
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Neskutečně zasekané a spomalené PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Zkuste v normálním režimu tento návod celý....a vložte mi patřičné logy...
http://www.viry.cz/forum/viewtopic.php? ... 7#p1036767
http://www.viry.cz/forum/viewtopic.php? ... 7#p1036767
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== REGISTRY ==========
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ErrorControl"|dword:00000001 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ErrorControl"|dword:00000001 /E!
========== COMMANDS ==========
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 456 bytes
User: All Users
User: Alů
->Flash cache emptied: 0 bytes
User: Default User
User: Guest
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Viti
->Flash cache emptied: 5446730 bytes
Total Flash Files Cleaned = 5,00 mb
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 14745496 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Alů
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Viti
->Temp folder emptied: 1853984155 bytes
->Temporary Internet Files folder emptied: 136341631 bytes
->Java cache emptied: 23529323 bytes
->FireFox cache emptied: 303938537 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2560 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2 225,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.29.1 log created on 09252011_123425
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== REGISTRY ==========
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ErrorControl"|dword:00000001 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ErrorControl"|dword:00000001 /E!
========== COMMANDS ==========
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 456 bytes
User: All Users
User: Alů
->Flash cache emptied: 0 bytes
User: Default User
User: Guest
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Viti
->Flash cache emptied: 5446730 bytes
Total Flash Files Cleaned = 5,00 mb
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 14745496 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Alů
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Viti
->Temp folder emptied: 1853984155 bytes
->Temporary Internet Files folder emptied: 136341631 bytes
->Java cache emptied: 23529323 bytes
->FireFox cache emptied: 303938537 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2560 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2 225,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.29.1 log created on 09252011_123425
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Re: Neskutečně zasekané a spomalené PC
Tak nevím kde dělám chybu ale kontrola je pořád prázdná... 

- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Tohle bylo v normálním režimu? momentík vymyslím další postup 

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
Ano, režim ve kterém normálně pracuji...
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Zkusíme to ještě jinak... teda stejně ale jiným programem...
1) Resetování práv
Stáhneme si program SWReg.exe
2) Provedení opravy
Stáhneme si na Plochu program OTM
1) Resetování práv

- Soubor uložíme přímo na disk C:\
- Otevřeme si Poznámkový blok
- (stiskneme klávesovou kombinaci WIN+R a napíšeme ,,notepad,, bez úvozovek a dáme enter)
- Vložíme do něj následující script:
Kód: Vybrat vše
@echo off c:\swreg.exe ACL "HKLM\SYSTEM\CurrentControlSet\Control\Services\wuauserv" /RESET /Q c:\swreg.exe ACL "HKLM\SYSTEM\CurrentControlSet\Control\Services\BITS" /RESET /Q
- Soubor uložíme jako reset.bat (při ukládání nastavte Uložit jako typ:Všechny soubory)
- Poté tento soubor spustíme a potvrdíme
2) Provedení opravy


- Spustíme soubor OTM.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
- Spustí se nám program OTM a do levého okna ,,Paste Instructions for Items to be Moved,, vložíme následující skript a stiskneme tlačítko MoveIt
Kód: Vybrat vše
:files %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :Reg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS] "ImagePath"=hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv] "ImagePath"=hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 :Commands [EmptyFlash] [EmptyTemp] [ResetHosts]
- Po restartu pc se vám objeví log z OTM,ten mi sem prosím vložte..
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
Moment. Teď tomu moc nerozumím. Když stáhnu program swreg, co pak s ním? A zároveň nechápu jak mám reset.bat potvrdit, když ho spustím... 

- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Máte to tam popsané
SWReg.exe = Soubor uložíme přímo na disk C:\ ,poté provedete akci s poznámkovým blokem,uložíte jako reset.bat a spustíte jako bězný program,poté následujete krokem č. 2
Zkuste a uvidíme...


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== REGISTRY ==========
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ErrorControl"|dword:00000001 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ErrorControl"|dword:00000001 /E!
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Alů
->Temp folder emptied: 99526 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 28208232 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Viti
->Temp folder emptied: 4069 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 220472081 bytes
->Flash cache emptied: 1223 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 691604 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 238,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTM by OldTimer - Version 3.1.18.0 log created on 09282011_093518
Files moved on Reboot...
Registry entries deleted on Reboot...
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== REGISTRY ==========
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\\"ErrorControl"|dword:00000001 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ImagePath"|hex(2):"%systemroot%\system32\svchost.exe -k netsvcs" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Type"|dword:00000020 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"Start"|dword:00000002 /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\\"ErrorControl"|dword:00000001 /E!
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Alů
->Temp folder emptied: 99526 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 28208232 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Viti
->Temp folder emptied: 4069 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 220472081 bytes
->Flash cache emptied: 1223 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 691604 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 238,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTM by OldTimer - Version 3.1.18.0 log created on 09282011_093518
Files moved on Reboot...
Registry entries deleted on Reboot...
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC


- Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
- Pokud používáte 64 bitový systém,zaškrkněte volbu Pro 64 bitové OS,pokud ne,tak by měla být nezaškrknutá
- Zaškrkněte okýnko Pro všechny uživatele,Kontrola havět "LOP",Kontrola havět "Purity"
- Staří souborů změňte z 30 dnů na 7 dnů
- Do spodního okýnka Vlastní skenování/opravy vložte následující script:
Kód: Vybrat vše
safebootminimal safebootnetwork drivers32 savembr:0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s /md5start scecli.dll autochk.exe csrss.exe explorer.exe lsass.exe services.exe smss.exe spoolsv.exe svchost.exe userinit.exe winlogon.exe atapi.sys cdrom.sys ndis.sys ntfs.sys tcpip.sys %SystemDrive%\PhysicalMBR.bin /md5stop C:\windows\system32\spool\prtprocs|dll;true;true;true /FP %systemroot%\system32\drivers\*.sys /5 %systemroot%\system32\drivers\*.sys /X %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\system32\*.* /5 %systemroot%\system32\*.dll /lockedfiles %systemroot%\system32\config\*.sav %systemroot%\Tasks\*.job /lockedfiles %systemroot%\*.* /U /s %systemroot%\*. /mp /s %ALLUSERSPROFILE%\Data Aplikací\*.* %ALLUSERSPROFILE%\Data Aplikací\*.exe /s %ALLUSERSPROFILE%\Dáta aplikácií\*.* %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s %APPDATA%\*. *crack* /s *keygen* /s %APPDATA%\*.* %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces sTime /rs reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c type c:\boot.ini >> test.txt /c
- Klikněte na tlačítko Prohledat
- Po dokončení skenu,který trvá mezi 5-15 minuty se vám zobrazý dva logy OTL.txt a Extras.txt a ty mě sem vložte
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
OTL logfile created on: 28.9.2011 14:17:51 - Run 2
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Viti\Plocha
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
511,48 Mb Total Physical Memory | 149,16 Mb Available Physical Memory | 29,16% Memory free
1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,73% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 5,80 Gb Free Space | 15,58% Space Free | Partition Type: NTFS
Drive H: | 596,02 Gb Total Space | 316,53 Gb Free Space | 53,11% Space Free | Partition Type: FAT32
Computer Name: UNGIS-KFHKNNXQI | User Name: Viti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2011.09.28 14:13:48 | 000,590,336 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
PRC - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
PRC - [2011.09.10 23:47:28 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] () -- C:\WINDOWS\system32\qmsvlpi.exe
========== Modules (No Company Name) ==========
MOD - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
MOD - [2011.09.10 23:47:25 | 001,846,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.09.09 16:32:04 | 006,277,280 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
MOD - [2006.10.22 06:22:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2006.10.22 06:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2004.12.27 13:46:04 | 000,311,296 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2004.12.26 21:34:38 | 000,121,344 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] () -- C:\WINDOWS\system32\qmsvlpi.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (MSDisk)
SRV - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () [Auto | Running] -- C:\WINDOWS\System32\smsc.exe -- (PrtSmanm)
SRV - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.03.23 16:52:12 | 000,056,552 | ---- | M] (Eng. Usama El-Mokadem) [Auto | Stopped] -- C:\WINDOWS\System32\Startsrv.exe -- (SRVStarter_Service)
SRV - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.05.10 11:59:04 | 000,353,912 | ---- | M] (Protection Technology (StarForce)) [Auto | Stopped] -- C:\WINDOWS\System32\sfrem01.exe -- (sfrem01) SF FrontLine Drivers Auto Removal (v1)
SRV - [2005.11.17 16:18:52 | 001,536,092 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2002.12.17 18:26:22 | 007,528,529 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,320,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (xkevza)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (vhjqjqbt)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (eybwi)
========== Driver Services (SafeList) ==========
DRV - [2009.11.12 14:48:58 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\StarOpen.sys -- (StarOpen)
DRV - [2009.08.04 13:09:42 | 000,018,560 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ymidusb.sys -- (YMIDUSB)
DRV - [2009.01.27 09:12:47 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.04.17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\regi.sys -- (regi)
DRV - [2007.03.15 22:07:14 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007.01.12 20:09:53 | 000,082,296 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2006.07.10 18:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2006.05.10 10:39:38 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.04.05 21:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.05 21:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.01.11 17:05:30 | 000,092,672 | ---- | M] (ALCATech) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL)
DRV - [2004.04.01 17:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002.11.18 17:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.08.29 02:32:44 | 000,009,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2002.06.20 19:45:44 | 000,013,920 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2002.06.20 19:45:42 | 000,020,128 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002.06.20 19:45:40 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2002.06.20 19:45:36 | 000,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2002.06.20 19:45:34 | 000,039,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2001.08.17 22:12:42 | 000,023,070 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [1997.12.23 02:00:00 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Viti\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_result ... r=1.3.1&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.0
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20101009
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.22
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.3.1&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.06.20 12:40:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.09.10 23:47:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.08 11:23:55 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.06.20 12:40:50 | 000,000,000 | ---D | M]
[2008.06.20 20:30:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Extensions
[2011.09.28 09:42:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Metal Lion - Vista) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (Qute) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2010.10.15 18:21:45 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2009.12.28 01:18:18 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2009.10.11 19:38:26 | 000,000,000 | ---D | M] (iFox Graphite) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{74b288e6-77b6-41c7-8138-bb81f4539689}
[2011.08.23 11:35:59 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (PimpZilla) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Blue Ice 2) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2011.09.10 23:47:39 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com
[2011.05.08 11:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\nostmp
[2011.09.28 09:42:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\staged
[2007.09.19 20:13:48 | 000,000,000 | ---D | M] ("VideoDownloader") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\videodowloader@videodownloader.net
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\defaults
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\chrome
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011.09.24 16:14:16 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-1.xml
[2009.06.15 15:32:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-10.xml
[2009.07.23 15:16:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-11.xml
[2009.08.04 20:40:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-12.xml
[2009.09.11 20:19:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-13.xml
[2009.10.29 10:16:06 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-14.xml
[2009.11.07 11:15:29 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-15.xml
[2009.12.17 15:19:50 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-16.xml
[2010.01.07 15:37:04 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-17.xml
[2010.02.19 19:11:40 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-18.xml
[2010.03.12 18:28:32 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-19.xml
[2008.10.01 17:09:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-2.xml
[2010.03.25 08:05:04 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-20.xml
[2010.04.03 23:01:11 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-21.xml
[2010.07.05 21:02:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-22.xml
[2010.07.23 13:46:37 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-23.xml
[2010.07.24 15:37:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-24.xml
[2010.09.12 18:11:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-25.xml
[2010.09.17 17:46:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-26.xml
[2010.10.22 23:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-27.xml
[2010.10.31 17:13:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-28.xml
[2010.11.01 16:32:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-29.xml
[2008.11.14 12:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-3.xml
[2011.03.02 00:33:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-30.xml
[2011.03.06 14:33:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-31.xml
[2011.03.24 21:06:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-32.xml
[2011.04.30 13:06:15 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-33.xml
[2011.05.08 11:24:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-34.xml
[2011.07.17 16:32:43 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-35.xml
[2011.08.28 08:24:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-36.xml
[2011.08.31 19:52:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-37.xml
[2011.09.10 23:48:21 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-38.xml
[2008.12.17 17:50:45 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-4.xml
[2009.02.08 12:49:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-5.xml
[2009.03.08 11:53:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-6.xml
[2009.03.29 12:51:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-7.xml
[2009.04.23 20:07:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-8.xml
[2009.04.28 19:03:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-9.xml
[2011.08.18 21:40:40 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.gif
[2011.08.18 21:40:40 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.src
[2010.06.21 17:35:24 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.xml
[2009.09.24 16:00:41 | 000,002,061 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\qipsearch.xml
[2011.09.17 23:14:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}
[2011.09.10 23:47:29 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.05.08 11:23:40 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.05.08 11:23:40 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.07.05 21:02:00 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.05.08 11:23:40 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.05.08 11:23:40 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.05.08 11:23:40 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011.09.28 09:37:19 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Viti\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O3 - HKLM\..\Toolbar: (&Rádio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKLM..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\.DEFAULT..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\S-1-5-18..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [FreeCall] "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [LClock] C:\Program Files\LClock\lclock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [mxClock] C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Start WingMan Profiler] File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows Updates] bqpldgv.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-18..\RunOnce: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKLM..\RunServices: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 67108863
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O15 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.12.27 16:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.09.20 18:04:04 | 000,095,034 | RHS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\...exe [@ = exefile] -- "%1" %*
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
Drivers32: midi2 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2011.09.28 14:14:12 | 000,590,336 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
[2011.09.28 09:35:18 | 000,000,000 | ---D | C] -- C:\_OTM
[2011.09.28 09:34:40 | 000,530,944 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTM.exe
[2011.09.28 09:33:04 | 000,297,472 | ---- | C] (SteelWerX) -- C:\swreg.exe
[2011.09.25 12:09:21 | 000,150,528 | ---- | C] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
========== Files - Modified Within 7 Days ==========
[2011.09.28 14:20:14 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.09.28 14:13:48 | 000,590,336 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
[2011.09.28 13:01:52 | 001,935,622 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\nike final male samolepky.cdr
[2011.09.28 12:03:39 | 000,002,507 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\CorelDRAW 11.lnk
[2011.09.28 11:58:38 | 004,799,314 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\NIKE LETAK FINAL.cdr
[2011.09.28 11:53:55 | 003,674,582 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\Záloha_NIKE LETAK FINAL.cdr
[2011.09.28 09:48:25 | 000,462,848 | ---- | M] () -- C:\WINDOWS\System32\winlolx.exe
[2011.09.28 09:48:18 | 000,000,066 | ---- | M] () -- C:\WINDOWS\System32\o
[2011.09.28 09:45:46 | 000,002,272 | ---- | M] () -- C:\WINDOWS\System32\eras.fon
[2011.09.28 09:37:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.09.28 09:34:23 | 000,530,944 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTM.exe
[2011.09.28 09:33:46 | 000,000,177 | ---- | M] () -- C:\reset.bat
[2011.09.28 09:30:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\scanonline.exe
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\WINDOWS\System32\lsas.exe
[2011.09.25 12:33:02 | 000,297,472 | ---- | M] (SteelWerX) -- C:\swreg.exe
[2011.09.25 12:09:26 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
[2011.09.24 23:10:21 | 000,121,968 | ---- | M] () -- C:\WINDOWS\System32\x
[2011.09.24 22:36:48 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.09.24 17:10:53 | 000,064,684 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\nike aukro oran.jpg
[2011.09.21 22:06:49 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\System32\smsc.exe
========== Files Created - No Company Name ==========
[2011.09.28 13:01:51 | 001,935,622 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\nike final male samolepky.cdr
[2011.09.28 11:53:54 | 003,674,582 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\Záloha_NIKE LETAK FINAL.cdr
[2011.09.28 11:47:39 | 004,799,314 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\NIKE LETAK FINAL.cdr
[2011.09.28 09:33:46 | 000,000,177 | ---- | C] () -- C:\reset.bat
[2011.09.25 23:42:52 | 000,175,467 | ---- | C] () -- C:\WINDOWS\System32\lsas.exe
[2011.09.25 23:42:47 | 000,175,467 | ---- | C] () -- C:\scanonline.exe
[2011.09.25 12:27:39 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\winlolx.exe
[2011.09.24 23:10:21 | 000,121,968 | ---- | C] () -- C:\WINDOWS\System32\x
[2011.09.24 17:10:46 | 000,064,684 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\nike aukro oran.jpg
[2011.09.20 20:37:36 | 000,057,871 | R--- | C] () -- C:\WINDOWS\System32\smsc.exe
[2011.09.18 18:53:14 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.09.18 18:44:47 | 001,081,344 | RHS- | C] () -- C:\WINDOWS\System32\xsycs.dll
[2011.05.12 18:37:08 | 000,263,680 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.05.12 18:37:08 | 000,105,984 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.05.12 18:37:08 | 000,099,328 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.05.12 18:37:08 | 000,087,580 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.05.12 18:37:08 | 000,075,264 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2010.05.30 16:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CorelDrw110.INI
[2010.05.16 20:10:10 | 000,000,622 | ---- | C] () -- C:\WINDOWS\DMN.INI
[2010.04.16 21:10:29 | 000,176,248 | ---- | C] () -- C:\WINDOWS\hpoins36.dat
[2010.04.16 21:10:29 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat
[2010.02.22 00:29:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\vypalovac.ini
[2010.01.02 20:31:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2010.01.02 14:07:36 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010.01.02 14:07:35 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010.01.02 14:07:35 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010.01.02 14:07:35 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010.01.02 14:07:35 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010.01.02 14:07:35 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010.01.02 14:07:35 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010.01.02 14:07:35 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010.01.02 14:07:35 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010.01.02 14:07:35 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010.01.02 14:07:35 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010.01.02 14:07:35 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010.01.02 14:07:35 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010.01.02 14:07:35 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010.01.02 14:07:35 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009.11.29 18:24:04 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009.11.12 14:48:58 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\StarOpen.sys
[2009.08.07 14:38:41 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2008.11.15 19:55:30 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez9066.dat
[2008.07.14 10:52:54 | 000,000,395 | ---- | C] () -- C:\WINDOWS\capella.ini
[2008.07.11 21:00:29 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008.01.16 18:09:46 | 000,467,968 | RHS- | C] () -- C:\WINDOWS\System32\qmsvlpi.exe
[2007.12.30 22:46:11 | 000,000,031 | ---- | C] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2007.12.30 22:43:58 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.30 22:43:58 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.29 20:01:13 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.08.21 19:21:14 | 000,000,036 | ---- | C] () -- C:\WINDOWS\CONTEXT.INI
[2007.08.21 19:20:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2007.08.19 20:21:56 | 000,000,041 | -H-- | C] () -- C:\WINDOWS\dsez6006.dat
[2007.04.21 10:21:06 | 000,000,948 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007.04.19 19:42:51 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\fusioncache.dat
[2007.03.02 22:49:20 | 000,000,058 | ---- | C] () -- C:\WINDOWS\FSaver.ini
[2007.02.17 19:32:19 | 000,001,459 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.17 19:31:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.15 17:18:21 | 000,000,463 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.01.26 22:46:44 | 000,006,378 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.01.26 22:35:45 | 000,610,304 | -H-- | C] () -- C:\WINDOWS\System32\dfxg115.dll
[2007.01.26 20:36:23 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2007.01.24 22:44:01 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2007.01.12 19:01:37 | 000,130,560 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.12.31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006.12.27 19:20:15 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.27 16:53:32 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006.12.27 16:33:49 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006.12.27 16:28:03 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.10.22 06:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 06:22:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006.10.22 06:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 06:22:00 | 001,347,584 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006.10.22 06:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 06:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 06:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 06:22:00 | 000,450,560 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006.10.22 06:22:00 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006.10.22 06:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 06:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2004.01.01 03:51:48 | 000,004,439 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.01.01 03:50:39 | 001,127,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.12.16 14:00:34 | 000,039,260 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002.12.16 13:58:52 | 000,022,337 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2002.09.20 18:19:36 | 000,001,740 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001.10.25 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 14:00:00 | 000,439,628 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 14:00:00 | 000,437,386 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 14:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 14:00:00 | 000,089,794 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 14:00:00 | 000,078,556 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 14:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 14:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001.08.07 05:16:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\OTS_UI.EXE
[1993.07.23 20:31:02 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
========== LOP Check ==========
[2011.05.17 15:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avg7
[2010.02.22 00:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.05.12 19:26:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2010.11.01 16:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.01.08 22:17:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MAGIX
[2011.05.12 19:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2008.07.11 21:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
[2007.11.04 13:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.03.02 18:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.05.16 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Yamaha
[2010.04.22 23:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\COWON
[2011.05.08 14:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\GetRightToGo
[2011.05.13 23:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\ICQ
[2007.05.22 07:18:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\COWON
[2007.05.22 06:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQLite
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2002.08.20 16:08:38 | 001,519,645 | ---- | M] (Microsoft Corporation)
"FreeCall" = "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized
"Start WingMan Profiler" =
"ctfmon.exe" = C:\WINDOWS\System32\ctfmon.exe -- [2002.09.20 18:05:18 | 000,020,480 | ---- | M] (Microsoft Corporation)
"mxClock" = C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe
"LClock" = C:\Program Files\LClock\lclock.exe
"ViStart" = C:\Program Files\ViStart\ViStart.exe
"ViOrb" = C:\Program Files\ViOrb\ViOrb.exe
"ICQ" = "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4 -- [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.)
"Windows LoL Layer" = qmsvlpi.exe -- [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] ()
"Windows Updates" = bqpldgv.exe
"windows updatess" = lsas.exe -- [2011.09.25 23:42:48 | 000,175,467 | ---- | M] ()
< MD5 for: ATAPI.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\drivers\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2002.09.20 18:05:14 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\cmdcons\autochk.exe
[2002.09.20 18:05:14 | 000,578,048 | -H-- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\WINDOWS\system32\autochk.exe
< MD5 for: CDROM.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2002.08.29 01:27:56 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CSRSS.EXE >
[2001.10.25 14:00:00 | 000,004,096 | ---- | M] (Microsoft Corporation) MD5=E5C52921CC7B099CEA19C53E31F4AB0E -- C:\WINDOWS\system32\csrss.exe
< MD5 for: EXPLORER.EXE >
[2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) MD5=2E83E5B8558D562031AF987BFDC78073 -- C:\WINDOWS\explorer.exe
[2002.09.20 18:05:24 | 001,401,856 | ---- | M] (Microsoft Corporation) MD5=F313FD11075A3CF7480EC77DD21C1FE4 -- C:\VTPFiles\explorer.exe
< MD5 for: LSASS.EXE >
[2002.09.20 18:05:32 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2002.08.29 02:09:26 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NTFS.SYS >
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\cmdcons\NTFS.SYS
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\WINDOWS\system32\drivers\ntfs.sys
< MD5 for: SCECLI.DLL >
[2002.09.20 18:04:42 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >
[2001.10.25 14:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=159D79FE3E22DCD5770AF0D08DDF9A07 -- C:\WINDOWS\system32\services.exe
< MD5 for: SMSS.EXE >
[2001.10.24 03:52:12 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=0B7569ECA93964A39BEDCF763E78E22A -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2002.09.20 18:05:44 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SPOOLSV.EXE >
[2001.10.25 14:00:00 | 000,058,368 | ---- | M] (Microsoft Corporation) MD5=3A5AF33B43267D051F9D23F9DAE95BAE -- C:\WINDOWS\system32\spoolsv.exe
< MD5 for: SVCHOST.EXE >
[2001.10.25 14:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=93A69214D0909E73BB2061DB9DB7F3E9 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2002.08.29 01:58:12 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2002.09.20 18:05:48 | 000,029,184 | ---- | M] (Microsoft Corporation) MD5=D7F9593829D41DEB324142D3B603E271 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2002.09.20 18:05:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\system32\winlogon.exe
< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.10.06 15:37:30 | 000,315,392 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2003.06.19 02:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\system32\drivers\*.sys /5 >
< %systemroot%\system32\drivers\*.sys /X >
[2001.10.25 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.01.27 09:12:47 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\system32\*.* /5 >
[2011.09.24 22:36:48 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2011.09.28 09:45:46 | 000,002,272 | ---- | M] () -- C:\WINDOWS\system32\eras.fon
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\WINDOWS\system32\lsas.exe
[2011.09.28 09:48:18 | 000,000,066 | ---- | M] () -- C:\WINDOWS\system32\o
[2011.09.25 12:09:26 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\system32\svchots.exe
[2011.09.28 09:48:25 | 000,462,848 | ---- | M] () -- C:\WINDOWS\system32\winlolx.exe
[2011.09.28 09:30:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2011.09.24 23:10:21 | 000,121,968 | ---- | M] () -- C:\WINDOWS\system32\x
< %systemroot%\system32\*.dll /lockedfiles >
[2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\xsycs.dll
< %systemroot%\system32\config\*.sav >
[2004.01.01 03:50:09 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004.01.01 03:50:09 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004.01.01 03:50:09 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Viti\Plocha
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
511,48 Mb Total Physical Memory | 149,16 Mb Available Physical Memory | 29,16% Memory free
1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,73% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 5,80 Gb Free Space | 15,58% Space Free | Partition Type: NTFS
Drive H: | 596,02 Gb Total Space | 316,53 Gb Free Space | 53,11% Space Free | Partition Type: FAT32
Computer Name: UNGIS-KFHKNNXQI | User Name: Viti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2011.09.28 14:13:48 | 000,590,336 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
PRC - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
PRC - [2011.09.10 23:47:28 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] () -- C:\WINDOWS\system32\qmsvlpi.exe
========== Modules (No Company Name) ==========
MOD - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
MOD - [2011.09.10 23:47:25 | 001,846,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.09.09 16:32:04 | 006,277,280 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
MOD - [2006.10.22 06:22:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2006.10.22 06:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2004.12.27 13:46:04 | 000,311,296 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2004.12.26 21:34:38 | 000,121,344 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] () -- C:\WINDOWS\system32\qmsvlpi.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (MSDisk)
SRV - [2011.09.21 22:01:51 | 000,057,871 | R--- | M] () [Auto | Running] -- C:\WINDOWS\System32\smsc.exe -- (PrtSmanm)
SRV - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.03.23 16:52:12 | 000,056,552 | ---- | M] (Eng. Usama El-Mokadem) [Auto | Stopped] -- C:\WINDOWS\System32\Startsrv.exe -- (SRVStarter_Service)
SRV - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.05.10 11:59:04 | 000,353,912 | ---- | M] (Protection Technology (StarForce)) [Auto | Stopped] -- C:\WINDOWS\System32\sfrem01.exe -- (sfrem01) SF FrontLine Drivers Auto Removal (v1)
SRV - [2005.11.17 16:18:52 | 001,536,092 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2002.12.17 18:26:22 | 007,528,529 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,320,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (xkevza)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (vhjqjqbt)
SRV - [2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (eybwi)
========== Driver Services (SafeList) ==========
DRV - [2009.11.12 14:48:58 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\StarOpen.sys -- (StarOpen)
DRV - [2009.08.04 13:09:42 | 000,018,560 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ymidusb.sys -- (YMIDUSB)
DRV - [2009.01.27 09:12:47 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.04.17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\regi.sys -- (regi)
DRV - [2007.03.15 22:07:14 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007.01.12 20:09:53 | 000,082,296 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2006.07.10 18:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2006.05.10 10:39:38 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.04.05 21:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.05 21:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.01.11 17:05:30 | 000,092,672 | ---- | M] (ALCATech) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL)
DRV - [2004.04.01 17:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002.11.18 17:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.08.29 02:32:44 | 000,009,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2002.06.20 19:45:44 | 000,013,920 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2002.06.20 19:45:42 | 000,020,128 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002.06.20 19:45:40 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2002.06.20 19:45:36 | 000,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2002.06.20 19:45:34 | 000,039,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2001.08.17 22:12:42 | 000,023,070 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [1997.12.23 02:00:00 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Viti\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_result ... r=1.3.1&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.0
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20101009
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.22
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.3.1&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.06.20 12:40:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.09.10 23:47:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.08 11:23:55 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.06.20 12:40:50 | 000,000,000 | ---D | M]
[2008.06.20 20:30:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Extensions
[2011.09.28 09:42:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Metal Lion - Vista) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (Qute) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2010.10.15 18:21:45 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2009.12.28 01:18:18 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2009.10.11 19:38:26 | 000,000,000 | ---D | M] (iFox Graphite) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{74b288e6-77b6-41c7-8138-bb81f4539689}
[2011.08.23 11:35:59 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (PimpZilla) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Blue Ice 2) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2011.09.10 23:47:39 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com
[2011.05.08 11:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\nostmp
[2011.09.28 09:42:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\staged
[2007.09.19 20:13:48 | 000,000,000 | ---D | M] ("VideoDownloader") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\videodowloader@videodownloader.net
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\defaults
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\chrome
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011.09.24 16:14:16 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-1.xml
[2009.06.15 15:32:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-10.xml
[2009.07.23 15:16:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-11.xml
[2009.08.04 20:40:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-12.xml
[2009.09.11 20:19:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-13.xml
[2009.10.29 10:16:06 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-14.xml
[2009.11.07 11:15:29 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-15.xml
[2009.12.17 15:19:50 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-16.xml
[2010.01.07 15:37:04 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-17.xml
[2010.02.19 19:11:40 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-18.xml
[2010.03.12 18:28:32 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-19.xml
[2008.10.01 17:09:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-2.xml
[2010.03.25 08:05:04 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-20.xml
[2010.04.03 23:01:11 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-21.xml
[2010.07.05 21:02:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-22.xml
[2010.07.23 13:46:37 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-23.xml
[2010.07.24 15:37:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-24.xml
[2010.09.12 18:11:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-25.xml
[2010.09.17 17:46:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-26.xml
[2010.10.22 23:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-27.xml
[2010.10.31 17:13:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-28.xml
[2010.11.01 16:32:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-29.xml
[2008.11.14 12:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-3.xml
[2011.03.02 00:33:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-30.xml
[2011.03.06 14:33:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-31.xml
[2011.03.24 21:06:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-32.xml
[2011.04.30 13:06:15 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-33.xml
[2011.05.08 11:24:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-34.xml
[2011.07.17 16:32:43 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-35.xml
[2011.08.28 08:24:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-36.xml
[2011.08.31 19:52:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-37.xml
[2011.09.10 23:48:21 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-38.xml
[2008.12.17 17:50:45 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-4.xml
[2009.02.08 12:49:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-5.xml
[2009.03.08 11:53:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-6.xml
[2009.03.29 12:51:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-7.xml
[2009.04.23 20:07:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-8.xml
[2009.04.28 19:03:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-9.xml
[2011.08.18 21:40:40 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.gif
[2011.08.18 21:40:40 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.src
[2010.06.21 17:35:24 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.xml
[2009.09.24 16:00:41 | 000,002,061 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\qipsearch.xml
[2011.09.17 23:14:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}
[2011.09.10 23:47:29 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.05.08 11:23:40 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.05.08 11:23:40 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.07.05 21:02:00 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.05.08 11:23:40 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.05.08 11:23:40 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.05.08 11:23:40 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011.09.28 09:37:19 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Viti\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O3 - HKLM\..\Toolbar: (&Rádio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKLM..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\.DEFAULT..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\S-1-5-18..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [FreeCall] "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [LClock] C:\Program Files\LClock\lclock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [mxClock] C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Start WingMan Profiler] File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows Updates] bqpldgv.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKU\S-1-5-18..\RunOnce: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\qmsvlpi.exe ()
O4 - HKLM..\RunServices: [windows updatess] C:\WINDOWS\System32\lsas.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 67108863
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O15 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.12.27 16:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.09.20 18:04:04 | 000,095,034 | RHS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\...exe [@ = exefile] -- "%1" %*
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
Drivers32: midi2 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2011.09.28 14:14:12 | 000,590,336 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
[2011.09.28 09:35:18 | 000,000,000 | ---D | C] -- C:\_OTM
[2011.09.28 09:34:40 | 000,530,944 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTM.exe
[2011.09.28 09:33:04 | 000,297,472 | ---- | C] (SteelWerX) -- C:\swreg.exe
[2011.09.25 12:09:21 | 000,150,528 | ---- | C] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
========== Files - Modified Within 7 Days ==========
[2011.09.28 14:20:14 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.09.28 14:13:48 | 000,590,336 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
[2011.09.28 13:01:52 | 001,935,622 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\nike final male samolepky.cdr
[2011.09.28 12:03:39 | 000,002,507 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\CorelDRAW 11.lnk
[2011.09.28 11:58:38 | 004,799,314 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\NIKE LETAK FINAL.cdr
[2011.09.28 11:53:55 | 003,674,582 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\Záloha_NIKE LETAK FINAL.cdr
[2011.09.28 09:48:25 | 000,462,848 | ---- | M] () -- C:\WINDOWS\System32\winlolx.exe
[2011.09.28 09:48:18 | 000,000,066 | ---- | M] () -- C:\WINDOWS\System32\o
[2011.09.28 09:45:46 | 000,002,272 | ---- | M] () -- C:\WINDOWS\System32\eras.fon
[2011.09.28 09:37:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.09.28 09:34:23 | 000,530,944 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTM.exe
[2011.09.28 09:33:46 | 000,000,177 | ---- | M] () -- C:\reset.bat
[2011.09.28 09:30:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\scanonline.exe
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\WINDOWS\System32\lsas.exe
[2011.09.25 12:33:02 | 000,297,472 | ---- | M] (SteelWerX) -- C:\swreg.exe
[2011.09.25 12:09:26 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\System32\svchots.exe
[2011.09.24 23:10:21 | 000,121,968 | ---- | M] () -- C:\WINDOWS\System32\x
[2011.09.24 22:36:48 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.09.24 17:10:53 | 000,064,684 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\nike aukro oran.jpg
[2011.09.21 22:06:49 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.09.21 22:01:51 | 000,057,871 | R--- | M] () -- C:\WINDOWS\System32\smsc.exe
========== Files Created - No Company Name ==========
[2011.09.28 13:01:51 | 001,935,622 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\nike final male samolepky.cdr
[2011.09.28 11:53:54 | 003,674,582 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\Záloha_NIKE LETAK FINAL.cdr
[2011.09.28 11:47:39 | 004,799,314 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\NIKE LETAK FINAL.cdr
[2011.09.28 09:33:46 | 000,000,177 | ---- | C] () -- C:\reset.bat
[2011.09.25 23:42:52 | 000,175,467 | ---- | C] () -- C:\WINDOWS\System32\lsas.exe
[2011.09.25 23:42:47 | 000,175,467 | ---- | C] () -- C:\scanonline.exe
[2011.09.25 12:27:39 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\winlolx.exe
[2011.09.24 23:10:21 | 000,121,968 | ---- | C] () -- C:\WINDOWS\System32\x
[2011.09.24 17:10:46 | 000,064,684 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\nike aukro oran.jpg
[2011.09.20 20:37:36 | 000,057,871 | R--- | C] () -- C:\WINDOWS\System32\smsc.exe
[2011.09.18 18:53:14 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.09.18 18:44:47 | 001,081,344 | RHS- | C] () -- C:\WINDOWS\System32\xsycs.dll
[2011.05.12 18:37:08 | 000,263,680 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.05.12 18:37:08 | 000,105,984 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.05.12 18:37:08 | 000,099,328 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.05.12 18:37:08 | 000,087,580 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.05.12 18:37:08 | 000,075,264 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2010.05.30 16:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CorelDrw110.INI
[2010.05.16 20:10:10 | 000,000,622 | ---- | C] () -- C:\WINDOWS\DMN.INI
[2010.04.16 21:10:29 | 000,176,248 | ---- | C] () -- C:\WINDOWS\hpoins36.dat
[2010.04.16 21:10:29 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat
[2010.02.22 00:29:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\vypalovac.ini
[2010.01.02 20:31:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2010.01.02 14:07:36 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010.01.02 14:07:35 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010.01.02 14:07:35 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010.01.02 14:07:35 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010.01.02 14:07:35 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010.01.02 14:07:35 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010.01.02 14:07:35 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010.01.02 14:07:35 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010.01.02 14:07:35 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010.01.02 14:07:35 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010.01.02 14:07:35 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010.01.02 14:07:35 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010.01.02 14:07:35 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010.01.02 14:07:35 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010.01.02 14:07:35 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009.11.29 18:24:04 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009.11.12 14:48:58 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\StarOpen.sys
[2009.08.07 14:38:41 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2008.11.15 19:55:30 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez9066.dat
[2008.07.14 10:52:54 | 000,000,395 | ---- | C] () -- C:\WINDOWS\capella.ini
[2008.07.11 21:00:29 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008.01.16 18:09:46 | 000,467,968 | RHS- | C] () -- C:\WINDOWS\System32\qmsvlpi.exe
[2007.12.30 22:46:11 | 000,000,031 | ---- | C] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2007.12.30 22:43:58 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.30 22:43:58 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.29 20:01:13 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.08.21 19:21:14 | 000,000,036 | ---- | C] () -- C:\WINDOWS\CONTEXT.INI
[2007.08.21 19:20:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2007.08.19 20:21:56 | 000,000,041 | -H-- | C] () -- C:\WINDOWS\dsez6006.dat
[2007.04.21 10:21:06 | 000,000,948 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007.04.19 19:42:51 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\fusioncache.dat
[2007.03.02 22:49:20 | 000,000,058 | ---- | C] () -- C:\WINDOWS\FSaver.ini
[2007.02.17 19:32:19 | 000,001,459 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.17 19:31:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.15 17:18:21 | 000,000,463 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.01.26 22:46:44 | 000,006,378 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.01.26 22:35:45 | 000,610,304 | -H-- | C] () -- C:\WINDOWS\System32\dfxg115.dll
[2007.01.26 20:36:23 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2007.01.24 22:44:01 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2007.01.12 19:01:37 | 000,130,560 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.12.31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006.12.27 19:20:15 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.27 16:53:32 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006.12.27 16:33:49 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006.12.27 16:28:03 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.10.22 06:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 06:22:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006.10.22 06:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 06:22:00 | 001,347,584 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006.10.22 06:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 06:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 06:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 06:22:00 | 000,450,560 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006.10.22 06:22:00 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006.10.22 06:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 06:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2004.01.01 03:51:48 | 000,004,439 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.01.01 03:50:39 | 001,127,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.12.16 14:00:34 | 000,039,260 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002.12.16 13:58:52 | 000,022,337 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2002.09.20 18:19:36 | 000,001,740 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001.10.25 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 14:00:00 | 000,439,628 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 14:00:00 | 000,437,386 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 14:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 14:00:00 | 000,089,794 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 14:00:00 | 000,078,556 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 14:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 14:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001.08.07 05:16:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\OTS_UI.EXE
[1993.07.23 20:31:02 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
========== LOP Check ==========
[2011.05.17 15:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avg7
[2010.02.22 00:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.05.12 19:26:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2010.11.01 16:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.01.08 22:17:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MAGIX
[2011.05.12 19:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2008.07.11 21:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
[2007.11.04 13:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.03.02 18:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.05.16 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Yamaha
[2010.04.22 23:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\COWON
[2011.05.08 14:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\GetRightToGo
[2011.05.13 23:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\ICQ
[2007.05.22 07:18:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\COWON
[2007.05.22 06:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQLite
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2002.08.20 16:08:38 | 001,519,645 | ---- | M] (Microsoft Corporation)
"FreeCall" = "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized
"Start WingMan Profiler" =
"ctfmon.exe" = C:\WINDOWS\System32\ctfmon.exe -- [2002.09.20 18:05:18 | 000,020,480 | ---- | M] (Microsoft Corporation)
"mxClock" = C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe
"LClock" = C:\Program Files\LClock\lclock.exe
"ViStart" = C:\Program Files\ViStart\ViStart.exe
"ViOrb" = C:\Program Files\ViOrb\ViOrb.exe
"ICQ" = "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4 -- [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.)
"Windows LoL Layer" = qmsvlpi.exe -- [2002.09.20 18:05:24 | 000,467,968 | RHS- | M] ()
"Windows Updates" = bqpldgv.exe
"windows updatess" = lsas.exe -- [2011.09.25 23:42:48 | 000,175,467 | ---- | M] ()
< MD5 for: ATAPI.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\drivers\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2002.09.20 18:05:14 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\cmdcons\autochk.exe
[2002.09.20 18:05:14 | 000,578,048 | -H-- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\WINDOWS\system32\autochk.exe
< MD5 for: CDROM.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2002.08.29 01:27:56 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CSRSS.EXE >
[2001.10.25 14:00:00 | 000,004,096 | ---- | M] (Microsoft Corporation) MD5=E5C52921CC7B099CEA19C53E31F4AB0E -- C:\WINDOWS\system32\csrss.exe
< MD5 for: EXPLORER.EXE >
[2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) MD5=2E83E5B8558D562031AF987BFDC78073 -- C:\WINDOWS\explorer.exe
[2002.09.20 18:05:24 | 001,401,856 | ---- | M] (Microsoft Corporation) MD5=F313FD11075A3CF7480EC77DD21C1FE4 -- C:\VTPFiles\explorer.exe
< MD5 for: LSASS.EXE >
[2002.09.20 18:05:32 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2002.08.29 02:09:26 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NTFS.SYS >
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\cmdcons\NTFS.SYS
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\WINDOWS\system32\drivers\ntfs.sys
< MD5 for: SCECLI.DLL >
[2002.09.20 18:04:42 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >
[2001.10.25 14:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=159D79FE3E22DCD5770AF0D08DDF9A07 -- C:\WINDOWS\system32\services.exe
< MD5 for: SMSS.EXE >
[2001.10.24 03:52:12 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=0B7569ECA93964A39BEDCF763E78E22A -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2002.09.20 18:05:44 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SPOOLSV.EXE >
[2001.10.25 14:00:00 | 000,058,368 | ---- | M] (Microsoft Corporation) MD5=3A5AF33B43267D051F9D23F9DAE95BAE -- C:\WINDOWS\system32\spoolsv.exe
< MD5 for: SVCHOST.EXE >
[2001.10.25 14:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=93A69214D0909E73BB2061DB9DB7F3E9 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2002.08.29 01:58:12 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2002.09.20 18:05:48 | 000,029,184 | ---- | M] (Microsoft Corporation) MD5=D7F9593829D41DEB324142D3B603E271 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2002.09.20 18:05:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\system32\winlogon.exe
< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.10.06 15:37:30 | 000,315,392 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2003.06.19 02:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\system32\drivers\*.sys /5 >
< %systemroot%\system32\drivers\*.sys /X >
[2001.10.25 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.01.27 09:12:47 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\system32\*.* /5 >
[2011.09.24 22:36:48 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2011.09.28 09:45:46 | 000,002,272 | ---- | M] () -- C:\WINDOWS\system32\eras.fon
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\WINDOWS\system32\lsas.exe
[2011.09.28 09:48:18 | 000,000,066 | ---- | M] () -- C:\WINDOWS\system32\o
[2011.09.25 12:09:26 | 000,150,528 | ---- | M] (OldMan's Tales) -- C:\WINDOWS\system32\svchots.exe
[2011.09.28 09:48:25 | 000,462,848 | ---- | M] () -- C:\WINDOWS\system32\winlolx.exe
[2011.09.28 09:30:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2011.09.24 23:10:21 | 000,121,968 | ---- | M] () -- C:\WINDOWS\system32\x
< %systemroot%\system32\*.dll /lockedfiles >
[2002.09.20 18:04:04 | 001,081,344 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\xsycs.dll
< %systemroot%\system32\config\*.sav >
[2004.01.01 03:50:09 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004.01.01 03:50:09 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004.01.01 03:50:09 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
Re: Neskutečně zasekané a spomalené PC
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\*.* /U /s >
[8 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]
[11 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[1 C:\WINDOWS\PCHealth\HelpCtr\Binaries\*.tmp files -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\*.tmp -> ]
< %systemroot%\*. /mp /s >
< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2011.05.12 18:36:44 | 000,012,576 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2007.12.29 20:01:13 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2011.09.17 17:32:53 | 000,006,476 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\hpzinstall.log
[2009.09.03 19:39:23 | 000,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\KGyGaAvL.sys
< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758059181\thlkczve.exe
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060725\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060903\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1189700787495\thlkczve.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758059181\sjrshrre.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060725\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060903\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1189700787495\sjrshrre.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\snrjlbjn.exe
[2011.09.07 00:40:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758059181\eevjjlll.exe
[2011.09.07 00:40:51 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060725\eevjjlll.exe
[2011.09.07 00:40:53 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060903\eevjjlll.exe
[2011.09.07 00:40:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1189700787495\eevjjlll.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758059181\ljrkvtwh.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060725\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060903\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1189700787495\ljrkvtwh.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758059181\brwrlskz.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060725\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060903\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1189700787495\brwrlskz.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758059181\hnrhllzh.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060725\hnrhllzh.exe
[2011.09.07 00:41:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060903\hnrhllzh.exe
[2011.09.07 00:41:02 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1189700787495\hnrhllzh.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\cbrkrrqh.exe
[2011.09.07 00:41:17 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ejjkrtsn.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\etskskkb.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ewkknejq.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\hetqxlxk.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\nnteklcs.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\srewjcqe.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\thncexre.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\xnrzjqkk.exe
[2011.09.07 00:41:13 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\lwjsbskq.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\nxrvjrhs.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\srehhqvr.exe
[2011.09.07 00:41:23 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ICQ\ICQNewTab\lhnllvjb.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\jehckswh.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\wthhxtzs.exe
[2011.09.21 22:06:30 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Data Aplikací\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
[2007.01.14 19:39:39 | 005,535,448 | ---- | M] (InstallShield Software Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\CT4SkypePlugin10_Multi_Lite.exe
[2007.01.14 19:39:39 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\RLLauncher.exe
[2007.01.14 19:42:07 | 001,371,136 | ---- | M] (EasyBits Software Corp.) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F35E193DC3E84933B83DE961D9AC33BF\SketchPad.exe
[2011.09.07 00:41:38 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\kxllttje.exe
< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >
< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >
< %APPDATA%\*. >
[2011.09.17 23:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Adobe
[2007.01.13 18:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AdobeUM
[2007.01.31 22:36:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Apple Computer
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2009.06.21 18:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AVG8
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2010.03.12 18:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Corel
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2007.01.13 18:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Google
[2007.03.16 22:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Hamachi
[2007.02.15 17:37:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Help
[2010.06.20 12:44:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HP
[2011.09.17 22:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HPAppData
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2006.12.27 16:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Identities
[2009.07.01 14:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield
[2007.02.16 22:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield Installation Information
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2011.05.12 19:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Lavasoft
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2007.08.18 18:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Macromedia
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2011.09.16 21:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Malwarebytes
[2008.11.22 12:24:01 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Viti\Data aplikací\Microsoft
[2008.06.20 20:30:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Mozilla
[2007.07.30 15:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MSN6
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2010.01.07 16:27:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Real
[2007.01.14 19:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Reallusion
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2009.09.25 20:10:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Skype
[2009.09.25 20:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\skypePM
[2007.01.26 22:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sonic Foundry
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2007.07.16 13:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sun
[2007.03.24 19:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\teamspeak2
[2010.05.04 21:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\U3
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner
< *crack* /s >
[2010.05.17 16:55:47 | 000,016,743 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\FL.Studio.9.XXL.mit.Crack.und.VSTi.Cracks.torrent
[2010.05.19 12:22:12 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack.torrent
[2010.05.19 12:22:34 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack[0].torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack.torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack[0].torrent
[2007.02.17 13:17:32 | 001,059,939 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Texty\GrandTheftAutoViceCity - CRACK.rar
[2008.08.27 10:46:18 | 000,000,310 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crack.bat
[2008.08.27 10:46:18 | 000,000,327 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crackTS.bat
[1999.06.11 20:18:36 | 000,092,827 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 18:31:34 | 000,016,068 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 19:15:38 | 000,010,560 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2001.07.10 11:03:00 | 000,028,276 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackerc.wmf
[2001.07.10 11:02:18 | 000,032,558 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackers.wmf
[1995.07.03 18:24:04 | 000,125,094 | ---- | M] () -- \WINDOWS\Fonts\Newcrack.ttf
[11 \WINDOWS\Fonts\*.tmp files -> \WINDOWS\Fonts\*.tmp -> ]
< *keygen* /s >
[2007.08.09 16:54:17 | 381,145,088 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen.iso
< %APPDATA%\*.* >
[2011.08.07 18:04:40 | 000,000,031 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2011.08.23 08:52:05 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Bh8HEGhGffH2.txJgIfiKafIij1.txt
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Viti\Data aplikací\desktop.ini
< %APPDATA%\*.exe /s >
[2011.09.07 00:52:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\xthzqbbn.exe
[2011.09.07 00:52:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\xthzqbbn.exe
[2011.09.07 00:52:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\xthzqbbn.exe
[2011.09.07 00:52:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\ntjlbqlw.exe
[2011.09.07 00:52:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1218560040918\nvnhsscj.exe
[2011.09.07 00:52:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758059181\ntbttzcq.exe
[2011.09.07 00:53:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060725\ntbttzcq.exe
[2011.09.07 00:53:05 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060903\ntbttzcq.exe
[2011.09.07 00:53:22 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1189700787495\swntnjqb.exe
[2011.09.07 00:53:24 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1218560040918\snenqhhb.exe
[2011.09.07 00:53:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\COWON\JetAudio\hhxzkcse.exe
[2010.03.31 19:20:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Viti\Data aplikací\Facebook\uninstall.exe
[2010.05.16 19:55:56 | 000,004,286 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{271A659B-A7D3-405E-AE31-3086133BE0B7}\ARPPRODUCTICON.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_28b42f11.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3344702d.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3a4d46e7.exe
[2008.11.22 12:24:01 | 000,000,478 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_49c45178.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_4e244cd.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_54f16447.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6038279.exe
[2008.11.22 12:24:01 | 000,000,894 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6ca2753e.exe
[2011.09.08 22:19:11 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\jqtjbrqc.exe
[2007.11.04 13:05:46 | 023,510,720 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\09063B41-0916-4360-A80D-0C2A2B89D300\dotnetfx.exe
[2007.11.04 13:05:04 | 002,585,872 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\CF356349-4782-4F9D-AE42-7E3C6AD74B9C\WindowsInstaller-KB893803-v2-x86.exe
[2006.12.14 10:00:02 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\cleanup.exe
[2007.02.12 17:46:54 | 003,104,768 | -H-- | M] (SanDisk Corporation) -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\Launchpad Removal.exe
[2011.09.08 22:19:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Uniblue\Registry Booster2\sqhvzklx.exe
< %SYSTEMDRIVE%\*.exe >
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\scanonline.exe
[2011.08.28 21:43:29 | 000,921,805 | ---- | M] (instyler installation software) -- C:\Setup.exe
[2011.09.25 12:33:02 | 000,297,472 | ---- | M] (SteelWerX) -- C:\swreg.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces >
< sTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\ProgID\\: MSTIME.TIMEMotionAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\VersionIndependentProgID\\: MSTIME.TIMEMotionAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\ProgID\\: MSTIME.SMILAnimCompSiteFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\VersionIndependentProgID\\: MSTIME.SMILAnimCompSiteFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\ProgID\\: MSTIME.TIMEFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\VersionIndependentProgID\\: MSTIME.TIMEFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\ProgID\\: MSTIME.SMILAnimDefaultCompFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\VersionIndependentProgID\\: MSTIME.SMILAnimDefaultCompFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\ProgID\\: MSTIME.TIMEColorAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\VersionIndependentProgID\\: MSTIME.TIMEColorAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A951B11A-C712-45B3-B884-2469A6243368}\InProcServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\ProgID\\: MSTIME.TIMESetAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\VersionIndependentProgID\\: MSTIME.TIMESetAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\ProgID\\: MSTIME.TIMEFilterAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\VersionIndependentProgID\\: MSTIME.TIMEFilterAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\ProgID\\: MSTIME.TIMEAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\VersionIndependentProgID\\: MSTIME.TIMEAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2F5A901-4080-11D1-A3AC-00C04FB950DC}\\: IADsTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\\: MSTIME [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\0\win32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\\ProcessTimeOut: 3600
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\\LeaseTerminatesTime: 1317220028
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\Parameters\Tcpip\\LeaseTerminatesTime: 1317220028
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar\Settings\General\\LastUpdateGamesTime: 1304845938
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %fystemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %fystemRoot%\System32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:58B11540
< End of report >
< %systemroot%\*.* /U /s >
[8 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]
[11 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[1 C:\WINDOWS\PCHealth\HelpCtr\Binaries\*.tmp files -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\*.tmp -> ]
< %systemroot%\*. /mp /s >
< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2011.05.12 18:36:44 | 000,012,576 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2007.12.29 20:01:13 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2011.09.17 17:32:53 | 000,006,476 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\hpzinstall.log
[2009.09.03 19:39:23 | 000,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\KGyGaAvL.sys
< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758059181\thlkczve.exe
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060725\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060903\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1189700787495\thlkczve.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758059181\sjrshrre.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060725\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060903\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1189700787495\sjrshrre.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\snrjlbjn.exe
[2011.09.07 00:40:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758059181\eevjjlll.exe
[2011.09.07 00:40:51 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060725\eevjjlll.exe
[2011.09.07 00:40:53 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060903\eevjjlll.exe
[2011.09.07 00:40:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1189700787495\eevjjlll.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758059181\ljrkvtwh.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060725\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060903\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1189700787495\ljrkvtwh.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758059181\brwrlskz.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060725\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060903\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1189700787495\brwrlskz.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758059181\hnrhllzh.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060725\hnrhllzh.exe
[2011.09.07 00:41:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060903\hnrhllzh.exe
[2011.09.07 00:41:02 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1189700787495\hnrhllzh.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\cbrkrrqh.exe
[2011.09.07 00:41:17 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ejjkrtsn.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\etskskkb.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ewkknejq.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\hetqxlxk.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\nnteklcs.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\srewjcqe.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\thncexre.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\xnrzjqkk.exe
[2011.09.07 00:41:13 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\lwjsbskq.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\nxrvjrhs.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\srehhqvr.exe
[2011.09.07 00:41:23 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ICQ\ICQNewTab\lhnllvjb.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\jehckswh.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\wthhxtzs.exe
[2011.09.21 22:06:30 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Data Aplikací\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
[2007.01.14 19:39:39 | 005,535,448 | ---- | M] (InstallShield Software Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\CT4SkypePlugin10_Multi_Lite.exe
[2007.01.14 19:39:39 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\RLLauncher.exe
[2007.01.14 19:42:07 | 001,371,136 | ---- | M] (EasyBits Software Corp.) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F35E193DC3E84933B83DE961D9AC33BF\SketchPad.exe
[2011.09.07 00:41:38 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\kxllttje.exe
< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >
< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >
< %APPDATA%\*. >
[2011.09.17 23:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Adobe
[2007.01.13 18:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AdobeUM
[2007.01.31 22:36:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Apple Computer
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2009.06.21 18:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AVG8
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2010.03.12 18:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Corel
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2007.01.13 18:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Google
[2007.03.16 22:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Hamachi
[2007.02.15 17:37:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Help
[2010.06.20 12:44:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HP
[2011.09.17 22:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HPAppData
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2006.12.27 16:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Identities
[2009.07.01 14:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield
[2007.02.16 22:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield Installation Information
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2011.05.12 19:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Lavasoft
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2007.08.18 18:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Macromedia
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2011.09.16 21:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Malwarebytes
[2008.11.22 12:24:01 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Viti\Data aplikací\Microsoft
[2008.06.20 20:30:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Mozilla
[2007.07.30 15:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MSN6
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2010.01.07 16:27:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Real
[2007.01.14 19:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Reallusion
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2009.09.25 20:10:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Skype
[2009.09.25 20:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\skypePM
[2007.01.26 22:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sonic Foundry
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2007.07.16 13:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sun
[2007.03.24 19:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\teamspeak2
[2010.05.04 21:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\U3
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner
< *crack* /s >
[2010.05.17 16:55:47 | 000,016,743 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\FL.Studio.9.XXL.mit.Crack.und.VSTi.Cracks.torrent
[2010.05.19 12:22:12 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack.torrent
[2010.05.19 12:22:34 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack[0].torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack.torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack[0].torrent
[2007.02.17 13:17:32 | 001,059,939 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Texty\GrandTheftAutoViceCity - CRACK.rar
[2008.08.27 10:46:18 | 000,000,310 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crack.bat
[2008.08.27 10:46:18 | 000,000,327 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crackTS.bat
[1999.06.11 20:18:36 | 000,092,827 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 18:31:34 | 000,016,068 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 19:15:38 | 000,010,560 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2001.07.10 11:03:00 | 000,028,276 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackerc.wmf
[2001.07.10 11:02:18 | 000,032,558 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackers.wmf
[1995.07.03 18:24:04 | 000,125,094 | ---- | M] () -- \WINDOWS\Fonts\Newcrack.ttf
[11 \WINDOWS\Fonts\*.tmp files -> \WINDOWS\Fonts\*.tmp -> ]
< *keygen* /s >
[2007.08.09 16:54:17 | 381,145,088 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen.iso
< %APPDATA%\*.* >
[2011.08.07 18:04:40 | 000,000,031 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2011.08.23 08:52:05 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Bh8HEGhGffH2.txJgIfiKafIij1.txt
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Viti\Data aplikací\desktop.ini
< %APPDATA%\*.exe /s >
[2011.09.07 00:52:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\xthzqbbn.exe
[2011.09.07 00:52:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\xthzqbbn.exe
[2011.09.07 00:52:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\xthzqbbn.exe
[2011.09.07 00:52:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\ntjlbqlw.exe
[2011.09.07 00:52:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1218560040918\nvnhsscj.exe
[2011.09.07 00:52:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758059181\ntbttzcq.exe
[2011.09.07 00:53:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060725\ntbttzcq.exe
[2011.09.07 00:53:05 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060903\ntbttzcq.exe
[2011.09.07 00:53:22 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1189700787495\swntnjqb.exe
[2011.09.07 00:53:24 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1218560040918\snenqhhb.exe
[2011.09.07 00:53:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\COWON\JetAudio\hhxzkcse.exe
[2010.03.31 19:20:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Viti\Data aplikací\Facebook\uninstall.exe
[2010.05.16 19:55:56 | 000,004,286 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{271A659B-A7D3-405E-AE31-3086133BE0B7}\ARPPRODUCTICON.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_28b42f11.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3344702d.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3a4d46e7.exe
[2008.11.22 12:24:01 | 000,000,478 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_49c45178.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_4e244cd.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_54f16447.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6038279.exe
[2008.11.22 12:24:01 | 000,000,894 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6ca2753e.exe
[2011.09.08 22:19:11 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\jqtjbrqc.exe
[2007.11.04 13:05:46 | 023,510,720 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\09063B41-0916-4360-A80D-0C2A2B89D300\dotnetfx.exe
[2007.11.04 13:05:04 | 002,585,872 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\CF356349-4782-4F9D-AE42-7E3C6AD74B9C\WindowsInstaller-KB893803-v2-x86.exe
[2006.12.14 10:00:02 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\cleanup.exe
[2007.02.12 17:46:54 | 003,104,768 | -H-- | M] (SanDisk Corporation) -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\Launchpad Removal.exe
[2011.09.08 22:19:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Uniblue\Registry Booster2\sqhvzklx.exe
< %SYSTEMDRIVE%\*.exe >
[2011.09.25 23:42:48 | 000,175,467 | ---- | M] () -- C:\scanonline.exe
[2011.08.28 21:43:29 | 000,921,805 | ---- | M] (instyler installation software) -- C:\Setup.exe
[2011.09.25 12:33:02 | 000,297,472 | ---- | M] (SteelWerX) -- C:\swreg.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces >
< sTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\ProgID\\: MSTIME.TIMEMotionAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\VersionIndependentProgID\\: MSTIME.TIMEMotionAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\ProgID\\: MSTIME.SMILAnimCompSiteFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\VersionIndependentProgID\\: MSTIME.SMILAnimCompSiteFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\ProgID\\: MSTIME.TIMEFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\VersionIndependentProgID\\: MSTIME.TIMEFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\ProgID\\: MSTIME.SMILAnimDefaultCompFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\VersionIndependentProgID\\: MSTIME.SMILAnimDefaultCompFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\ProgID\\: MSTIME.TIMEColorAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\VersionIndependentProgID\\: MSTIME.TIMEColorAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A951B11A-C712-45B3-B884-2469A6243368}\InProcServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\ProgID\\: MSTIME.TIMESetAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\VersionIndependentProgID\\: MSTIME.TIMESetAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\ProgID\\: MSTIME.TIMEFilterAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\VersionIndependentProgID\\: MSTIME.TIMEFilterAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\ProgID\\: MSTIME.TIMEAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\VersionIndependentProgID\\: MSTIME.TIMEAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2F5A901-4080-11D1-A3AC-00C04FB950DC}\\: IADsTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\\: MSTIME [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\0\win32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\\ProcessTimeOut: 3600
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\\LeaseTerminatesTime: 1317220028
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\Parameters\Tcpip\\LeaseTerminatesTime: 1317220028
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar\Settings\General\\LastUpdateGamesTime: 1304845938
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %fystemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %fystemRoot%\System32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:58B11540
< End of report >
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Program nepoužívejte bez doporučení Rádce a pozorně se řiďte následujících pokynu,protože program netoleruje chyby a může dojít k úplnému poškození systému!!
Pokud nepůjde normálně,tak zkuste v nouzovém režimu..
Stáhneme si Combofix
- Program uložíme nejlépe na Plochu
- Vypneme všechny rezidentní štíty.Jak antiviru,tak antispywaru a firewallu
- Vypneme všechny běžící aplikace (ICQ,prohlížeč,programy) a necháme pouze Combofix
- Spustíme Combofix.exe s administrátorským oprávněním
U Windows XP se přihlásíme pod účtem správce
Ve Windows 7 a Vista klikněte pravým tlačítkem myši na Combofix.exe a dejte ,,Spustit jako správce,,) - Hned po startu programu na vás vyskočí licenční podmínky,tak potvrdíme tlačítkemANO
- Pokud vám Combofix nabídne instalaci Konzoly pro zotavení,tak souhlaste a nechte nainstalovat(zde je potřeba aktivní připojení na internet)
- Pokračujte dle pokynů programu a během skenování na nic neklikejte,na pc nepracujte(ICQ,jiné aplikace,internet..).Nechte počítač v klidu.
- Celý sken tvá mezi 5-15 min,ale pokud je v PC hodně havěti,tak se čas může lišit.
- Po skončení skenování(případném restartu počítače) se vám zobrazí log z Combofixu,který mi vložte sem(Kdyby se log nezobrazil,tak jej najdete zde: C:\ComboFix.txt
- (Pokud si nevíte rady s kterýmkoliv z výše uvedených kroků,tak se ptejte nebo mrkněte na detailnější návod včetně obrázků http://www.bleepingcomputer.com/combofi ... t-combofix )
Pokud nepůjde normálně,tak zkuste v nouzovém režimu..

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Neskutečně zasekané a spomalené PC
Opět vyskočila chyba:
!! VAROVÁNÍ !! Není bezpečné dále pokračovat!
Obsah a součásti Combofixu byly narušeny.
Stáhněte si prosím novou kopii z:
http://www.bleepingcomputer.com/combofi ... e-combofix
Poznámka: Můžete být infikováni parazitickým souborovým virem (typicky: Virut)
Zkoušel jsem to v normálním i v nouzovém režimu..
!! VAROVÁNÍ !! Není bezpečné dále pokračovat!
Obsah a součásti Combofixu byly narušeny.
Stáhněte si prosím novou kopii z:
http://www.bleepingcomputer.com/combofi ... e-combofix
Poznámka: Můžete být infikováni parazitickým souborovým virem (typicky: Virut)
Zkoušel jsem to v normálním i v nouzovém režimu..

- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Neskutečně zasekané a spomalené PC
Krucipísek...nějaká mrcha nám blokuje Combofix a taky opravu těch aktualizací..mrkneme,zda nemáme rootkit a když ne,tak dočistíme přes OTL 
Stáhněte si TDSSKiller


- Spuste program a klikněte na Start Scan
- Pokud program najde infikekci,tak ji bude lecit (Cure), povolte léčení kliknutím na tlačítko Continue
- Pokud program najde podezrely soubor (suspicious),bude ho chtít přeskočit (Skip), povolte přeskočení kliknutim na tlačítko Continue
- Po dokončení skenování bude možná potřeba restartovat počítač,ten povolíte programu kliknutím na tlačítko Reboot now
- Po restartování počítače na vás vyskočí log(pokud se tak nestane,tak ho najdete na disku,kde máte nainstalovaná systém s názvem TDSSKiller.xxxx_log.txt) a vložte mi sem jeho obsah
- Pokud nebude program požadovat restartování počítače,klikněte na tlačítko Close a následně na Report , čímž se Vám vytvoří log a jeho obsah mu sem vložte
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2