Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Neskutečně zasekané a spomalené PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#16 Příspěvek od WiZARD_ »

Vyskočila chyba:

!! VAROVÁNÍ !! Není bezpečné dále pokračovat!

Obsah a součásti Combofixu byly narušeny.

Stáhněte si prosím novou kopii z:

http://www.bleepingcomputer.com/combofi ... e-combofix

Poznámka: Můžete být infikováni parazitickým souborovým virem (typicky: Virut)

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#17 Příspěvek od WiZARD_ »

Stánul jsem novou kopii a vyskočila opět stejná chyba.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#18 Příspěvek od chodnik74 »

Použijte před Combofixem...


:arrow: Stáhněte Rkill z jednoho odkazu,kdyby nešel spustit první,tak zkuste další(havěť někdy blokuje spuštění určitých typů souborů)

Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe

Rkill COM:
http://download.bleepingcomputer.com/grinler/rkill.com

Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr

Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif

Nyní nerestartujte PC!


Pokud nezabere,tak....

:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 2 a enter
  • Objeví se vám log a ten sem vložte
  • Stějně tak opakujte s volbou 3 a 4 a vložte logy
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#19 Příspěvek od WiZARD_ »

První program nepomohl, opět vyskočila ta samá chyba.
Druhý program, při spuštění napíše chybu:
Vstupní bod procedury EncodePointer se nepodařilo v dynamicky propojované knihovně KERNEL32.dll nalézt.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#20 Příspěvek od chodnik74 »

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#21 Příspěvek od WiZARD_ »

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 7696

Windows 5.1.2600 Service Pack 1 (Safe Mode)
Internet Explorer 6.0.2800.1106

11.9.2011 22:34:13
mbam-log-2011-09-11 (22-34-02).txt

Typ kontroly: Úplný test (A:\|C:\|D:\|G:\|H:\|)
Testované objekty: 384964
Uplynulý čas: 42 minut, 34 sekund

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 127
Infikované hodnoty v registru: 20
Infikované datové položky v registru: 4
Infikované složky: 0
Infikované soubory: 27

Infikované procesy v paměti:
c:\WINDOWS\system32\svchots.exe (CrypTool.Agent) -> 2012 -> No action taken.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Administrattor (CrypTool.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc (Malware.Packer.u64) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Hosts Controller (Virus.Virut) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0026A548-2A19-E8A0-B03E-B8692A75086E} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{007196C5-0DD4-0764-F61E-200F74EEE57C} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00A77F45-682B-8DE9-9E19-E2C9F51D8388} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{03F7EF8A-104D-1443-9F1B-069899745744} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{06F57557-AB6C-8A55-4922-73547511B8D2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0737E842-2BBE-EE74-78D8-D848BDF721C1} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0A82E0CD-C707-C66F-56D8-BFEEEC72B3FF} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{101E4C4F-A301-AD71-148E-584F7618A0AC} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{18A58AED-3730-309F-8879-665F0274DEA3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1BB5D22A-38E3-3CDD-6FC2-017E4B687843} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1C64F2C7-C016-2C06-7A72-AED0431EDCD1} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1FCB9023-A1D4-188C-5AE1-F34B8E87832B} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{20D10BF1-3113-E7B7-0A47-A5B469034DB2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{26A2097D-FE7E-31E3-EB0D-B476CC974DA8} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2B74AF48-6A85-7222-6651-EBBAE148C5B3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2BBBB93E-C8E8-C1EE-093F-EA211A62B27B} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2C7A5774-0575-3C1C-1789-B8C3E1CD9DDE} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2EF89262-692C-51D0-CD84-C415D73F84EB} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{308E81ED-7218-8209-0B65-409E8A527503} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3246BB5C-F56C-50CE-9DC1-4568A444BF1F} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{35400ED6-5CB6-5FB6-F0B9-AF184FD63763} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3676C97E-85F8-4FE1-4FF3-5761EBCB649D} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{37FA2744-03C3-5EAA-90C6-D685E5878DB2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3C0749DE-9D0D-1B9A-52E6-2C347FDD15A9} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4014C362-2DA7-40F3-1C21-53E8844CD087} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{494FEB7F-6626-1241-41D8-59E22DB24FC2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{49BC4B7D-A77B-DCF4-C29B-8F5040D7C9A5} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4A167404-9A8F-6684-EF47-19FB5BD943EF} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4AA4DEB6-F141-B724-8BCF-4995A82419F6} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4C80FDD5-398A-C978-C78B-16A1293DD4DE} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4D9B3AD6-F9C1-0739-3A6E-3D55D45A69E3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4F2D630B-CD4C-1206-EDF4-4ED3900B1398} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5064A943-EF53-7ACA-9C6F-789E5941E345} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{52287B95-3257-CCF7-3B86-B73978B045A2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{54E27EDA-9B99-0E27-7246-DB3CDD577165} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5506853D-22AD-1BB8-2845-212325E942A5} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{555B79E9-DA80-976E-4918-FE9C20D88A6F} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{575E02AB-D638-2559-43AB-60DF97B0D256} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5820F447-EF2B-74E0-E561-3A3CA71075CB} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5B228E8B-E361-D45F-80A9-90E145C6C2D7} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5BE00A73-5A3E-77A2-C459-9289E7FFBB15} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5DF14F9D-6ED4-DA4A-49A4-40F085A9BB86} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{60F07540-55BC-AC34-166A-67B6FA4DD197} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{62E182EE-072E-85DF-552C-319B98B64E6C} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6756A72C-5FD9-3E32-6951-6704AEF8DD60} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6B4FB954-58B2-E021-8CE4-02B6166FF436} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6C3EC276-E5AB-B2F5-9FF2-DC2EA9780271} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6CC6DDD2-220B-8F89-077A-058CE7A629E7} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6EAF3580-B150-6D5F-D7BB-CC0EC951A6CF} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{717B6B22-F136-7AEB-2A9C-C75BEAAEAF04} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{71AD80F1-0996-B6AC-8140-3E7EE8B8E5DD} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{75175DF7-EF56-52A0-8766-55465E7173E2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{78138571-F4A5-1948-2DF6-7E7EB47A2658} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{796977ED-D431-7FF4-F3CB-2ABEBC687630} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7A353246-74DA-B2BB-F2FB-06498428684C} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7D708FBB-FDAD-D4ED-7B5A-FE8D0FFA7493} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{80314ACA-04E4-B2F8-6BB3-7D4A764F3C5F} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{82FC74DE-CCA4-17F1-FA1E-760DC404A317} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{83166DE3-A295-61FA-C73A-BD2EBDD68168} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{83EA0F26-E3A8-F644-2E66-1BEC818FD94B} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{83F033B6-3E4F-B858-069E-1DEA757A732D} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{84485E16-B0EE-B618-6D56-157A7AFC754C} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8B6B6AF7-467C-32F0-1C1F-CF0AB649D65E} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8BF6F24D-2C3C-D83A-E9AE-EC1C4F01DAEE} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8CE16525-B646-EEE9-9681-39D46032B080} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8FBE6833-4B81-D3D0-BD98-7B192C046CC5} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{917C9DB7-A28B-CB00-ADAF-6908C65B70AD} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{91FB423F-5099-7870-A17C-A31006B70863} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{920D60B8-BB03-71F7-3EDF-E3410301F4E0} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9238D60C-A78B-0639-7E0D-921AA5100090} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{924E3D0D-2679-EF9B-71B4-113A38F4B786} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{92C756DF-E46F-0CE9-9FC2-B05BCAC48D54} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9615EF71-014F-8973-B235-6BB870093E0E} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{96186C85-0E8A-D7D6-B8CE-58925A368A34} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9639A854-6A08-A929-EA74-6658559553E1} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{96B5C05D-0A64-92D1-38DC-46A95C6A77B6} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{99E96E31-813C-416A-B501-37DCD14C1253} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9C8C2A58-0FAD-AF7C-CDB7-4CDC59E8E5A3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9E929E0C-FD56-322E-BE5E-49024FC954A7} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9EEBBEDB-D9B2-5CEA-1B37-C835EE0CA7F2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A1C155BC-81B7-7E44-B517-235D34BD11E6} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A1EB21B0-93CB-6A56-C7F3-D8BAC1C6D9E4} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A2F6940D-2E6A-C73B-077D-01A6FDD1A521} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A444DA5E-8020-74A6-F83A-E1D4431F9C12} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A56129F2-22A9-26DE-9D0F-9FFE9585F22B} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A783A33D-30B6-C96D-115C-30BFA0B79CBC} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ADDF57D7-6C02-B77D-9604-A850006B4601} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{AFA58B0D-4C3D-E90B-CF64-00CE780BA5BA} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{B2C11550-352D-2588-2B00-55B92A5AE1A2} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{B467C6CB-1F46-9988-CCDE-83FD25DE8439} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C039A8AE-771A-2609-ABE9-6FF57A8E39B3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C1C97595-B998-B9A8-EEBA-A15A7B78460F} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C4C08C4B-AD9B-37B1-8F3F-AD38323512C3} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C57C74A9-ABB0-E9F3-8C85-DDD33CAD0CC8} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{CA776317-17BB-7877-01FA-D15CFEE0C200} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{CC64B45D-D6FC-76B2-D06F-CEF1AD314B4D} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D6189896-AD1C-E3B2-AFE6-4B692E91B20F} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D72366D6-CA69-61DD-540C-ACA7B20FA09A} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D8583457-F929-F1B1-F466-B04B4DE7B055} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{DEDA84E9-967E-0E2E-ADE2-FDBFBD314AAB} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{E3FB3D9B-A958-33C1-23B9-C8414EC3D98D} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{E81E3309-BDD5-BC2F-852A-715DB42797F9} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{E995A142-7914-3FE8-D60B-AD05B1EE5EFC} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{EA871865-08D6-D09D-46FD-1F353EB479FC} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{EB14F04F-488B-81F4-9203-A1A7C1EAE661} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{EFFB84CB-2818-00BA-CEF5-914848B920AE} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F059511F-ED8F-4E6D-1CA0-71D619AFB174} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F148A717-4004-F18A-39BF-324236EA4566} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F47CF54F-845E-6CA5-3C6B-EE10C17D4AD5} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F59B9001-7B62-FC18-C39A-959985D05ED7} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F699592F-1B83-75DA-AFEF-3F2E360FBE28} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F78FD0B0-9278-DAC5-18A8-ABCD9B80B615} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F83557ED-5FD1-739A-99EC-11BA129BF0CE} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{F9C5784C-C3B6-DD55-1C3F-F4AE48481FE8} (Worm.Allaple) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{6D3F5DE4-E980-4407-A10F-9AC771ABAAE6} (Adware.ISTBar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7B9A715E-9D87-4C21-BF9E-F914F2FA953F} (Adware.ISTBar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D6F180CB-E683-41a3-8CD2-C53DBAA0530D} (Adware.ISTBar) -> No action taken.
HKEY_CLASSES_ROOT\Pugi.PugiObj.1 (Adware.ISTBar) -> No action taken.
HKEY_CLASSES_ROOT\Pugi.PugiObj (Adware.ISTBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rightdown SoftwareRightdown Software SearchBar (Adware.ISTBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dbgmgr (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_HOSTS_CONTROLLER (Worm.Kolab) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVC (Trojan.Agent) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows updatess (CrypTool.Agent) -> Value: windows updatess -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\windows updatess (CrypTool.Agent) -> Value: windows updatess -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows updatess (CrypTool.Agent) -> Value: windows updatess -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows updatess (CrypTool.Agent) -> Value: windows updatess -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\windows updatess (CrypTool.Agent) -> Value: windows updatess -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows System Update Tools (Virus.Virut) -> Value: Windows System Update Tools -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Windows System Update Tools (Virus.Virut) -> Value: Windows System Update Tools -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Updates (Malware.Packer.Gen) -> Value: Windows Updates -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Updates (Malware.Packer.Gen) -> Value: Windows Updates -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D6F180CB-E683-41A3-8CD2-C53DBAA0530D} (Adware.ISTBar) -> Value: {D6F180CB-E683-41A3-8CD2-C53DBAA0530D} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Internet Connection Wizard Setup Tool (Trojan.Downloader) -> Value: Internet Connection Wizard Setup Tool -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft System Service (Backdoor.Bot) -> Value: Microsoft System Service -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Microsoft System Service (Backdoor.Bot) -> Value: Microsoft System Service -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\intime (Malware.Trace) -> Value: intime -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\reup (Malware.Trace) -> Value: reup -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WaitToKillServiceT (Malware.Trace) -> Value: WaitToKillServiceT -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\unwise_.exe (Trojan.Agent) -> Value: unwise_.exe -> No action taken.

Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\System32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\WINDOWS\system32\svchots.exe (CrypTool.Agent) -> No action taken.
c:\WINDOWS\system32\upds.exe (Virus.Virut) -> No action taken.
c:\WINDOWS\system32\bqpldgv.exe (Malware.Packer.Gen) -> No action taken.
c:\WINDOWS\system32\csrsc.exe (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\Fonts\unwise_.exe (Virus.Virut) -> No action taken.
c:\program files\rightdown software searchbar\rssb.dll (Adware.ISTBar) -> No action taken.
c:\Setupz.exe (Malware.Packer.Gen) -> No action taken.
c:\documents and settings\localservice\local settings\temporary internet files\Content.IE5\1JB3BSUL\aa4[1].exe (Malware.Packer.Gen) -> No action taken.
c:\documents and settings\Viti\local settings\Temp\regincd2.exe (Spyware.OnLineGames) -> No action taken.
c:\program files\image-line\Shared\DSP_IPP\uninstall.exe (Rootkit.Agent) -> No action taken.
c:\program files\trend micro\hijackthis.exe (PWS.Fignotok) -> No action taken.
c:\program files\trend micro\Viti.exe (PWS.Fignotok) -> No action taken.
c:\WINDOWS\system32\77463279.INS (Riskware.HideWindow) -> No action taken.
c:\WINDOWS\system32\82562790.INS (Riskware.HideWindow) -> No action taken.
c:\WINDOWS\system32\91723679.INS (Riskware.HideWindow) -> No action taken.
c:\WINDOWS\system32\asr_61185.exe (Virus.Virut) -> No action taken.
c:\WINDOWS\system32\host.exe (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\system32\reotspnwy.dll (Riskware.HideWindow) -> No action taken.
c:\WINDOWS\system32\Rwasred.exe (Malware.Packer.Gen) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\B0OOEQ17\x[1] (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\HV4N3A4C\ypqbgpuj[1].bmp (Extension.Mismatch) -> No action taken.
h:\RECYCLER\s-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx (Worm.Conficker) -> No action taken.
c:\documents and settings\Viti\data aplikací\wiaserva.log (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\crt.dat (Malware.Trace) -> No action taken.
c:\program files\common files\System\ado\tsektjkj.exe (Worm.Allaple) -> No action taken.
c:\WINDOWS\system32\hzuxsbi.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\system32\globalpatch.exe (Backdoor.Bot) -> No action taken.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#22 Příspěvek od chodnik74 »

Ou ou :D

Všechny nalezené položky dejte mazat a pokračujte Combofixem :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#23 Příspěvek od WiZARD_ »

Vše jsem udělal, jen mi ten program Malwarebytes napsal, že nějaké soubory nelze odstranit!
Poté opět během Combofixu vyskočila chyba:

!! VAROVÁNÍ !! Není bezpečné dále pokračovat!

Obsah a součásti Combofixu byly narušeny.

Stáhněte si prosím novou kopii z:

http://www.bleepingcomputer.com/combofi ... e-combofix

Poznámka: Můžete být infikováni parazitickým souborovým virem (typicky: Virut)

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#24 Příspěvek od chodnik74 »

Udělejte sken s programem AVPtool a výsledný log dejte sem :)

viewtopic.php?f=29&t=58179
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#25 Příspěvek od WiZARD_ »

Já už se z toho fakt asi zblázním...

Aplikace nemohla bý spuštěna, protože součást FLTLIB.DLL nelze najít. Potíže pravděpodobně odstraníte opětovnou instalací aplikace.

Zkoušel jsem to několikrát a prostě to nejde ani naistalovat... co s tím :roll:

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#26 Příspěvek od chodnik74 »

:arrow: Stáhneme si na Plochu program OTLObrázek
  • Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Pokud používáte 64 bitový systém,zaškrkněte volbu Pro 64 bitové OS,pokud ne,tak by měla být nezaškrknutá
  • Zaškrkněte okýnko Pro všechny uživatele,Kontrola havět "LOP",Kontrola havět "Purity"
  • Staří souborů změňte z 30 dnů na 7 dnů
  • Do spodního okýnka Vlastní skenování/opravy vložte následující script:

    Kód: Vybrat vše

    safebootminimal 
    safebootnetwork
    drivers32
    savembr:0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    /md5start
    scecli.dll
    autochk.exe
    csrss.exe
    explorer.exe
    lsass.exe
    services.exe
    smss.exe
    spoolsv.exe
    svchost.exe
    userinit.exe
    winlogon.exe
    atapi.sys
    cdrom.sys 
    ndis.sys
    ntfs.sys
    tcpip.sys
    %SystemDrive%\PhysicalMBR.bin
    /md5stop
    C:\windows\system32\spool\prtprocs|dll;true;true;true /FP
    %systemroot%\system32\drivers\*.sys /5
    %systemroot%\system32\drivers\*.sys /X 
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.* /5
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\config\*.sav 
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\*.* /U /s
    %systemroot%\*. /mp /s
    %ALLUSERSPROFILE%\Data Aplikací\*.*
    %ALLUSERSPROFILE%\Data Aplikací\*.exe /s
    %ALLUSERSPROFILE%\Dáta aplikácií\*.*
    %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s
    %APPDATA%\*.
    *crack* /s
    *keygen* /s
    %APPDATA%\*.*
    %APPDATA%\*.exe /s
    %SYSTEMDRIVE%\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces
    sTime /rs
    reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c
    type c:\boot.ini >> test.txt /c
    
  • Klikněte na tlačítko Prohledat
  • Po dokončení skenu,který trvá mezi 5-15 minuty se vám zobrazý dva logy OTL.txt a Extras.txt a ty mě sem vložte
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#27 Příspěvek od WiZARD_ »

OTL logfile created on: 17.9.2011 20:16:52 - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Documents and Settings\Administrator\Plocha
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,48 Mb Total Physical Memory | 303,61 Mb Available Physical Memory | 59,36% Memory free
1,22 Gb Paging File | 1,09 Gb Available in Paging File | 89,24% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 0,70 Gb Free Space | 1,88% Space Free | Partition Type: NTFS
Drive H: | 596,02 Gb Total Space | 317,24 Gb Free Space | 53,23% Space Free | Partition Type: FAT32

Computer Name: UNGIS-KFHKNNXQI | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2011.09.17 20:15:06 | 000,589,312 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Plocha\OTL.exe
PRC - [2011.09.10 23:47:28 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011.09.10 23:47:25 | 001,846,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2006.10.22 06:22:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2006.10.22 06:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2004.12.27 13:46:04 | 000,311,296 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2004.12.26 21:34:38 | 000,121,344 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (xmlprov)
SRV - File not found [Disabled | Stopped] -- -- (wscsvc)
SRV - File not found [Auto | Stopped] -- -- (PEVSystemStart)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011.09.17 17:47:32 | 000,057,871 | R--- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\smsc.exe -- (PrtSmanm)
SRV - [2011.09.17 17:40:17 | 000,035,840 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\csrsc.exe -- (WinSpoolSvc)
SRV - [2011.09.17 17:40:12 | 000,155,648 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system\VMwareService.exe -- (VMwareService)
SRV - [2011.09.17 09:17:23 | 000,150,528 | ---- | M] (OldMan's Tales) [Auto | Stopped] -- C:\WINDOWS\System32\svchots.exe -- (System Administrattor)
SRV - [2011.09.07 00:40:36 | 001,015,808 | -HS- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\irdvxc.exe -- (MSDisk)
SRV - [2010.09.06 19:56:38 | 000,247,096 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () [Auto | Stopped] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.03.23 16:52:12 | 000,056,552 | ---- | M] (Eng. Usama El-Mokadem) [Auto | Stopped] -- C:\WINDOWS\System32\Startsrv.exe -- (SRVStarter_Service)
SRV - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Stopped] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.05.10 11:59:04 | 000,353,912 | ---- | M] (Protection Technology (StarForce)) [Auto | Stopped] -- C:\WINDOWS\System32\sfrem01.exe -- (sfrem01) SF FrontLine Drivers Auto Removal (v1)
SRV - [2005.11.17 16:18:52 | 001,536,092 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2002.12.17 18:26:22 | 007,528,529 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,320,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)


========== Driver Services (SafeList) ==========

DRV - [2009.11.12 14:48:58 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\StarOpen.sys -- (StarOpen)
DRV - [2009.08.04 13:09:42 | 000,018,560 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ymidusb.sys -- (YMIDUSB)
DRV - [2009.01.27 09:12:47 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.04.17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\regi.sys -- (regi)
DRV - [2007.03.15 22:07:14 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007.01.12 20:09:53 | 000,082,296 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2006.07.10 18:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2006.05.10 10:39:38 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.04.05 21:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.05 21:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.01.11 17:05:30 | 000,092,672 | ---- | M] (ALCATech) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL)
DRV - [2004.04.01 17:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002.11.18 17:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.08.29 02:32:44 | 000,009,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2002.06.20 19:45:44 | 000,013,920 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2002.06.20 19:45:42 | 000,020,128 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002.06.20 19:45:40 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2002.06.20 19:45:36 | 000,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2002.06.20 19:45:34 | 000,039,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2001.08.17 22:12:42 | 000,023,070 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [1997.12.23 02:00:00 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2052111302-507921405-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.06.20 12:40:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.09.10 23:47:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.08 11:23:55 | 000,000,000 | ---D | M]

[2011.09.11 21:18:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions
[2011.05.07 18:07:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009.09.25 18:16:45 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.07.23 16:27:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2008.12.22 11:45:47 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.09.10 23:47:29 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.05.08 11:23:40 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.05.08 11:23:40 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.07.05 21:02:00 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.05.08 11:23:40 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.05.08 11:23:40 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.05.08 11:23:40 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.09.17 20:13:47 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Viti\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll File not found
O3 - HKLM\..\Toolbar: (&Rádio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O4 - HKLM..\Run: [365dni] File not found
O4 - HKLM..\Run: [365dní] File not found
O4 - HKLM..\Run: [Microsoft System Service] C:\WINDOWS\System32\globalpatch.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
O4 - HKLM..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKLM..\Run: [WMC_AutoUpdate] File not found
O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
O4 - HKU\.DEFAULT..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
O4 - HKU\S-1-5-18..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKLM..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - HKLM..\RunServices: [Microsoft System Service] C:\WINDOWS\System32\globalpatch.exe ()
O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
O4 - HKLM..\RunServices: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\ICQ6.5.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet32: DllName - (cryptnet32.dll) - File not found
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.12.27 16:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.09.20 18:04:04 | 000,095,034 | RHS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - File not found
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - File not found
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

Drivers32: midi2 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2011.09.17 20:15:05 | 000,589,312 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Plocha\OTL.exe
[2011.09.17 09:17:15 | 000,150,528 | ---- | C] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
[2011.09.11 21:47:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
[2011.09.11 21:47:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.09.11 21:47:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.09.11 21:47:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.09.11 21:47:48 | 000,019,288 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.09.11 21:47:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.09.11 21:21:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory
[2011.09.11 21:18:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Macromedia
[2011.09.11 21:18:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Adobe
[2011.09.11 21:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Mozilla
[2011.09.11 21:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla
[2011.09.11 21:15:45 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Obrázky
[2011.09.11 21:15:45 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Hudba
[2011.09.11 21:15:45 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Filmy
[2011.09.11 21:13:50 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
[2011.09.11 21:13:50 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator\Cookies
[2011.09.11 21:13:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\SendTo
[2011.09.11 21:13:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Data aplikací
[2011.09.11 21:13:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Příslušenství
[2011.09.11 21:13:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
[2011.09.11 21:13:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start
[2011.09.11 21:13:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Šablony
[2011.09.11 21:13:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Recent
[2011.09.11 21:13:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Okolní tiskárny
[2011.09.11 21:13:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Okolní síť
[2011.09.11 21:13:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Local Settings
[2011.09.11 21:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Plocha
[2011.09.11 21:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Oblíbené položky
[2011.09.11 21:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft
[2011.09.11 21:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dokumenty
[2011.09.11 21:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.09.11 21:03:04 | 000,000,000 | ---D | C] -- C:\rsit
[2011.09.11 20:17:14 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2011.09.17 20:17:33 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.09.17 20:17:14 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
[2011.09.17 20:15:06 | 000,589,312 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Plocha\OTL.exe
[2011.09.17 20:13:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.09.17 18:21:20 | 000,000,065 | ---- | M] () -- C:\WINDOWS\System32\o
[2011.09.17 18:07:26 | 000,005,184 | ---- | M] () -- C:\WINDOWS\System32\eras.fon
[2011.09.17 18:03:35 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011.09.17 17:50:24 | 000,219,000 | ---- | M] () -- C:\WINDOWS\System32\x
[2011.09.17 17:47:32 | 000,057,871 | R--- | M] () -- C:\WINDOWS\System32\smsc.exe
[2011.09.17 17:40:17 | 000,035,840 | RHS- | M] () -- C:\WINDOWS\System32\csrsc.exe
[2011.09.17 17:40:17 | 000,035,840 | ---- | M] () -- C:\WINDOWS\System32\x.exe
[2011.09.17 17:40:12 | 000,155,648 | RHS- | M] () -- C:\WINDOWS\System\VMwareService.exe
[2011.09.17 00:37:51 | 000,671,744 | RHS- | M] () -- C:\WINDOWS\System32\globalpatch.exe
[2011.09.16 21:48:40 | 000,439,628 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.09.16 21:48:40 | 000,437,386 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.09.16 21:48:40 | 000,089,794 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.09.16 21:48:40 | 000,078,556 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.09.16 20:47:46 | 000,000,151 | ---- | M] () -- C:\WINDOWS\System32\drenxr.dll
[2011.09.15 07:33:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.09.11 21:47:51 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.09.11 21:38:24 | 000,577,536 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\RogueKiller.exe
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.09.17 20:17:33 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.09.17 17:47:49 | 000,219,000 | ---- | C] () -- C:\WINDOWS\System32\x
[2011.09.17 17:40:17 | 000,035,840 | RHS- | C] () -- C:\WINDOWS\System32\csrsc.exe
[2011.09.17 17:40:12 | 000,155,648 | RHS- | C] () -- C:\WINDOWS\System\VMwareService.exe
[2011.09.17 17:40:11 | 000,035,840 | ---- | C] () -- C:\WINDOWS\System32\x.exe
[2011.09.17 00:37:40 | 000,671,744 | RHS- | C] () -- C:\WINDOWS\System32\globalpatch.exe
[2011.09.16 20:53:07 | 000,057,871 | R--- | C] () -- C:\WINDOWS\System32\smsc.exe
[2011.09.11 21:47:51 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.09.11 21:38:25 | 000,577,536 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\RogueKiller.exe
[2011.09.11 21:13:50 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Vzdálená pomoc.lnk
[2011.09.11 21:13:50 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Windows Media Player.lnk
[2011.09.07 00:40:37 | 001,015,808 | -HS- | C] () -- C:\WINDOWS\System32\irdvxc.exe
[2011.09.07 00:39:54 | 001,015,808 | -HS- | C] () -- C:\WINDOWS\System32\.exe
[2011.09.06 23:53:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ftpupd.exe
[2011.07.19 08:29:40 | 000,024,089 | ---- | C] () -- C:\WINDOWS\System32\ortecnx.dll
[2011.07.19 08:29:40 | 000,020,608 | ---- | C] () -- C:\WINDOWS\System32\ortecnxr.dll
[2011.07.19 08:29:40 | 000,019,315 | ---- | C] () -- C:\WINDOWS\System32\crecnxr.dll
[2011.07.19 08:29:40 | 000,017,275 | ---- | C] () -- C:\WINDOWS\System32\erecnxr.dll
[2011.07.19 08:29:40 | 000,009,279 | ---- | C] () -- C:\WINDOWS\System32\brecnxr.dll
[2011.07.19 08:29:40 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\drenxr.dll
[2011.05.12 18:37:08 | 000,263,680 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.05.12 18:37:08 | 000,105,984 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.05.12 18:37:08 | 000,099,328 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.05.12 18:37:08 | 000,087,580 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.05.12 18:37:08 | 000,075,264 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011.03.06 09:01:31 | 000,297,000 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll
[2010.06.20 12:01:06 | 000,175,987 | ---- | C] () -- C:\WINDOWS\hpoins36.dat.temp
[2010.06.20 12:01:05 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat.temp
[2010.05.30 16:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CorelDrw110.INI
[2010.05.16 20:10:10 | 000,000,622 | ---- | C] () -- C:\WINDOWS\DMN.INI
[2010.04.16 21:10:29 | 000,176,248 | ---- | C] () -- C:\WINDOWS\hpoins36.dat
[2010.04.16 21:10:29 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat
[2010.02.22 00:29:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\vypalovac.ini
[2010.01.02 20:31:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2010.01.02 14:07:36 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010.01.02 14:07:35 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010.01.02 14:07:35 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010.01.02 14:07:35 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010.01.02 14:07:35 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010.01.02 14:07:35 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010.01.02 14:07:35 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010.01.02 14:07:35 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010.01.02 14:07:35 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010.01.02 14:07:35 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010.01.02 14:07:35 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010.01.02 14:07:35 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010.01.02 14:07:35 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010.01.02 14:07:35 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010.01.02 14:07:35 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009.11.29 18:24:04 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009.11.12 14:48:58 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\StarOpen.sys
[2009.08.07 14:38:41 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2009.08.07 14:38:41 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\9CFEF50D54.sys
[2008.11.15 19:55:30 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez9066.dat
[2008.07.14 10:52:54 | 000,000,395 | ---- | C] () -- C:\WINDOWS\capella.ini
[2008.07.11 21:00:29 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008.01.16 18:09:46 | 000,464,896 | RHS- | C] () -- C:\WINDOWS\System32\zeqeqzd.exe
[2008.01.16 18:09:46 | 000,463,872 | RHS- | C] () -- C:\WINDOWS\System32\seamzrd.exe
[2008.01.16 18:09:46 | 000,462,848 | RHS- | C] () -- C:\WINDOWS\System32\ydchtad.exe
[2008.01.16 18:09:46 | 000,462,848 | RHS- | C] () -- C:\WINDOWS\System32\xmlnhjl.exe
[2007.12.30 22:43:58 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.30 22:43:58 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.29 20:01:13 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.08.21 19:21:14 | 000,000,036 | ---- | C] () -- C:\WINDOWS\CONTEXT.INI
[2007.08.21 19:20:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2007.08.19 20:21:56 | 000,000,041 | -H-- | C] () -- C:\WINDOWS\dsez6006.dat
[2007.04.21 10:21:06 | 000,000,948 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007.03.02 23:09:22 | 000,121,856 | ---- | C] () -- C:\WINDOWS\System32\Uharc.exe
[2007.03.02 23:09:22 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\moveex.exe
[2007.03.02 23:09:22 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\modifype.exe
[2007.03.02 22:49:20 | 000,000,058 | ---- | C] () -- C:\WINDOWS\FSaver.ini
[2007.02.17 19:32:19 | 000,001,459 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.17 19:31:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.15 17:18:21 | 000,000,463 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.01.26 22:46:44 | 000,006,378 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.01.26 22:35:45 | 000,610,304 | -H-- | C] () -- C:\WINDOWS\System32\dfxg115.dll
[2007.01.26 20:36:23 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2007.01.24 22:44:01 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2006.12.27 19:20:15 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.27 16:53:32 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006.12.27 16:33:49 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006.12.27 16:28:03 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.10.22 06:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 06:22:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006.10.22 06:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 06:22:00 | 001,347,584 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006.10.22 06:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 06:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 06:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 06:22:00 | 000,450,560 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006.10.22 06:22:00 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006.10.22 06:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 06:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.08.03 00:03:51 | 000,224,768 | -H-- | C] () -- C:\WINDOWS\System32\b4fm.dll
[2004.01.01 03:51:48 | 000,004,439 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.01.01 03:50:39 | 001,128,280 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.12.16 14:00:34 | 000,039,260 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002.12.16 13:58:52 | 000,022,337 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2002.09.20 18:19:36 | 000,001,740 | -H-- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2002.09.20 18:04:04 | 000,166,425 | RHS- | C] () -- C:\WINDOWS\System32\xsycs.dll
[2002.04.10 18:18:00 | 000,004,573 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001.10.25 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 14:00:00 | 000,439,628 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 14:00:00 | 000,437,386 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 14:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 14:00:00 | 000,089,794 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 14:00:00 | 000,078,556 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 14:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 14:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001.08.07 05:16:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\OTS_UI.EXE
[1993.07.23 20:31:02 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll

========== LOP Check ==========

[2011.05.17 15:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avg7
[2010.02.22 00:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.05.12 19:26:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2010.11.01 16:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.01.08 22:17:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MAGIX
[2011.05.12 19:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2008.07.11 21:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
[2007.11.04 13:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.03.02 18:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.05.16 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Yamaha
[2010.04.22 23:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\COWON
[2011.05.08 14:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\GetRightToGo
[2011.05.13 23:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\ICQ
[2007.05.22 07:18:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\COWON
[2007.05.22 06:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQLite

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\System32\CTFMON.EXE -- [2002.09.20 18:05:18 | 000,020,480 | -H-- | M] (Microsoft Corporation)


< MD5 for: ATAPI.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\drivers\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2002.09.20 18:05:14 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\cmdcons\autochk.exe
[2002.09.20 18:05:14 | 000,578,048 | -H-- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\WINDOWS\system32\autochk.exe

< MD5 for: CDROM.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2002.08.29 01:27:56 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CSRSS.EXE >
[2001.10.25 14:00:00 | 000,004,096 | -H-- | M] (Microsoft Corporation) MD5=E5C52921CC7B099CEA19C53E31F4AB0E -- C:\WINDOWS\system32\csrss.exe

< MD5 for: EXPLORER.EXE >
[2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) MD5=2E83E5B8558D562031AF987BFDC78073 -- C:\WINDOWS\explorer.exe
[2002.09.20 18:05:24 | 001,401,856 | ---- | M] (Microsoft Corporation) MD5=F313FD11075A3CF7480EC77DD21C1FE4 -- C:\VTPFiles\explorer.exe

< MD5 for: LSASS.EXE >
[2002.09.20 18:05:32 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2002.08.29 02:09:26 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NTFS.SYS >
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\cmdcons\NTFS.SYS
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\WINDOWS\system32\drivers\ntfs.sys

< MD5 for: SCECLI.DLL >
[2002.09.20 18:04:42 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2001.10.25 14:00:00 | 000,101,376 | ---- | M] (Microsoft Corporation) MD5=F4D2C4AF666E0224E961AA744A1B47E3 -- C:\WINDOWS\system32\services.exe

< MD5 for: SMSS.EXE >
[2001.10.24 03:52:12 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=0B7569ECA93964A39BEDCF763E78E22A -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2002.09.20 18:05:44 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2001.10.25 14:00:00 | 000,058,368 | ---- | M] (Microsoft Corporation) MD5=3A5AF33B43267D051F9D23F9DAE95BAE -- C:\WINDOWS\system32\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2001.10.25 14:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=93A69214D0909E73BB2061DB9DB7F3E9 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2002.08.29 01:58:12 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2002.09.20 18:05:48 | 000,029,184 | ---- | M] (Microsoft Corporation) MD5=D7F9593829D41DEB324142D3B603E271 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2002.09.20 18:05:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\system32\winlogon.exe

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.10.06 15:37:30 | 000,315,392 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2003.06.19 02:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2001.10.25 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.01.27 09:12:47 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2011.09.17 17:40:17 | 000,035,840 | RHS- | M] () -- C:\WINDOWS\system32\csrsc.exe
[2011.09.16 20:47:46 | 000,000,151 | ---- | M] () -- C:\WINDOWS\system32\drenxr.dll
[2011.09.17 18:07:26 | 000,005,184 | ---- | M] () -- C:\WINDOWS\system32\eras.fon
[2011.09.17 00:37:51 | 000,671,744 | RHS- | M] () -- C:\WINDOWS\system32\globalpatch.exe
[2011.09.17 18:03:35 | 000,088,566 | ---- | M] () -- C:\WINDOWS\system32\nvapps.xml
[2011.09.17 18:21:20 | 000,000,065 | ---- | M] () -- C:\WINDOWS\system32\o
[2011.09.16 21:48:40 | 000,089,794 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2011.09.16 21:48:40 | 000,078,556 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2011.09.16 21:48:40 | 000,437,386 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2011.09.16 21:48:40 | 000,439,628 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2011.09.16 21:48:40 | 001,060,592 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2011.09.17 17:47:32 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
[2011.09.17 20:17:14 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\system32\svchots.exe
[2011.09.15 07:33:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2011.09.17 17:50:24 | 000,219,000 | ---- | M] () -- C:\WINDOWS\system32\x
[2011.09.17 17:40:17 | 000,035,840 | ---- | M] () -- C:\WINDOWS\system32\x.exe
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[2002.09.20 18:04:04 | 000,166,425 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\xsycs.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\config\*.sav >
[2004.01.01 03:50:09 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004.01.01 03:50:09 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004.01.01 03:50:09 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\CSC\*.tmp files -> C:\WINDOWS\CSC\*.tmp -> ]
[9 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[10 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2011.05.12 18:36:44 | 000,012,576 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2009.09.03 19:39:23 | 000,000,088 | RHS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\9CFEF50D54.sys
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2007.12.29 20:01:13 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2011.09.17 17:32:53 | 000,006,476 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\hpzinstall.log
[2009.09.03 19:39:23 | 000,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\KGyGaAvL.sys

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758059181\thlkczve.exe
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060725\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060903\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1189700787495\thlkczve.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758059181\sjrshrre.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060725\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060903\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1189700787495\sjrshrre.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\snrjlbjn.exe
[2011.09.07 00:40:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758059181\eevjjlll.exe
[2011.09.07 00:40:51 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060725\eevjjlll.exe
[2011.09.07 00:40:53 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060903\eevjjlll.exe
[2011.09.07 00:40:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1189700787495\eevjjlll.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758059181\ljrkvtwh.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060725\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060903\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1189700787495\ljrkvtwh.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758059181\brwrlskz.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060725\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060903\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1189700787495\brwrlskz.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758059181\hnrhllzh.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060725\hnrhllzh.exe
[2011.09.07 00:41:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060903\hnrhllzh.exe
[2011.09.07 00:41:02 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1189700787495\hnrhllzh.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\cbrkrrqh.exe
[2011.09.07 00:41:17 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ejjkrtsn.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\etskskkb.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ewkknejq.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\hetqxlxk.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\nnteklcs.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\srewjcqe.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\thncexre.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\xnrzjqkk.exe
[2011.09.07 00:41:13 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\lwjsbskq.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\nxrvjrhs.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\srehhqvr.exe
[2011.09.07 00:41:23 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ICQ\ICQNewTab\lhnllvjb.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\jehckswh.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\wthhxtzs.exe
[2007.01.14 19:39:39 | 005,535,448 | ---- | M] (InstallShield Software Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\CT4SkypePlugin10_Multi_Lite.exe
[2007.01.14 19:39:39 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\RLLauncher.exe
[2007.01.14 19:42:07 | 001,371,136 | ---- | M] (EasyBits Software Corp.) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F35E193DC3E84933B83DE961D9AC33BF\SketchPad.exe
[2011.09.07 00:41:38 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\kxllttje.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.09.11 21:18:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Adobe
[2011.09.11 21:18:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Macromedia
[2011.09.11 21:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
[2011.09.11 21:33:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
[2011.09.11 21:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla

< *crack* /s >
[2008.08.27 10:46:18 | 000,000,310 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crack.bat
[2008.08.27 10:46:18 | 000,000,327 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crackTS.bat
[2010.05.17 16:55:47 | 000,016,743 | R--- | M] () -- \Program Files\BitLord\Torrents\FL.Studio.9.XXL.mit.Crack.und.VSTi.Cracks.torrent
[2010.05.19 12:22:12 | 000,015,879 | R--- | M] () -- \Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack.torrent
[2010.05.19 12:22:34 | 000,015,879 | R--- | M] () -- \Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack[0].torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack.torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack[0].torrent
[1999.06.11 20:18:36 | 000,092,827 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 18:31:34 | 000,016,068 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 19:15:38 | 000,010,560 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2001.07.10 11:03:00 | 000,028,276 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackerc.wmf
[2001.07.10 11:02:18 | 000,032,558 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackers.wmf
[1995.07.03 18:24:04 | 000,125,094 | ---- | M] () -- \WINDOWS\Fonts\Newcrack.ttf

< *keygen* /s >

< %APPDATA%\*.* >
[2011.09.11 21:33:24 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Administrator\Data aplikací\Bh8HEGhGffH2.txJgIfiKafIij1.txt
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Administrator\Data aplikací\desktop.ini

< %APPDATA%\*.exe /s >

< %SYSTEMDRIVE%\*.exe >
[2011.08.28 21:43:29 | 000,921,805 | ---- | M] (instyler installation software) -- C:\Setup.exe

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces >

< sTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\ProgID\\: MSTIME.TIMEMotionAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\VersionIndependentProgID\\: MSTIME.TIMEMotionAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\ProgID\\: MSTIME.SMILAnimCompSiteFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\VersionIndependentProgID\\: MSTIME.SMILAnimCompSiteFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\ProgID\\: MSTIME.TIMEFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\VersionIndependentProgID\\: MSTIME.TIMEFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\ProgID\\: MSTIME.SMILAnimDefaultCompFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\VersionIndependentProgID\\: MSTIME.SMILAnimDefaultCompFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\ProgID\\: MSTIME.TIMEColorAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\VersionIndependentProgID\\: MSTIME.TIMEColorAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A951B11A-C712-45B3-B884-2469A6243368}\InProcServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\ProgID\\: MSTIME.TIMESetAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\VersionIndependentProgID\\: MSTIME.TIMESetAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\ProgID\\: MSTIME.TIMEFilterAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\VersionIndependentProgID\\: MSTIME.TIMEFilterAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\ProgID\\: MSTIME.TIMEAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\VersionIndependentProgID\\: MSTIME.TIMEAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2F5A901-4080-11D1-A3AC-00C04FB950DC}\\: IADsTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\\: MSTIME [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\0\win32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\\ProcessTimeOut: 3600
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\\LeaseTerminatesTime: 1316295374
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\Parameters\Tcpip\\LeaseTerminatesTime: 1316295374

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %fystemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %fystemRoot%\System32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:58B11540

< End of report >

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#28 Příspěvek od WiZARD_ »

OTL Extras logfile created on: 17.9.2011 20:16:52 - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Documents and Settings\Administrator\Plocha
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,48 Mb Total Physical Memory | 303,61 Mb Available Physical Memory | 59,36% Memory free
1,22 Gb Paging File | 1,09 Gb Available in Paging File | 89,24% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 0,70 Gb Free Space | 1,88% Space Free | Partition Type: NTFS
Drive H: | 596,02 Gb Total Space | 317,24 Gb Free Space | 53,23% Space Free | Partition Type: FAT32

Computer Name: UNGIS-KFHKNNXQI | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotolab Fotosvet 3] -- "C:\Program Files\Fotolab\Fotolab Fotosvet 3\Fotolab Fotosvet 3.exe" "%1" ()
Directory [OtsMedia.Surf] -- "C:\OtsLabs\OTSPLAY.EXE" "%1" /play /surf ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
"UacDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"FirewallOverride" = 1
"UpdatesDisableNotify" = 1
"UacDisableNotify" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\upds.exe" = C:\WINDOWS\System32\upds.exe:*:Enabled:Windows System Update Tools
"C:\WINDOWS\System32\x.exe" = C:\WINDOWS\System32\x.exe:*:Enabled:ipsec -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00405945-70C1-4B1D-9A3C-45A2883366AF}" = PS_AIO_05_C4600_Software_Min
"{055FEF8E-4B86-400F-A5C6-8FAC0042DCD9}" = NVIDIA DVD Decoder
"{07A540AB-D785-11D5-8E89-0090275862A0}" = Corel Graphics Suite 11
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{200F584F-848D-4B6B-B1A1-C74D735F18A4}" = InstallRTC
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 20
"{271A659B-A7D3-405E-AE31-3086133BE0B7}" = Yamaha USB-MIDI Driver
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3063E0DA-A9EB-4B55-A04E-BC477DA52915}" = DrawPlus7
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362b5d37-5278-4714-94e0-00ba0cfc371a}" = RelevantKnowledge
"{3F9D3AF5-BB74-474A-92C8-410839303DB5}" = TubeSucker
"{435673AB-6821-416D-806A-E477DFA60A42}" = WingMan Software
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44C81D1A-0520-49BB-B510-98B8DD414EA1}" = HP Photosmart C4600 All-In-One Driver Software 13.0 Rel .5
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}" = upapp
"{4F62B1AE-E778-49E2-9C57-C1C65A122098}" = Zoner Callisto 5
"{51C91B84-7B46-4FE7-8999-8228CFA75F89}" = Intel(R) Integrated Performance Primitives RTI 4.0
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58005385-C433-4B89-BFA5-484A7C315C55}_is1" = Vypalovač CD / DVD / Blu-ray / HD-DVD 1.1
"{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}" = CDBurnerXP
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681343DC-2519-466F-B53E-05CB9A9A6A86}" = Restaurant Empire
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6CAED17B-1A75-4890-A20E-5555A8C1B72D}" = YAMAHA Digital Music Notebook
"{6D3C6846-CDB6-418F-8FDB-DA21FE064F86}" = YAMAHA Musicsoft Downloader 5
"{6E65247F-58F9-41CA-BE69-0316F7907170}" = Disc2Phone
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7CDD7C4C-5224-40E4-951F-51C12FEAB8AB}" = C4600
"{86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF}" = Adobe Audition 1.5
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{922E8525-AC7E-4294-ACAA-43712D4423C0}" = Adobe Flash Player 10 ActiveX
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1029-7B44-A70000000000}" = Adobe Reader 7.0 - Czech
"{ADE91A13-434D-4229-00BC-182BAD607303}" = Need for Speed™ Most Wanted
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B4C88CF0-B617-4658-8F84-C4E847FBC9F7}" = Microsoft Managed DirectX (1126)
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C263C8DC-FFBC-4358-A62F-BDBCD58AE64A}" = Sony ACID Pro 5.0c
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D60D2B02-125F-4DDB-9674-41DD538C457A}" = Sony Media Manager 2.0
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio Basic
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}" = Corel WinDVD 9
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"ASIO4ALL" = ASIO4ALL
"AVS DVD Copy_is1" = AVS DVD Copy version 1.4
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"BitLord" = BitLord 1.1
"Burn4Free" = Burn4Free CD and DVD
"Collab" = Collab
"Deckadance" = Deckadance
"Firebird SQL Server UK" = Firebird SQL Server - MAGIX Edition
"FL Studio 8" = FL Studio 8
"Fotolab Fotosvet 3" = Fotolab Fotosvet 3
"Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 2.1
"GameParkClient_is1" = GamePark
"HijackThis" = HijackThis 1.99.0
"hp deskjet 3325 series" = hp deskjet 3325 series (Pouze odstranit)
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ICQToolbar" = ICQ Toolbar
"IL Download Manager" = IL Download Manager
"InstallShield_{07A540AB-D785-11D5-8E89-0090275862A0}" = CorelDRAW Graphics Suite 11
"InstallShield_{681343DC-2519-466F-B53E-05CB9A9A6A86}" = Restaurant Empire
"InstallShield_{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}" = Corel WinDVD 9
"MagicScore_is1" = MagicScore
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"mIRC" = mIRC
"Mozilla Firefox 6.0.2 (x86 cs)" = Mozilla Firefox 6.0.2 (x86 cs)
"NI Service Center" = NI Service Center
"NVIDIA Drivers" = NVIDIA Drivers
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"Ots CD Scratch 1200" = Ots CD Scratch 1200 1.00.032
"OtsTurntables Free" = OtsTurntables Free 1.00.012
"PC Alert 4" = PC Alert 4
"PCI Audio Driver" = PCI Audio Driver
"PhotoFiltre" = PhotoFiltre
"PoiZone" = PoiZone
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Screamer 4x4" = Screamer 4x4
"Sibelius Scorch" = Sibelius Scorch
"TmNations_is1" = TrackMania Nations ESWC 1.7.9
"Toxic Biohazard" = Toxic Biohazard
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VirtualCloneDrive" = VirtualCloneDrive
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17.9.2011 11:24:51 | Computer Name = UNGIS-KFHKNNXQI | Source = VSS | ID = 8193
Description = Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance
došlo k neočekávané chybě. hr= 0x80040206.

Error - 17.9.2011 11:31:59 | Computer Name = UNGIS-KFHKNNXQI | Source = MsiInstaller | ID = 11719
Description = Product: WinDVD -- Error 1719.Windows Installer service could not
be accessed. Contact your support personnel to verify that it is properly registered
and enabled.

Error - 17.9.2011 11:34:25 | Computer Name = UNGIS-KFHKNNXQI | Source = Winlogon | ID = 1015
Description = Důležitý systémový proces C:\WINDOWS\system32\lsass.exe nebyl úspěšný,
stavový kód: c0000005. Počítač je nyní nutné restartovat.

Error - 17.9.2011 11:36:34 | Computer Name = UNGIS-KFHKNNXQI | Source = EventSystem | ID = 4609
Description = Systém událostí modelu COM+ zjistil při vnitřním zpracovávání chybný
návratový kód. Hodnota HRESULT byla 8007043C z řádku 44 v d:\nt\com\com1x\src\events\tier1\eventsystemobj.cpp.Obraťte
se na služby odborné pomoci společnosti Microsoft a informujte je o této chyb

Error - 17.9.2011 11:36:34 | Computer Name = UNGIS-KFHKNNXQI | Source = VSS | ID = 8193
Description = Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance
došlo k neočekávané chybě. hr= 0x80040206.

Error - 17.9.2011 11:51:25 | Computer Name = UNGIS-KFHKNNXQI | Source = EventSystem | ID = 4609
Description = Systém událostí modelu COM+ zjistil při vnitřním zpracovávání chybný
návratový kód. Hodnota HRESULT byla 8007043C z řádku 44 v d:\nt\com\com1x\src\events\tier1\eventsystemobj.cpp.Obraťte
se na služby odborné pomoci společnosti Microsoft a informujte je o této chyb

Error - 17.9.2011 11:51:25 | Computer Name = UNGIS-KFHKNNXQI | Source = VSS | ID = 8193
Description = Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance
došlo k neočekávané chybě. hr= 0x80040206.

Error - 17.9.2011 14:14:07 | Computer Name = UNGIS-KFHKNNXQI | Source = EventSystem | ID = 4609
Description = Systém událostí modelu COM+ zjistil při vnitřním zpracovávání chybný
návratový kód. Hodnota HRESULT byla 8007043C z řádku 44 v d:\nt\com\com1x\src\events\tier1\eventsystemobj.cpp.Obraťte
se na služby odborné pomoci společnosti Microsoft a informujte je o této chyb

Error - 17.9.2011 14:14:07 | Computer Name = UNGIS-KFHKNNXQI | Source = VSS | ID = 8193
Description = Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance
došlo k neočekávané chybě. hr= 0x80040206.

Error - 17.9.2011 14:18:21 | Computer Name = UNGIS-KFHKNNXQI | Source = EventSystem | ID = 4609
Description = Systém událostí modelu COM+ zjistil při vnitřním zpracovávání chybný
návratový kód. Hodnota HRESULT byla 8007043C z řádku 44 v d:\nt\com\com1x\src\events\tier1\eventsystemobj.cpp.Obraťte
se na služby odborné pomoci společnosti Microsoft a informujte je o této chyb

[ System Events ]
Error - 17.9.2011 12:21:19 | Computer Name = UNGIS-KFHKNNXQI | Source = LsaSrv | ID = 5000
Description = Balíček zabezpečení Negotiate vygeneroval výjimku. Balíček je nyní
zakázán. Informace o výjimce jsou uvedeny v datech.

Error - 17.9.2011 14:12:44 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Terminálová služba.

Error - 17.9.2011 14:12:44 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7000
Description = Služba Terminálová služba neuspěla při spuštění v důsledku následující
chyby: %%1053

Error - 17.9.2011 14:12:44 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7001
Description = Služba Kompatibilita pro rychlé přepínání uživatelů závisí na službě
Terminálová služba, která neuspěla při spuštění v důsledku následující chyby: %%1053

Error - 17.9.2011 14:14:02 | Computer Name = UNGIS-KFHKNNXQI | Source = sfsync02 | ID = 262156
Description =

Error - 17.9.2011 14:14:07 | Computer Name = UNGIS-KFHKNNXQI | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 17.9.2011 14:14:29 | Computer Name = UNGIS-KFHKNNXQI | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 17.9.2011 14:15:25 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: AmdK8 ElbyVCD Fips

Error - 17.9.2011 14:15:25 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Terminálová služba.

Error - 17.9.2011 14:15:25 | Computer Name = UNGIS-KFHKNNXQI | Source = Service Control Manager | ID = 7000
Description = Služba Terminálová služba neuspěla při spuštění v důsledku následující
chyby: %%1053


< End of report >

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#29 Příspěvek od chodnik74 »

:arrow: Aktualizujte Service Pack 3 + IE 8 (service pack řeší řadu problémů)
:arrow: Odinstalujte ICQ6Toolbar

:arrow: Stáhneme si na Plochu program OTLObrázek
  • Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Do dolního okna Vlastní skenování/opravy vložíme následující skript a stiskneme tlačítko Opravit

    Kód: Vybrat vše

    :OTL
    SRV - File not found [On_Demand | Stopped] -- -- (xmlprov)
    SRV - File not found [Disabled | Stopped] -- -- (wscsvc)
    SRV - File not found [Auto | Stopped] -- -- (PEVSystemStart)
    SRV - File not found [Disabled | Stopped] -- -- (HidServ)
    [2009.09.25 18:16:45 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    O4 - HKLM..\Run: [365dni] File not found
    O4 - HKLM..\Run: [365dní] File not found
    O4 - HKLM..\Run: [Microsoft System Service] C:\WINDOWS\System32\globalpatch.exe ()
    O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
    O4 - HKLM..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKLM..\Run: [WMC_AutoUpdate] File not found
    O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
    O4 - HKU\.DEFAULT..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
    O4 - HKU\S-1-5-18..\Run: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKLM..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
    O4 - HKU\.DEFAULT..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-18..\RunOnce: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - HKLM..\RunServices: [Microsoft System Service] C:\WINDOWS\System32\globalpatch.exe ()
    O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\xmlnhjl.exe ()
    O4 - HKLM..\RunServices: [windows updatess] C:\WINDOWS\System32\svchots.exe (OldMan's Tales)
    O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\ICQ6.5.lnk = File not found
    O20 - Winlogon\Notify\cryptnet32: DllName - (cryptnet32.dll) - File not found
    [2011.09.17 09:17:15 | 000,150,528 | ---- | C] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2011.09.17 18:21:20 | 000,000,065 | ---- | M] () -- C:\WINDOWS\System32\o
    [2011.09.17 18:07:26 | 000,005,184 | ---- | M] () -- C:\WINDOWS\System32\eras.fon
    [2011.09.17 18:03:35 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
    [2011.09.17 17:50:24 | 000,219,000 | ---- | M] () -- C:\WINDOWS\System32\x
    [2011.09.17 17:47:32 | 000,057,871 | R--- | M] () -- C:\WINDOWS\System32\smsc.exe
    [2011.09.17 17:40:17 | 000,035,840 | RHS- | M] () -- C:\WINDOWS\System32\csrsc.exe
    [2011.09.17 17:40:17 | 000,035,840 | ---- | M] () -- C:\WINDOWS\System32\x.exe
    [2011.09.17 00:37:51 | 000,671,744 | RHS- | M] () -- C:\WINDOWS\System32\globalpatch.exe
    [2011.09.16 20:47:46 | 000,000,151 | ---- | M] () -- C:\WINDOWS\System32\drenxr.dll
    [2011.09.07 00:40:37 | 001,015,808 | -HS- | C] () -- C:\WINDOWS\System32\irdvxc.exe
    [2011.09.07 00:39:54 | 001,015,808 | -HS- | C] () -- C:\WINDOWS\System32\.exe
    [2011.09.06 23:53:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ftpupd.exe
    [2011.07.19 08:29:40 | 000,024,089 | ---- | C] () -- C:\WINDOWS\System32\ortecnx.dll
    [2011.07.19 08:29:40 | 000,020,608 | ---- | C] () -- C:\WINDOWS\System32\ortecnxr.dll
    [2011.07.19 08:29:40 | 000,019,315 | ---- | C] () -- C:\WINDOWS\System32\crecnxr.dll
    [2011.07.19 08:29:40 | 000,017,275 | ---- | C] () -- C:\WINDOWS\System32\erecnxr.dll
    [2011.07.19 08:29:40 | 000,009,279 | ---- | C] () -- C:\WINDOWS\System32\brecnxr.dll
    [2011.07.19 08:29:40 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\drenxr.dll
    [2010.06.20 12:01:06 | 000,175,987 | ---- | C] () -- C:\WINDOWS\hpoins36.dat.temp
    [2010.06.20 12:01:05 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat.temp
    [2011.03.06 09:01:31 | 000,297,000 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll
    [2008.01.16 18:09:46 | 000,464,896 | RHS- | C] () -- C:\WINDOWS\System32\zeqeqzd.exe
    [2008.01.16 18:09:46 | 000,463,872 | RHS- | C] () -- C:\WINDOWS\System32\seamzrd.exe
    [2008.01.16 18:09:46 | 000,462,848 | RHS- | C] () -- C:\WINDOWS\System32\ydchtad.exe
    [2008.01.16 18:09:46 | 000,462,848 | RHS- | C] () -- C:\WINDOWS\System32\xmlnhjl.exe
    [2007.03.02 23:09:22 | 000,121,856 | ---- | C] () -- C:\WINDOWS\System32\Uharc.exe
    [2007.03.02 23:09:22 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\moveex.exe
    [2007.03.02 23:09:22 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\modifype.exe
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\CSC\*.tmp files -> C:\WINDOWS\CSC\*.tmp -> ]
    [9 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [10 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
    [1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
    [2009.09.03 19:39:23 | 000,000,088 | RHS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\9CFEF50D54.sys
    [2010.05.17 16:55:47 | 000,016,743 | R--- | M] () -- \Program Files\BitLord\Torrents\FL.Studio.9.XXL.mit.Crack.und.VSTi.Cracks.torrent
    [2010.05.19 12:22:12 | 000,015,879 | R--- | M] () -- \Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack.torrent
    [2010.05.19 12:22:34 | 000,015,879 | R--- | M] () -- \Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack[0].torrent
    [2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack.torrent
    [2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack[0].torrent
    
    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [ResetHosts]
    
    
  • Po restartu pc se vám objeví log z OTL,ten mi sem prosím vložte..
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#30 Příspěvek od chodnik74 »

Ale řeknu vám,máte to dobře zavirované :shock: tohle nazveme jako First wave :evil: neboli první vlna do boje proti havěti :D
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Odpovědět