Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Neskutečně zasekané a spomalené PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#76 Příspěvek od chodnik74 »

Zkusíme nyní Combofix,snad nám už půjde :)


:arrow: Stáhněte Rkill z jednoho odkazu,kdyby nešel spustit první,tak zkuste další(havěť někdy blokuje spuštění určitých typů souborů)

Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe

Rkill COM:
http://download.bleepingcomputer.com/grinler/rkill.com

Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr

Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif

Nyní nerestartujte PC!


Program nepoužívejte bez doporučení Rádce a pozorně se řiďte následujících pokynu,protože program netoleruje chyby a může dojít k úplnému poškození systému!!
  • :arrow: Stáhneme si Combofix Obrázek
  • Program uložíme nejlépe na Plochu
  • Vypneme všechny rezidentní štíty.Jak antiviru,tak antispywaru a firewallu
  • Vypneme všechny běžící aplikace (ICQ,prohlížeč,programy) a necháme pouze Combofix
  • Spustíme Combofix.exe s administrátorským oprávněním
    U Windows XP se přihlásíme pod účtem správce
    Ve Windows 7 a Vista klikněte pravým tlačítkem myši na Combofix.exe a dejte ,,Spustit jako správce,,)
  • Hned po startu programu na vás vyskočí licenční podmínky,tak potvrdíme tlačítkemANO
  • Pokud vám Combofix nabídne instalaci Konzoly pro zotavení,tak souhlaste a nechte nainstalovat(zde je potřeba aktivní připojení na internet)
  • Pokračujte dle pokynů programu a během skenování na nic neklikejte,na pc nepracujte(ICQ,jiné aplikace,internet..).Nechte počítač v klidu.
  • Celý sken tvá mezi 5-15 min,ale pokud je v PC hodně havěti,tak se čas může lišit.
  • Po skončení skenování(případném restartu počítače) se vám zobrazí log z Combofixu,který mi vložte sem(Kdyby se log nezobrazil,tak jej najdete zde: C:\ComboFix.txt
  • (Pokud si nevíte rady s kterýmkoliv z výše uvedených kroků,tak se ptejte nebo mrkněte na detailnější návod včetně obrázků http://www.bleepingcomputer.com/combofi ... t-combofix )
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#77 Příspěvek od WiZARD_ »

Stále vyskakuje ta samá tabulka... Co s tím programem RKill? :?:

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#78 Příspěvek od chodnik74 »

Ten by měl vyřadit aktivní havěť,která by blokoval CF...

Zkusíme tedy MBAM...

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#79 Příspěvek od WiZARD_ »

Ještě se chci zeptat, zda je nutné pracovat v nozovém režimu jako administrator, nebo jestli můžu v normálním...

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#80 Příspěvek od chodnik74 »

Zkuste v normálním :) pokud by byl problém,tak chodte do nouzáku :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#81 Příspěvek od chodnik74 »

I ten Combofix zkuste v normálním,pokud vá předtím nešel v nouzáku :) prostě zkoušejte.. co půjde..
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#82 Příspěvek od WiZARD_ »

Malwarebytes' Anti-Malware
www.malwarebytes.org

Database version:

Windows 5.1.2600 Service Pack 1
Internet Explorer 6.0.2800.1106

11.10.2011 14:09:51
mbam-log-2011-10-11 (14-09-43).txt

Scan type: Full scan (C:\|)
Objects scanned: 272572
Time elapsed: 37 minute(s), 26 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 7
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
c:\WINDOWS\system32\csrsc.exe (Malware.Packer.u64) -> 1896 -> No action taken.
c:\WINDOWS\system32\ipuzfds.exe (Backdoor.Bot) -> 400 -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc (Malware.Packer.u64) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srwsvc (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVC (Trojan.Agent) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\Microsoft System Service (Backdoor.Bot) -> Value: Microsoft System Service -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Updates (Backdoor.IRCBot) -> Value: Windows Updates -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows updatess (Backdoor.IRCBot) -> Value: windows updatess -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\OLE\Windows System Update Tools (Backdoor.Bot) -> Value: Windows System Update Tools -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\System32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\csrsc.exe (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\system32\drivers\srwsvc.sys (Rootkit.Agent) -> No action taken.
c:\WINDOWS\system32\x.exe (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\61I4HMWR\axsm[1].gif (Extension.Mismatch) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\61I4HMWR\tyf[1].jpg (Extension.Mismatch) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\LD6WQH9V\x[1] (Malware.Packer.u64) -> No action taken.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\UKRXYGLN\tyf[1].jpg (Extension.Mismatch) -> No action taken.
c:\_OTL\movedfiles\10102011_215005\c_windows\system32\svchots.exe (CrypTool.Agent) -> No action taken.
c:\WINDOWS\system32\ipuzfds.exe (Backdoor.Bot) -> No action taken.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#83 Příspěvek od chodnik74 »

Všechny nalezené položky dejte smazat..poté preventivně proskenovat znovu a zase vše smazat :) Vidím,že máme rootkit,takže poté pokračujte následovně...


:arrow: Stáhněte si TDSSKiller
  • Spuste program a klikněte na Start Scan
  • Pokud program najde infikekci,tak ji bude lecit (Cure), povolte léčení kliknutím na tlačítko Continue
  • Pokud program najde podezrely soubor (suspicious),bude ho chtít přeskočit (Skip), povolte přeskočení kliknutim na tlačítko Continue
  • Po dokončení skenování bude možná potřeba restartovat počítač,ten povolíte programu kliknutím na tlačítko Reboot now
  • Po restartování počítače na vás vyskočí log(pokud se tak nestane,tak ho najdete na disku,kde máte nainstalovaná systém s názvem TDSSKiller.xxxx_log.txt) a vložte mi sem jeho obsah
  • Pokud nebude program požadovat restartování počítače,klikněte na tlačítko Close a následně na Report , čímž se Vám vytvoří log a jeho obsah mu sem vložte
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#84 Příspěvek od WiZARD_ »

18:53:47.0609 0452 TDSS rootkit removing tool 2.6.7.0 Oct 10 2011 09:40:06
18:53:47.0765 0452 ============================================================
18:53:47.0765 0452 Current date / time: 2011/10/11 18:53:47.0765
18:53:47.0765 0452 SystemInfo:
18:53:47.0765 0452
18:53:47.0765 0452 OS Version: 5.1.2600 ServicePack: 1.0
18:53:47.0765 0452 Product type: Workstation
18:53:47.0765 0452 ComputerName: UNGIS-KFHKNNXQI
18:53:47.0765 0452 UserName: Administrator
18:53:47.0765 0452 Windows directory: C:\WINDOWS
18:53:47.0765 0452 System windows directory: C:\WINDOWS
18:53:47.0765 0452 Processor architecture: Intel x86
18:53:47.0765 0452 Number of processors: 1
18:53:47.0765 0452 Page size: 0x1000
18:53:47.0765 0452 Boot type: Safe boot with network
18:53:47.0765 0452 ============================================================
18:53:47.0937 0452 Initialize success
18:53:51.0500 0472 ============================================================
18:53:51.0500 0472 Scan started
18:53:51.0500 0472 Mode: Manual;
18:53:51.0500 0472 ============================================================
18:53:51.0687 0472 Abiosdsk - ok
18:53:51.0718 0472 abp480n5 - ok
18:53:51.0812 0472 ACPI (c792bfe75c01509954a9ab92d68cb892) C:\WINDOWS\System32\DRIVERS\ACPI.sys
18:53:51.0812 0472 ACPI - ok
18:53:51.0921 0472 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\System32\drivers\ACPIEC.sys
18:53:51.0921 0472 ACPIEC - ok
18:53:51.0968 0472 adpu160m - ok
18:53:52.0062 0472 aec (ff773feda15e8bd97fd54fe87a0acdbe) C:\WINDOWS\System32\drivers\aec.sys
18:53:52.0062 0472 aec - ok
18:53:52.0203 0472 AFD (51b1872b62d1c335bac53313913c8d5b) C:\WINDOWS\System32\drivers\afd.sys
18:53:52.0203 0472 AFD - ok
18:53:52.0281 0472 Aha154x - ok
18:53:52.0328 0472 aic78u2 - ok
18:53:52.0390 0472 aic78xx - ok
18:53:52.0453 0472 ALCXWDM - ok
18:53:52.0515 0472 AliIde - ok
18:53:52.0609 0472 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\System32\DRIVERS\AmdK8.sys
18:53:52.0609 0472 AmdK8 - ok
18:53:52.0640 0472 amsint - ok
18:53:52.0718 0472 Arp1394 (e47ae30589d7195bb044847fbb63a06e) C:\WINDOWS\System32\DRIVERS\arp1394.sys
18:53:52.0718 0472 Arp1394 - ok
18:53:52.0765 0472 asc - ok
18:53:52.0812 0472 asc3350p - ok
18:53:52.0859 0472 asc3550 - ok
18:53:52.0953 0472 Aspi32 (20d04091eba710f6988f710507d85868) C:\WINDOWS\System32\drivers\Aspi32.sys
18:53:52.0953 0472 Aspi32 - ok
18:53:53.0031 0472 AsyncMac (03f403b07a884fc2aa54a0916c410931) C:\WINDOWS\System32\DRIVERS\asyncmac.sys
18:53:53.0031 0472 AsyncMac - ok
18:53:53.0093 0472 atapi (95b858761a00e1d4f81f79a0da019aca) C:\WINDOWS\System32\DRIVERS\atapi.sys
18:53:53.0093 0472 atapi - ok
18:53:53.0125 0472 Atdisk - ok
18:53:53.0187 0472 Atmarpc (8d735ca1cbdb0081b0e3b9ff0eb222d0) C:\WINDOWS\System32\DRIVERS\atmarpc.sys
18:53:53.0187 0472 Atmarpc - ok
18:53:53.0281 0472 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\System32\DRIVERS\audstub.sys
18:53:53.0281 0472 audstub - ok
18:53:53.0359 0472 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\System32\drivers\Beep.sys
18:53:53.0359 0472 Beep - ok
18:53:53.0515 0472 catchme - ok
18:53:53.0609 0472 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\drivers\cbidf2k.sys
18:53:53.0609 0472 cbidf2k - ok
18:53:53.0656 0472 cd20xrnt - ok
18:53:53.0734 0472 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\System32\drivers\Cdaudio.sys
18:53:53.0734 0472 Cdaudio - ok
18:53:53.0796 0472 Cdfs (049a38451f2611caf2fd528e023a0b5a) C:\WINDOWS\System32\drivers\Cdfs.sys
18:53:53.0796 0472 Cdfs - ok
18:53:53.0828 0472 Cdrom (6506e033ad04cfec9ee56dbefd1083dd) C:\WINDOWS\System32\DRIVERS\cdrom.sys
18:53:53.0828 0472 Cdrom - ok
18:53:53.0859 0472 Changer - ok
18:53:53.0921 0472 CmdIde - ok
18:53:54.0031 0472 cmpci (e5842ccf0953d3d46d5e26427b67e901) C:\WINDOWS\System32\drivers\cmaudio.sys
18:53:54.0031 0472 cmpci - ok
18:53:54.0093 0472 Cpqarray - ok
18:53:54.0140 0472 dac2w2k - ok
18:53:54.0187 0472 dac960nt - ok
18:53:54.0281 0472 Disk (d1b16340ceaceecbf52340a0cbdf43e1) C:\WINDOWS\System32\DRIVERS\disk.sys
18:53:54.0281 0472 Disk - ok
18:53:54.0359 0472 dmboot (a71d4dcf0f18dab0d5ea1bf206fcb5f6) C:\WINDOWS\System32\drivers\dmboot.sys
18:53:54.0359 0472 dmboot - ok
18:53:54.0453 0472 dmio (ad811bf5557d8ff29fbf8a8a9a4ec279) C:\WINDOWS\System32\drivers\dmio.sys
18:53:54.0453 0472 dmio - ok
18:53:54.0515 0472 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\System32\drivers\dmload.sys
18:53:54.0515 0472 dmload - ok
18:53:54.0625 0472 DMusic (ef05974d47d56fa8387f170f05bae5e7) C:\WINDOWS\System32\drivers\DMusic.sys
18:53:54.0640 0472 DMusic - ok
18:53:54.0703 0472 dpti2o - ok
18:53:54.0734 0472 drmkaud (fd859e517fa2abb53654afa7ec9e3a94) C:\WINDOWS\System32\drivers\drmkaud.sys
18:53:54.0734 0472 drmkaud - ok
18:53:54.0843 0472 ElbyCDIO (084a13f18856d610d44d3109a9d2acde) C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
18:53:54.0843 0472 ElbyCDIO - ok
18:53:54.0906 0472 ElbyDelay (df9957db3bfe5136aad3c2c101806c98) C:\WINDOWS\System32\Drivers\ElbyDelay.sys
18:53:54.0906 0472 ElbyDelay - ok
18:53:54.0953 0472 ElbyVCD - ok
18:53:55.0046 0472 Fastfat (e4a3a8f3e60b542a747b10e86faa5dad) C:\WINDOWS\System32\drivers\Fastfat.sys
18:53:55.0046 0472 Fastfat - ok
18:53:55.0125 0472 Fdc (19c5c7eac0190a42522290bf002f64ea) C:\WINDOWS\System32\DRIVERS\fdc.sys
18:53:55.0125 0472 Fdc - ok
18:53:55.0171 0472 Fips (266dab58619b17bdf37fabbd48d875ca) C:\WINDOWS\System32\drivers\Fips.sys
18:53:55.0171 0472 Fips - ok
18:53:55.0218 0472 Flpydisk (8f70d1f7606f7442e2f7383f3701d728) C:\WINDOWS\System32\DRIVERS\flpydisk.sys
18:53:55.0218 0472 Flpydisk - ok
18:53:55.0281 0472 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\System32\drivers\Fs_Rec.sys
18:53:55.0281 0472 Fs_Rec - ok
18:53:55.0328 0472 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\System32\DRIVERS\ftdisk.sys
18:53:55.0328 0472 Ftdisk - ok
18:53:55.0390 0472 gameenum (6d18cad8a05d88e672b61db855a08289) C:\WINDOWS\System32\DRIVERS\gameenum.sys
18:53:55.0390 0472 gameenum - ok
18:53:55.0421 0472 GMSIPCI - ok
18:53:55.0484 0472 Gpc (13591e0a02e85de2a388f3ec4bd206df) C:\WINDOWS\System32\DRIVERS\msgpc.sys
18:53:55.0484 0472 Gpc - ok
18:53:55.0546 0472 hamachi (d30b31375c40309425c21efe75db90bb) C:\WINDOWS\System32\DRIVERS\hamachi.sys
18:53:55.0546 0472 hamachi - ok
18:53:55.0625 0472 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\System32\DRIVERS\hidusb.sys
18:53:55.0625 0472 HidUsb - ok
18:53:55.0671 0472 hpn - ok
18:53:55.0765 0472 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\System32\DRIVERS\HPZid412.sys
18:53:55.0765 0472 HPZid412 - ok
18:53:55.0812 0472 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\System32\DRIVERS\HPZipr12.sys
18:53:55.0812 0472 HPZipr12 - ok
18:53:55.0890 0472 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\System32\DRIVERS\HPZius12.sys
18:53:55.0890 0472 HPZius12 - ok
18:53:55.0953 0472 i2omgmt - ok
18:53:55.0984 0472 i2omp - ok
18:53:56.0062 0472 i8042prt (efff7945f256c5cf48481c23431de81a) C:\WINDOWS\System32\DRIVERS\i8042prt.sys
18:53:56.0062 0472 i8042prt - ok
18:53:56.0140 0472 Imapi (3cb4410747f2330d97b10b656d5bb2ac) C:\WINDOWS\System32\DRIVERS\imapi.sys
18:53:56.0140 0472 Imapi - ok
18:53:56.0171 0472 ini910u - ok
18:53:56.0234 0472 IntelIde - ok
18:53:56.0296 0472 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
18:53:56.0296 0472 IpFilterDriver - ok
18:53:56.0375 0472 IpInIp (f56dd863ba732a4e8ee58d486c31250f) C:\WINDOWS\System32\DRIVERS\ipinip.sys
18:53:56.0375 0472 IpInIp - ok
18:53:56.0421 0472 IpNat (fc672ad6e9676814a0c844912f2abcff) C:\WINDOWS\System32\DRIVERS\ipnat.sys
18:53:56.0421 0472 IpNat - ok
18:53:56.0468 0472 IPSec (1c4802409cfd4a7051f458b744cfcaa5) C:\WINDOWS\System32\DRIVERS\ipsec.sys
18:53:56.0468 0472 IPSec - ok
18:53:56.0531 0472 IRENUM (b43201394646b7e98c89056edda686b5) C:\WINDOWS\System32\DRIVERS\irenum.sys
18:53:56.0531 0472 IRENUM - ok
18:53:56.0609 0472 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\WINDOWS\System32\DRIVERS\isapnp.sys
18:53:56.0609 0472 isapnp - ok
18:53:56.0656 0472 Kbdclass (d7195aea3541737440f6b93fc72f63fd) C:\WINDOWS\System32\DRIVERS\kbdclass.sys
18:53:56.0656 0472 Kbdclass - ok
18:53:56.0703 0472 kbdhid (2597d9d538dbdeef183e74eb043c6170) C:\WINDOWS\System32\DRIVERS\kbdhid.sys
18:53:56.0703 0472 kbdhid - ok
18:53:56.0750 0472 kmixer (10e0feb086d8c1419b958c9034e4668a) C:\WINDOWS\System32\drivers\kmixer.sys
18:53:56.0750 0472 kmixer - ok
18:53:56.0812 0472 KSecDD (abc70e8b89cce44731a346deb764bf95) C:\WINDOWS\System32\drivers\KSecDD.sys
18:53:56.0812 0472 KSecDD - ok
18:53:56.0859 0472 lbrtfdc - ok
18:53:56.0953 0472 MMRTKRNL (58bc110e2d6f93e4c7a5dc092b263c30) C:\WINDOWS\System32\drivers\mmrtkrnl.sys
18:53:56.0953 0472 MMRTKRNL - ok
18:53:57.0015 0472 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\System32\drivers\mnmdd.sys
18:53:57.0015 0472 mnmdd - ok
18:53:57.0093 0472 Modem (0ad37920edce337eff4d3366dcd8566f) C:\WINDOWS\System32\drivers\Modem.sys
18:53:57.0093 0472 Modem - ok
18:53:57.0156 0472 Mouclass (8908fa25e4d9b38c0b962acbc9a50d27) C:\WINDOWS\System32\DRIVERS\mouclass.sys
18:53:57.0156 0472 Mouclass - ok
18:53:57.0218 0472 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\System32\DRIVERS\mouhid.sys
18:53:57.0218 0472 mouhid - ok
18:53:57.0281 0472 MountMgr (d4face53a1c48cf8419b4cf494d2ee2e) C:\WINDOWS\System32\drivers\MountMgr.sys
18:53:57.0281 0472 MountMgr - ok
18:53:57.0312 0472 mraid35x - ok
18:53:57.0359 0472 MRxDAV (d30cba20cc355d3648b9fed5bb55a9d5) C:\WINDOWS\System32\DRIVERS\mrxdav.sys
18:53:57.0375 0472 MRxDAV - ok
18:53:57.0453 0472 MRxSmb (7a3a2be44e12e2abde1af891e83ac130) C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
18:53:57.0453 0472 MRxSmb - ok
18:53:57.0546 0472 Msfs (a1831538e119363d0d90d757ac8a2012) C:\WINDOWS\System32\drivers\Msfs.sys
18:53:57.0546 0472 Msfs - ok
18:53:57.0609 0472 MSKSSRV (85736f804191cb420a31aca2a7f0674f) C:\WINDOWS\System32\drivers\MSKSSRV.sys
18:53:57.0609 0472 MSKSSRV - ok
18:53:57.0671 0472 MSPCLOCK (e943adb93d83c5cbc0ca3f53f53b48cc) C:\WINDOWS\System32\drivers\MSPCLOCK.sys
18:53:57.0671 0472 MSPCLOCK - ok
18:53:57.0734 0472 MSPQM (f6a726b8832db1f88326b8be98b11981) C:\WINDOWS\System32\drivers\MSPQM.sys
18:53:57.0734 0472 MSPQM - ok
18:53:57.0796 0472 Mup (08c56887f06473b09fc1b39e7dec0fb6) C:\WINDOWS\System32\drivers\Mup.sys
18:53:57.0812 0472 Mup - ok
18:53:57.0843 0472 NDIS (3b350e5a2a5e951453f3993275a4523a) C:\WINDOWS\System32\drivers\NDIS.sys
18:53:57.0843 0472 NDIS - ok
18:53:57.0906 0472 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\System32\DRIVERS\ndistapi.sys
18:53:57.0906 0472 NdisTapi - ok
18:53:57.0921 0472 Ndisuio (e6b6d5e4c9c199b7bb56d7862ea68fbc) C:\WINDOWS\System32\DRIVERS\ndisuio.sys
18:53:57.0921 0472 Ndisuio - ok
18:53:57.0968 0472 NdisWan (15787deca8c5428beeaa8044f544fd85) C:\WINDOWS\System32\DRIVERS\ndiswan.sys
18:53:57.0968 0472 NdisWan - ok
18:53:58.0000 0472 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\System32\drivers\NDProxy.sys
18:53:58.0000 0472 NDProxy - ok
18:53:58.0046 0472 NetBIOS (e351339fa17c4a70940e15b5e3dae6e2) C:\WINDOWS\System32\DRIVERS\netbios.sys
18:53:58.0046 0472 NetBIOS - ok
18:53:58.0093 0472 NetBT (d96f3bc5a6e7452b0e3275b560dc8528) C:\WINDOWS\System32\DRIVERS\netbt.sys
18:53:58.0109 0472 NetBT - ok
18:53:58.0218 0472 NIC1394 (ff4ceca01030be87d530e2c5859738db) C:\WINDOWS\System32\DRIVERS\nic1394.sys
18:53:58.0218 0472 NIC1394 - ok
18:53:58.0281 0472 Npfs (20aba9f035e3a98877480e34fcc4dcb3) C:\WINDOWS\System32\drivers\Npfs.sys
18:53:58.0281 0472 Npfs - ok
18:53:58.0343 0472 Ntfs (e3ae9c79498210a5f39fe5a9ad62bc55) C:\WINDOWS\System32\drivers\Ntfs.sys
18:53:58.0343 0472 Ntfs - ok
18:53:58.0437 0472 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\System32\drivers\Null.sys
18:53:58.0437 0472 Null - ok
18:53:58.0640 0472 nv (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\System32\DRIVERS\nv4_mini.sys
18:53:58.0671 0472 nv - ok
18:53:58.0765 0472 nvata (0344aa9113dc16eec379f4652020849d) C:\WINDOWS\System32\DRIVERS\nvata.sys
18:53:58.0765 0472 nvata - ok
18:53:58.0828 0472 NVENETFD (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\System32\DRIVERS\NVENETFD.sys
18:53:58.0828 0472 NVENETFD - ok
18:53:58.0875 0472 nvnetbus (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\System32\DRIVERS\nvnetbus.sys
18:53:58.0875 0472 nvnetbus - ok
18:53:58.0953 0472 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys
18:53:58.0953 0472 NwlnkFlt - ok
18:53:59.0046 0472 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys
18:53:59.0046 0472 NwlnkFwd - ok
18:53:59.0109 0472 ohci1394 (52c36c911f83f200130b2f84e01f3511) C:\WINDOWS\System32\DRIVERS\ohci1394.sys
18:53:59.0109 0472 ohci1394 - ok
18:53:59.0171 0472 Parport (888ee36ddbcd6793c845815b0e8435f3) C:\WINDOWS\System32\DRIVERS\parport.sys
18:53:59.0171 0472 Parport - ok
18:53:59.0203 0472 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\System32\drivers\PartMgr.sys
18:53:59.0203 0472 PartMgr - ok
18:53:59.0281 0472 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\System32\drivers\ParVdm.sys
18:53:59.0281 0472 ParVdm - ok
18:53:59.0328 0472 PCI (da76153b8abd5f894a8b32c09a5f5cbd) C:\WINDOWS\System32\DRIVERS\pci.sys
18:53:59.0328 0472 PCI - ok
18:53:59.0390 0472 PCIDump - ok
18:53:59.0437 0472 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\System32\DRIVERS\pciide.sys
18:53:59.0437 0472 PCIIde - ok
18:53:59.0515 0472 Pcmcia (71c6d1edd74657806190032704b3c1ef) C:\WINDOWS\System32\drivers\Pcmcia.sys
18:53:59.0515 0472 Pcmcia - ok
18:53:59.0578 0472 PDCOMP - ok
18:53:59.0625 0472 PDFRAME - ok
18:53:59.0656 0472 PDRELI - ok
18:53:59.0703 0472 PDRFRAME - ok
18:53:59.0750 0472 perc2 - ok
18:53:59.0781 0472 perc2hib - ok
18:53:59.0890 0472 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\System32\drivers\pfc.sys
18:53:59.0890 0472 pfc - ok
18:54:00.0000 0472 PptpMiniport (fed674d73eb56c35444f701e847bf85b) C:\WINDOWS\System32\DRIVERS\raspptp.sys
18:54:00.0000 0472 PptpMiniport - ok
18:54:00.0062 0472 Processor (603cf9e9fddf4468ac9439796598d902) C:\WINDOWS\System32\DRIVERS\processr.sys
18:54:00.0062 0472 Processor - ok
18:54:00.0125 0472 PSched (944440247fe6988c88b376ed85a0cd1a) C:\WINDOWS\System32\DRIVERS\psched.sys
18:54:00.0125 0472 PSched - ok
18:54:00.0187 0472 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\System32\DRIVERS\ptilink.sys
18:54:00.0187 0472 Ptilink - ok
18:54:00.0265 0472 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\System32\Drivers\PxHelp20.sys
18:54:00.0265 0472 PxHelp20 - ok
18:54:00.0296 0472 ql1080 - ok
18:54:00.0343 0472 Ql10wnt - ok
18:54:00.0390 0472 ql12160 - ok
18:54:00.0421 0472 ql1240 - ok
18:54:00.0453 0472 ql1280 - ok
18:54:00.0531 0472 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\System32\DRIVERS\rasacd.sys
18:54:00.0531 0472 RasAcd - ok
18:54:00.0609 0472 Rasl2tp (4c242c79a9c0d98d52d6f8cb9248d528) C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
18:54:00.0609 0472 Rasl2tp - ok
18:54:00.0671 0472 RasPppoe (888335b3be346119cf7b4eff3a3fca7c) C:\WINDOWS\System32\DRIVERS\raspppoe.sys
18:54:00.0671 0472 RasPppoe - ok
18:54:00.0734 0472 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\System32\DRIVERS\raspti.sys
18:54:00.0734 0472 Raspti - ok
18:54:00.0796 0472 Rdbss (df80c149c96fcfbb8a3dc3d5dd950aa8) C:\WINDOWS\System32\DRIVERS\rdbss.sys
18:54:00.0796 0472 Rdbss - ok
18:54:00.0890 0472 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
18:54:00.0890 0472 RDPCDD - ok
18:54:00.0984 0472 rdpdr (5208d077065ea8775e319f9834f94136) C:\WINDOWS\System32\DRIVERS\rdpdr.sys
18:54:00.0984 0472 rdpdr - ok
18:54:01.0046 0472 RDPWD (0606700377b6fb8b04475e92507adade) C:\WINDOWS\System32\drivers\RDPWD.sys
18:54:01.0046 0472 RDPWD - ok
18:54:01.0125 0472 redbook (f96247e7d101acddb9089fc9fdca51bd) C:\WINDOWS\System32\DRIVERS\redbook.sys
18:54:01.0125 0472 redbook - ok
18:54:01.0187 0472 regi (001b4278407f4303efc902a2b16f2453) C:\WINDOWS\System32\drivers\regi.sys
18:54:01.0187 0472 regi - ok
18:54:01.0312 0472 rtl8139 (7a0db9fc3dc3c620aea30ea2a6557cac) C:\WINDOWS\System32\DRIVERS\RTL8139.SYS
18:54:01.0312 0472 rtl8139 - ok
18:54:01.0406 0472 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\System32\DRIVERS\secdrv.sys
18:54:01.0406 0472 Secdrv - ok
18:54:01.0500 0472 serenum (65a7c4d86c153c82e33a552c217abb29) C:\WINDOWS\System32\DRIVERS\serenum.sys
18:54:01.0500 0472 serenum - ok
18:54:01.0546 0472 Serial (85ad2d12ccb39d825b3490c102f77e6a) C:\WINDOWS\System32\DRIVERS\serial.sys
18:54:01.0546 0472 Serial - ok
18:54:01.0640 0472 sfdrv01 (58235f4483b63ff33b0fc41c1cd624c5) C:\WINDOWS\System32\drivers\sfdrv01.sys
18:54:01.0640 0472 sfdrv01 - ok
18:54:01.0703 0472 sfdrv01a (4d0ce0fadca29e7da68ce597ac9010bd) C:\WINDOWS\System32\drivers\sfdrv01a.sys
18:54:01.0703 0472 sfdrv01a - ok
18:54:01.0765 0472 sfhlp02 (daad4c099ebf5094d32c373ac1ac0f3c) C:\WINDOWS\System32\drivers\sfhlp02.sys
18:54:01.0765 0472 sfhlp02 - ok
18:54:01.0828 0472 Sfloppy (4e1b8866f3d208dee3906a191cb493e3) C:\WINDOWS\System32\drivers\Sfloppy.sys
18:54:01.0828 0472 Sfloppy - ok
18:54:01.0906 0472 sfsync02 (6dc03269f4c71e4ab313c3597f42a340) C:\WINDOWS\System32\drivers\sfsync02.sys
18:54:01.0906 0472 sfsync02 - ok
18:54:01.0968 0472 sfvfs02 (107b772690050d3b19cbc637ad8fd96e) C:\WINDOWS\System32\drivers\sfvfs02.sys
18:54:01.0968 0472 sfvfs02 - ok
18:54:02.0046 0472 Simbad - ok
18:54:02.0078 0472 Sparrow - ok
18:54:02.0156 0472 splitter (32c54211e9e8a45cbcb097beaeb1999a) C:\WINDOWS\System32\drivers\splitter.sys
18:54:02.0156 0472 splitter - ok
18:54:02.0265 0472 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\System32\Drivers\sptd.sys
18:54:02.0265 0472 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
18:54:02.0265 0472 sptd ( LockedFile.Multi.Generic ) - warning
18:54:02.0265 0472 sptd - detected LockedFile.Multi.Generic (1)
18:54:02.0359 0472 sr (af4cf05e5b2f413a8bfeed9bb2a294f4) C:\WINDOWS\System32\DRIVERS\sr.sys
18:54:02.0359 0472 sr - ok
18:54:02.0421 0472 Srv (94619eb663216f9bf12f9b950fcab3c0) C:\WINDOWS\System32\DRIVERS\srv.sys
18:54:02.0421 0472 Srv - ok
18:54:02.0500 0472 StarOpen - ok
18:54:02.0578 0472 swenum (616a013d3ea068b6dee83d905e92ee9f) C:\WINDOWS\System32\DRIVERS\swenum.sys
18:54:02.0578 0472 swenum - ok
18:54:02.0609 0472 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\System32\drivers\swmidi.sys
18:54:02.0625 0472 swmidi - ok
18:54:02.0656 0472 symc810 - ok
18:54:02.0703 0472 symc8xx - ok
18:54:02.0750 0472 sym_hi - ok
18:54:02.0781 0472 sym_u3 - ok
18:54:02.0843 0472 sysaudio (b0b19f036f76333ab3338c7493e87b12) C:\WINDOWS\System32\drivers\sysaudio.sys
18:54:02.0843 0472 sysaudio - ok
18:54:02.0906 0472 Tcpip (244a2f9816bc9b593957281ef577d976) C:\WINDOWS\System32\DRIVERS\tcpip.sys
18:54:02.0921 0472 Tcpip - ok
18:54:03.0000 0472 TDPIPE (1a96630babbd59e8b885eae0dfbe6a3e) C:\WINDOWS\System32\drivers\TDPIPE.sys
18:54:03.0000 0472 TDPIPE - ok
18:54:03.0046 0472 TDTCP (d1c578c6b37713694c5edd7c2d7f7451) C:\WINDOWS\System32\drivers\TDTCP.sys
18:54:03.0046 0472 TDTCP - ok
18:54:03.0109 0472 TermDD (194c51bc28a7ce9818012142b062e431) C:\WINDOWS\System32\DRIVERS\termdd.sys
18:54:03.0109 0472 TermDD - ok
18:54:03.0171 0472 TosIde - ok
18:54:03.0250 0472 Udfs (01ca8ec606522d2f60820b0c0086fdd5) C:\WINDOWS\System32\drivers\Udfs.sys
18:54:03.0250 0472 Udfs - ok
18:54:03.0296 0472 ultra - ok
18:54:03.0359 0472 Update (164cfae1d766905f56c432acfc54f28c) C:\WINDOWS\System32\DRIVERS\update.sys
18:54:03.0375 0472 Update - ok
18:54:03.0453 0472 usbccgp (79fee3cfec5b14194dbe0a703d82b2a4) C:\WINDOWS\System32\DRIVERS\usbccgp.sys
18:54:03.0453 0472 usbccgp - ok
18:54:03.0500 0472 usbehci (2d0c2f3836f72e85d41d9c50aeeb5423) C:\WINDOWS\System32\DRIVERS\usbehci.sys
18:54:03.0500 0472 usbehci - ok
18:54:03.0546 0472 usbhub (d7bf70ac85e48b6c4df953401eccb75a) C:\WINDOWS\System32\DRIVERS\usbhub.sys
18:54:03.0546 0472 usbhub - ok
18:54:03.0593 0472 usbohci (4e7d2f6df7a7e02d80fe0b109f0c9f02) C:\WINDOWS\System32\DRIVERS\usbohci.sys
18:54:03.0593 0472 usbohci - ok
18:54:03.0656 0472 usbprint (c9a83be290c89730ae59f6c3085f072d) C:\WINDOWS\System32\DRIVERS\usbprint.sys
18:54:03.0656 0472 usbprint - ok
18:54:03.0703 0472 usbscan (7691af2109474eb923004f3dca4c9559) C:\WINDOWS\System32\DRIVERS\usbscan.sys
18:54:03.0703 0472 usbscan - ok
18:54:03.0765 0472 USBSTOR (4923c60f9c381eae679db04021d26abb) C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
18:54:03.0765 0472 USBSTOR - ok
18:54:03.0843 0472 VClone (e69eb856ba6528d0373000683cc869a8) C:\WINDOWS\System32\DRIVERS\VClone.sys
18:54:03.0843 0472 VClone - ok
18:54:03.0921 0472 VgaSave (08d2edfd7261242b8aea27f1fe11e120) C:\WINDOWS\System32\drivers\vga.sys
18:54:03.0921 0472 VgaSave - ok
18:54:03.0937 0472 Suspicious service (NoAccess): vgchpoipr
18:54:03.0984 0472 ViaIde - ok
18:54:04.0046 0472 VolSnap (bd7edaee708c8c4141f2eab80b89904a) C:\WINDOWS\System32\drivers\VolSnap.sys
18:54:04.0046 0472 VolSnap - ok
18:54:04.0109 0472 Wanarp (484af08f15d1306ff2e8b64fe62a160c) C:\WINDOWS\System32\DRIVERS\wanarp.sys
18:54:04.0109 0472 Wanarp - ok
18:54:04.0140 0472 WDICA - ok
18:54:04.0187 0472 wdmaud (499b653356a9e5589ee83ac47e5d2a8c) C:\WINDOWS\System32\drivers\wdmaud.sys
18:54:04.0187 0472 wdmaud - ok
18:54:04.0312 0472 WmBEnum (588c1df21321ec51eebff2c8909d1587) C:\WINDOWS\System32\drivers\WmBEnum.sys
18:54:04.0312 0472 WmBEnum - ok
18:54:04.0375 0472 WmFilter (3b45b7bfd513d3313e895d187849e3a3) C:\WINDOWS\System32\drivers\WmFilter.sys
18:54:04.0375 0472 WmFilter - ok
18:54:04.0453 0472 WmHidLo (a340efc6c494bd2a2aa5c030459a27d2) C:\WINDOWS\System32\drivers\WmHidLo.sys
18:54:04.0453 0472 WmHidLo - ok
18:54:04.0546 0472 WmVirHid (fe7d6991fd5894f06aae95dc78e79948) C:\WINDOWS\System32\drivers\WmVirHid.sys
18:54:04.0546 0472 WmVirHid - ok
18:54:04.0609 0472 WmXlCore (dcbb4688ee775912444b9010cd3fe9b6) C:\WINDOWS\System32\drivers\WmXlCore.sys
18:54:04.0609 0472 WmXlCore - ok
18:54:04.0687 0472 WpdUsb (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\System32\Drivers\wpdusb.sys
18:54:04.0687 0472 WpdUsb - ok
18:54:04.0781 0472 YMIDUSB (6e04f159b0ffcb2d72a2b149553ef6fc) C:\WINDOWS\System32\Drivers\ymidusb.sys
18:54:04.0781 0472 YMIDUSB - ok
18:54:04.0859 0472 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
18:54:05.0015 0472 \Device\Harddisk0\DR0 - ok
18:54:05.0046 0472 Boot (0x1200) (a3fe1f1f6359d97cba428fa0536c0a3f) \Device\Harddisk0\DR0\Partition0
18:54:05.0062 0472 \Device\Harddisk0\DR0\Partition0 - ok
18:54:05.0078 0472 ============================================================
18:54:05.0078 0472 Scan finished
18:54:05.0078 0472 ============================================================
18:54:05.0093 0464 Detected object count: 1
18:54:05.0093 0464 Actual detected object count: 1
18:54:08.0281 0464 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:54:08.0281 0464 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#85 Příspěvek od chodnik74 »

SUPER..nyní zkuste spustit Combofix dle návodu...pokud nepůjde,tak..

:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 2 a enter
  • Objeví se vám log a ten sem vložte
  • Stějně tak opakujte s volbou 3 a 4 a vložte logy
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#86 Příspěvek od WiZARD_ »

Nejde ani jedno ani druhé... :(

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#87 Příspěvek od chodnik74 »

Ani v nouzovém režimu? pokud ne,tak se budeme zase muset mrknout,zda tam neí havěť..Malwarebytes nic nenašlo už?
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#88 Příspěvek od WiZARD_ »

Ne... Pouze TDSSKiller našel jeden soubor, který jsem skipoval...

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Neskutečně zasekané a spomalené PC

#89 Příspěvek od chodnik74 »

Tak se budeme muset podívat zase přes OTL co nám to blokuje.. :roll:


:arrow: Stáhneme si na Plochu program OTLObrázek
  • Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Pokud používáte 64 bitový systém,zaškrkněte volbu Pro 64 bitové OS,pokud ne,tak by měla být nezaškrknutá
  • Zaškrkněte okýnko Pro všechny uživatele,Kontrola havět "LOP",Kontrola havět "Purity"
  • Staří souborů změňte z 30 dnů na 7 dnů
  • Do spodního okýnka Vlastní skenování/opravy vložte následující script:

    Kód: Vybrat vše

    safebootminimal 
    safebootnetwork
    drivers32
    savembr:0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    /md5start
    scecli.dll
    autochk.exe
    csrss.exe
    explorer.exe
    lsass.exe
    services.exe
    smss.exe
    spoolsv.exe
    svchost.exe
    userinit.exe
    winlogon.exe
    atapi.sys
    cdrom.sys 
    ndis.sys
    ntfs.sys
    tcpip.sys
    %SystemDrive%\PhysicalMBR.bin
    /md5stop
    C:\windows\system32\spool\prtprocs|dll;true;true;true /FP
    %systemroot%\system32\drivers\*.sys /5
    %systemroot%\system32\drivers\*.sys /X 
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.* /5
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\config\*.sav 
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\*.* /U /s
    %systemroot%\*. /mp /s
    %ALLUSERSPROFILE%\Data Aplikací\*.*
    %ALLUSERSPROFILE%\Data Aplikací\*.exe /s
    %ALLUSERSPROFILE%\Dáta aplikácií\*.*
    %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s
    %APPDATA%\*.
    *crack* /s
    *keygen* /s
    %APPDATA%\*.*
    %APPDATA%\*.exe /s
    %SYSTEMDRIVE%\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces
    sTime /rs
    reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c
    type c:\boot.ini >> test.txt /
    
  • Klikněte na tlačítko Prohledat
  • Po dokončení skenu,který trvá mezi 5-15 minuty se vám zobrazý dva logy OTL.txt a Extras.txt a ty mě sem vložte

a pro jistotu mi hoďte ještě log z GMERU...

:arrow: Stáhněte SPTD
  • Vyberte si verzi svého operačního systému,jestli máte 32 bitů nebo 64 bitů
  • Stáhněte si program na plochu a spuste
  • Zvolte možnost Uninstall,poté restartujte PC (Kdyby nešlo na tlačítko Uninstall kliknou a bylo šedé,tak tento krok přeskočte
:arrow: Stáhněte Defogger
  • Stáhněte si program a uložte na plochu
  • Spuste program
  • Kliknete na tlačítko Disable,poté restartujte PC(Kdyby nešlo na tlačítko Disable kliknou a bylo šedé,tak tento krok přeskočte

Log z GMERU podle návodu : http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

WiZARD_
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 09 kvě 2011 14:47

Re: Neskutečně zasekané a spomalené PC

#90 Příspěvek od WiZARD_ »

OTL logfile created on: 12.10.2011 12:20:17 - Run 3
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Viti\Plocha
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,48 Mb Total Physical Memory | 170,64 Mb Available Physical Memory | 33,36% Memory free
1,22 Gb Paging File | 0,94 Gb Available in Paging File | 76,89% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 6,09 Gb Free Space | 16,36% Space Free | Partition Type: NTFS

Computer Name: UNGIS-KFHKNNXQI | User Name: Viti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2011.10.11 18:53:28 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
PRC - [2011.10.03 00:23:50 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011.09.28 14:13:48 | 000,590,336 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Viti\Plocha\OTL(1).exe
PRC - [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ7.2\ICQ.exe
PRC - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2004.12.14 15:44:06 | 000,036,864 | R--- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 18:05:24 | 000,468,992 | RHS- | M] () -- C:\WINDOWS\system32\cxmoagb.exe


========== Modules (No Company Name) ==========

MOD - [2011.10.11 18:53:28 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
MOD - [2011.10.03 00:23:49 | 001,833,944 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.09.09 16:32:04 | 006,277,280 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011.01.05 10:18:56 | 000,733,184 | ---- | M] () -- C:\Program Files\ICQ7.2\MDb.dll
MOD - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
MOD - [2006.10.22 06:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2002.12.12 01:14:32 | 000,013,312 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2002.09.20 18:05:24 | 000,468,992 | RHS- | M] () -- C:\WINDOWS\system32\cxmoagb.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (MSDisk)
SRV - File not found [Auto | Stopped] -- -- (hpqddsvc)
SRV - File not found [On_Demand | Stopped] -- -- (hpqcxs08)
SRV - [2011.10.11 18:53:28 | 000,057,871 | R--- | M] () [Auto | Running] -- C:\WINDOWS\System32\smsc.exe -- (PrtSmanm)
SRV - [2011.10.11 18:52:48 | 000,149,503 | RHS- | M] () [Auto | Running] -- C:\WINDOWS\Fonts\unwise_.exe -- (Windows Hosts Controller)
SRV - [2009.11.12 14:48:58 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.03.23 16:52:12 | 000,056,552 | ---- | M] (Eng. Usama El-Mokadem) [Auto | Stopped] -- C:\WINDOWS\System32\Startsrv.exe -- (SRVStarter_Service)
SRV - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.05.10 11:59:04 | 000,353,912 | ---- | M] (Protection Technology (StarForce)) [Auto | Stopped] -- C:\WINDOWS\System32\sfrem01.exe -- (sfrem01) SF FrontLine Drivers Auto Removal (v1)
SRV - [2005.11.17 16:18:52 | 001,536,092 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2002.12.17 18:26:22 | 007,528,529 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,320,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (uhabyhp)
SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (hszvrfa)
SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (bqyvckklk)


========== Driver Services (SafeList) ==========

DRV - [2009.11.12 14:48:58 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\StarOpen.sys -- (StarOpen)
DRV - [2009.08.04 13:09:42 | 000,018,560 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ymidusb.sys -- (YMIDUSB)
DRV - [2009.01.27 09:12:47 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.04.17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\regi.sys -- (regi)
DRV - [2007.03.15 22:07:14 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007.01.12 20:09:53 | 000,082,296 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2006.07.10 18:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2006.05.10 10:39:38 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.04.05 21:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.05 21:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.01.11 17:05:30 | 000,092,672 | ---- | M] (ALCATech) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL)
DRV - [2004.04.01 17:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002.11.18 17:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.08.29 02:32:44 | 000,009,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2002.06.20 19:45:44 | 000,013,920 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2002.06.20 19:45:42 | 000,020,128 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002.06.20 19:45:40 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2002.06.20 19:45:36 | 000,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2002.06.20 19:45:34 | 000,039,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2001.08.17 22:12:42 | 000,023,070 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [1997.12.23 02:00:00 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_result ... r=1.3.3&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.0
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20101009
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.22
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.3.3&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Viti\Data aplikací\Facebook\npfbplugin_1_0_3.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.10.03 00:23:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.08 11:23:55 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: H:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

[2008.06.20 20:30:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Extensions
[2011.10.12 01:24:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Metal Lion - Vista) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (Qute) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2010.10.15 18:21:45 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2009.12.28 01:18:18 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2009.10.11 19:38:26 | 000,000,000 | ---D | M] (iFox Graphite) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{74b288e6-77b6-41c7-8138-bb81f4539689}
[2011.09.28 17:15:53 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.06.15 11:54:38 | 000,000,000 | ---D | M] (PimpZilla) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2008.04.16 17:13:40 | 000,000,000 | ---D | M] (Blue Ice 2) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2011.10.12 01:24:59 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com
[2011.05.08 11:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\nostmp
[2007.09.19 20:13:48 | 000,000,000 | ---D | M] ("VideoDownloader") -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\videodowloader@videodownloader.net
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\defaults
[2010.10.15 18:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\extension@virtusdesigns.com\chrome
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.10.15 18:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011.10.09 18:46:16 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-1.xml
[2009.06.15 15:32:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-10.xml
[2009.07.23 15:16:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-11.xml
[2009.08.04 20:40:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-12.xml
[2009.09.11 20:19:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-13.xml
[2009.10.29 10:16:06 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-14.xml
[2009.11.07 11:15:29 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-15.xml
[2009.12.17 15:19:50 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-16.xml
[2010.01.07 15:37:04 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-17.xml
[2010.02.19 19:11:40 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-18.xml
[2010.03.12 18:28:32 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-19.xml
[2008.10.01 17:09:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-2.xml
[2010.03.25 08:05:04 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-20.xml
[2010.04.03 23:01:11 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-21.xml
[2010.07.05 21:02:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-22.xml
[2010.07.23 13:46:37 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-23.xml
[2010.07.24 15:37:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-24.xml
[2010.09.12 18:11:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-25.xml
[2010.09.17 17:46:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-26.xml
[2010.10.22 23:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-27.xml
[2010.10.31 17:13:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-28.xml
[2010.11.01 16:32:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-29.xml
[2008.11.14 12:06:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-3.xml
[2011.03.02 00:33:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-30.xml
[2011.03.06 14:33:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-31.xml
[2011.03.24 21:06:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-32.xml
[2011.04.30 13:06:15 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-33.xml
[2011.05.08 11:24:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-34.xml
[2011.07.17 16:32:43 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-35.xml
[2011.08.28 08:24:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-36.xml
[2011.08.31 19:52:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-37.xml
[2011.09.10 23:48:21 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-38.xml
[2011.10.03 00:24:07 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-39.xml
[2008.12.17 17:50:45 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-4.xml
[2009.02.08 12:49:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-5.xml
[2009.03.08 11:53:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-6.xml
[2009.03.29 12:51:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-7.xml
[2009.04.23 20:07:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-8.xml
[2009.04.28 19:03:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin-9.xml
[2011.09.25 17:27:46 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.gif
[2011.09.25 17:27:46 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.src
[2010.06.21 17:35:24 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\icqplugin.xml
[2009.09.24 16:00:41 | 000,002,061 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Profiles\vt4rufzo.default\searchplugins\qipsearch.xml
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\VITI\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\VT4RUFZO.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}
[2011.10.03 00:23:50 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.03 00:23:47 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.10.03 00:23:47 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.07.05 21:02:00 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.10.03 00:23:47 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.10.03 00:23:47 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.10.03 00:23:47 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.10.12 12:18:32 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - H:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll File not found
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - H:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File not found
O3 - HKLM\..\Toolbar: (&Rádio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] H:\Program Files\HP\HP Software Update\HPWuSchd2.exe File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [FreeCall] "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [LClock] C:\Program Files\LClock\lclock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [mxClock] C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Start WingMan Profiler] File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe File not found
O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 67108863
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - H:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File not found
O15 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Viti\Data aplikací\Mozilla\Firefox\Pozadí plochy.bmp
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.12.27 16:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

Drivers32: midi2 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\xgusb.cpl (Yamaha Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2011.10.12 01:24:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Viti\Nabídka Start\Programy\Nástroje pro správu
[2011.10.11 16:56:07 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

========== Files - Modified Within 7 Days ==========

[2011.10.12 12:21:51 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.10.12 12:18:58 | 000,001,673 | ---- | M] () -- C:\WINDOWS\System32\eras.fon
[2011.10.12 12:18:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.10.11 22:24:33 | 000,465,920 | ---- | M] () -- C:\WINDOWS\System32\winlolx.exe
[2011.10.11 22:24:27 | 000,000,065 | ---- | M] () -- C:\WINDOWS\System32\o
[2011.10.11 19:29:21 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.10.11 18:53:28 | 000,057,871 | R--- | M] () -- C:\WINDOWS\System32\smsc.exe
[2011.10.11 18:52:48 | 000,149,503 | ---- | M] () -- C:\WINDOWS\System32\asr_01444.exe
[2011.10.11 18:52:41 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_vcuqy
[2011.10.11 18:00:29 | 000,000,052 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2011.10.11 17:23:25 | 000,043,482 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\adidas jeremy scott.jpg
[2011.10.11 16:56:07 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.10.11 15:28:37 | 000,002,507 | ---- | M] () -- C:\Documents and Settings\Viti\Plocha\CorelDRAW 11.lnk
[2011.10.09 18:43:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2011.10.11 22:24:27 | 000,465,920 | ---- | C] () -- C:\WINDOWS\System32\winlolx.exe
[2011.10.11 18:52:49 | 000,149,503 | RHS- | C] () -- C:\WINDOWS\Fonts\unwise_.exe
[2011.10.11 18:52:41 | 000,149,503 | ---- | C] () -- C:\WINDOWS\System32\asr_01444.exe
[2011.10.11 18:52:41 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_vcuqy
[2011.10.11 17:23:21 | 000,043,482 | ---- | C] () -- C:\Documents and Settings\Viti\Plocha\adidas jeremy scott.jpg
[2011.10.10 21:53:32 | 000,057,871 | R--- | C] () -- C:\WINDOWS\System32\smsc.exe
[2011.10.10 21:51:45 | 000,001,673 | ---- | C] () -- C:\WINDOWS\System32\eras.fon
[2011.09.18 18:53:14 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.09.18 18:44:47 | 001,064,960 | RHS- | C] () -- C:\WINDOWS\System32\xsycs.dll
[2011.05.12 18:37:08 | 000,263,680 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.05.12 18:37:08 | 000,105,984 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.05.12 18:37:08 | 000,099,328 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.05.12 18:37:08 | 000,087,580 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.05.12 18:37:08 | 000,075,264 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2010.05.30 16:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CorelDrw110.INI
[2010.05.16 20:10:10 | 000,000,622 | ---- | C] () -- C:\WINDOWS\DMN.INI
[2010.04.16 21:10:29 | 000,176,248 | ---- | C] () -- C:\WINDOWS\hpoins36.dat
[2010.04.16 21:10:29 | 000,000,652 | ---- | C] () -- C:\WINDOWS\hpomdl36.dat
[2010.02.22 00:29:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\vypalovac.ini
[2010.01.02 20:31:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2010.01.02 14:07:36 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010.01.02 14:07:35 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010.01.02 14:07:35 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010.01.02 14:07:35 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010.01.02 14:07:35 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010.01.02 14:07:35 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010.01.02 14:07:35 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010.01.02 14:07:35 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010.01.02 14:07:35 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010.01.02 14:07:35 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010.01.02 14:07:35 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010.01.02 14:07:35 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010.01.02 14:07:35 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010.01.02 14:07:35 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010.01.02 14:07:35 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010.01.02 14:07:35 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010.01.02 14:07:35 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009.11.29 18:24:04 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009.11.12 14:48:58 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\StarOpen.sys
[2009.08.07 14:38:41 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2008.11.15 19:55:30 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez9066.dat
[2008.07.14 10:52:54 | 000,000,395 | ---- | C] () -- C:\WINDOWS\capella.ini
[2008.07.11 21:00:29 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008.01.16 18:09:46 | 000,468,992 | RHS- | C] () -- C:\WINDOWS\System32\cxmoagb.exe
[2007.12.30 22:46:11 | 000,000,052 | ---- | C] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2007.12.30 22:43:58 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.30 22:43:58 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.29 20:01:13 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.08.21 19:21:14 | 000,000,036 | ---- | C] () -- C:\WINDOWS\CONTEXT.INI
[2007.08.21 19:20:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2007.08.19 20:21:56 | 000,000,041 | -H-- | C] () -- C:\WINDOWS\dsez6006.dat
[2007.04.21 10:21:06 | 000,000,948 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007.04.19 19:42:51 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\fusioncache.dat
[2007.03.02 22:49:20 | 000,000,058 | ---- | C] () -- C:\WINDOWS\FSaver.ini
[2007.02.17 19:32:19 | 000,001,459 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.17 19:31:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.15 17:18:21 | 000,000,463 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.01.26 22:46:44 | 000,006,378 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.01.26 22:35:45 | 000,610,304 | -H-- | C] () -- C:\WINDOWS\System32\dfxg115.dll
[2007.01.26 20:36:23 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2007.01.24 22:44:01 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2007.01.12 19:01:37 | 000,130,560 | ---- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.12.31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006.12.27 19:20:15 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.27 16:53:32 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006.12.27 16:33:49 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006.12.27 16:28:03 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.10.22 06:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 06:22:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006.10.22 06:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 06:22:00 | 001,347,584 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006.10.22 06:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 06:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 06:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 06:22:00 | 000,450,560 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006.10.22 06:22:00 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006.10.22 06:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 06:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2004.01.01 03:51:48 | 000,004,439 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.01.01 03:50:39 | 001,127,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.12.16 14:00:34 | 000,039,260 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002.12.16 13:58:52 | 000,022,337 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2002.09.20 18:19:36 | 000,001,740 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001.10.25 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 14:00:00 | 000,439,628 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 14:00:00 | 000,437,386 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 14:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 14:00:00 | 000,089,794 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 14:00:00 | 000,078,556 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 14:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 14:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001.08.07 05:16:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\OTS_UI.EXE
[1993.07.23 20:31:02 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll

========== LOP Check ==========

[2011.05.17 15:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avg7
[2010.02.22 00:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.05.12 19:26:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2010.11.01 16:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.01.08 22:17:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MAGIX
[2011.05.12 19:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2008.07.11 21:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
[2007.11.04 13:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.03.02 18:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.05.16 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Yamaha
[2010.04.22 23:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\COWON
[2011.05.08 14:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\GetRightToGo
[2011.05.13 23:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alů\Data aplikací\ICQ
[2007.05.22 07:18:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\COWON
[2007.05.22 06:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQLite
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2002.08.20 16:08:38 | 001,519,645 | ---- | M] (Microsoft Corporation)
"FreeCall" = "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized
"Start WingMan Profiler" =
"ctfmon.exe" = C:\WINDOWS\System32\ctfmon.exe -- [2002.09.20 18:05:18 | 000,020,480 | ---- | M] (Microsoft Corporation)
"mxClock" = C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe
"LClock" = C:\Program Files\LClock\lclock.exe
"ViStart" = C:\Program Files\ViStart\ViStart.exe
"ViOrb" = C:\Program Files\ViOrb\ViOrb.exe
"ICQ" = "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4 -- [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.)
"Windows LoL Layer" = cxmoagb.exe -- [2002.09.20 18:05:24 | 000,468,992 | RHS- | M] ()


< MD5 for: ATAPI.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\drivers\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2002.09.20 18:05:14 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\cmdcons\autochk.exe
[2002.09.20 18:05:14 | 000,578,048 | -H-- | M] (Microsoft Corporation) MD5=82CD2AA659D68781D29BA87421BE0E40 -- C:\WINDOWS\system32\autochk.exe

< MD5 for: CDROM.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2002.08.29 01:27:56 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CSRSS.EXE >
[2001.10.25 14:00:00 | 000,004,096 | ---- | M] (Microsoft Corporation) MD5=E5C52921CC7B099CEA19C53E31F4AB0E -- C:\WINDOWS\system32\csrss.exe

< MD5 for: EXPLORER.EXE >
[2011.01.16 16:55:21 | 000,262,656 | ---- | M] () MD5=114006808E05E4C44F3E8779E1086B33 -- C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\procs\explorer.exe
[2002.09.20 18:05:24 | 001,011,712 | ---- | M] (Microsoft Corporation) MD5=2E83E5B8558D562031AF987BFDC78073 -- C:\WINDOWS\explorer.exe
[2011.01.16 16:55:21 | 000,262,656 | ---- | M] () MD5=60B8CF9BA0442D18F4A29C7F3B8F02A8 -- C:\Documents and Settings\Viti\Local Settings\Temp\RarSFX0\procs\explorer.exe
[2005.08.16 02:54:58 | 000,008,704 | ---- | M] () MD5=C34307F7C297EB65D92C27ADAA4FA220 -- C:\Documents and Settings\Viti\Local Settings\Temp\RarSFX0\h\explorer.exe
[2005.08.16 02:54:58 | 000,008,704 | ---- | M] () MD5=DC6A2342816B277F3CE100E588E1B813 -- C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\h\explorer.exe
[2002.09.20 18:05:24 | 001,401,856 | ---- | M] (Microsoft Corporation) MD5=F313FD11075A3CF7480EC77DD21C1FE4 -- C:\VTPFiles\explorer.exe

< MD5 for: LSASS.EXE >
[2002.09.20 18:05:32 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2002.08.29 02:09:26 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NTFS.SYS >
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\cmdcons\NTFS.SYS
[2002.08.29 02:13:40 | 000,561,920 | ---- | M] (Microsoft Corporation) MD5=E3AE9C79498210A5F39FE5A9AD62BC55 -- C:\WINDOWS\system32\drivers\ntfs.sys

< MD5 for: SCECLI.DLL >
[2002.09.20 18:04:42 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2001.10.25 14:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=159D79FE3E22DCD5770AF0D08DDF9A07 -- C:\WINDOWS\system32\services.exe

< MD5 for: SMSS.EXE >
[2001.10.24 03:52:12 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=0B7569ECA93964A39BEDCF763E78E22A -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2002.09.20 18:05:44 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2001.10.25 14:00:00 | 000,058,368 | ---- | M] (Microsoft Corporation) MD5=3A5AF33B43267D051F9D23F9DAE95BAE -- C:\WINDOWS\system32\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2001.10.25 14:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=93A69214D0909E73BB2061DB9DB7F3E9 -- C:\WINDOWS\system32\svchost.exe

Odpovědět