený údaj je kód chyby.

Error - 29.4.2010 8:32:59 | Computer Name = ABTEST-PC2 | Source = Ntfs | ID = 262199
Description = Struktura systému souborů disku je poškozena a je nepoužitelná. Je
nutné na svazek spustit nástroj chkdsk.

Error - 29.4.2010 8:33:19 | Computer Name = ABTEST-PC2 | Source = Ntfs | ID = 262199
Description = Struktura systému souborů disku je poškozena a je nepoužitelná. Je
nutné na svazek F: spustit nástroj chkdsk.

Error - 29.4.2010 8:41:22 | Computer Name = ABTEST-PC2 | Source = Disk | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\Harddisk1\D.

Error - 29.4.2010 9:13:16 | Computer Name = ABTEST-PC2 | Source = ipnathlp | ID = 31008
Description = Agentu serveru proxy služby DNS se nepodařilo načíst místní seznam
serverů pro překlad adres IP z registru. Uvedený údaj je kód chyby.


< End of report >

iwigirl
VIP
VIP
Příspěvky: 331
Registrován: 25 dub 2005 18:27
Bydliště: Praha-Bubeneč
Kontaktovat uživatele:

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#8 Příspěvek od iwigirl »

Dobrý den,
naše fórum funguje na bázi dobrovolnosti, rádci zde radí zadarmo a ve svém volném čase.
Z kapacitních a ani etických důvodů nesuplujeme práci bezpečnostních techniků ani lidí, kteří za tuto činnost jsou placeni. Během dnešního dne jste sem vložil minimálně 5 logů z různých počítačů, majících navíc nainstalovaný firemní software - z tohoto důvodu Vás nepovažujeme za domácího uživatele.

Ráda bych Vás tedy jménem teamu požádala, abyste zde již v budoucnu žádné problémy s počítači svých klientů/zaměstnanců apod. nevkládal.

S pozdravem

iwigirl
site admin
:arrow: Chcete se stát vzorným návštěvníkem? Podrobnosti naleznete ZDE.
:arrow: VIRY řešte zde na fóru, pokud máte technický dotaz či dotaz související s chodem fóra, pište na iwi(zavináč)forum.viry.cz
:arrow: pomohla Vám moje rada? podpořte fórum smskou, přes SuperCash nebo nově přes PayPal :)
__________________________________________

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#9 Příspěvek od Miguelow »

resim nasi zavirovanou kancelar, bohuzel pocitacu mame dohromady 8, takze nevim jak odvirovat vsechny soucasne..

netusil jsem ze ma forum tyto pravidla, omlouvam se ze jsem si to nezjistil, prosim vsak o pomoc..

iwigirl
VIP
VIP
Příspěvky: 331
Registrován: 25 dub 2005 18:27
Bydliště: Praha-Bubeneč
Kontaktovat uživatele:

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#10 Příspěvek od iwigirl »

To mě mrzí. Bohužel skutečně není v našich silách řešit zde 8 logů od jednoho člověka. Doporučuji nechat si počítače odvirovat placeným odborníkem, náklady na něj lze dát do nákladů. Je mi líto, že nemohu poskytnout příznivější zprávy...
:arrow: Chcete se stát vzorným návštěvníkem? Podrobnosti naleznete ZDE.
:arrow: VIRY řešte zde na fóru, pokud máte technický dotaz či dotaz související s chodem fóra, pište na iwi(zavináč)forum.viry.cz
:arrow: pomohla Vám moje rada? podpořte fórum smskou, přes SuperCash nebo nově přes PayPal :)
__________________________________________

Miguelow
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 27 dub 2010 15:40

Re: Velke mnozstvi odeslane posty - prosim o kontrolu logu P

#11 Příspěvek od Miguelow »

Chapu, taky me to mrzi, hlavne me mrzi, ze jsme pocitace nechali pred mesicem odvirovat a situace se opakuje a nikdo neni schopny mi rict proc..

Odpovědět