Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pls o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#31 Příspěvek od civrs »

mozilla furt pomalá :-(

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#32 Příspěvek od motji »

Zkuste v moziile zakázat všechny doplnky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#33 Příspěvek od civrs »

je to o mnohem lepší :-)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#34 Příspěvek od motji »

Tak potom ty doplňky co nepoužíváte, odinstalujte.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#35 Příspěvek od civrs »

Zdá se to lepší (mozilla určitě)ale třeba start/restart je hrozně dlouhý,jako když tam ještě neco je,původně to bylo o poznání lepší..

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#36 Příspěvek od motji »

A nemáte staženou třeba novější verzi. Ona co verze, tak reaguje jinak :?:

:arrow: Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

netsvcs
drivers32
savembr:0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s

/md5start
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
hal.dll
logevent.dll
netlogon.dll
ntelogon.dll
scecli.dll
sceclt.dll
ws2_32.dll
autochk.exe
csrss.exe
explorer.exe
lsass.exe
services.exe
smss.exe
spoolsv.exe
svchost.exe
userinit.exe
winlogon.exe
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
cdrom.sys
Changer.sys
fastfat.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
mv61xx.sys
ndis.sys
ntfs.sys
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
symmpi.sys
tcpip.sys
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
/md5stop

C:\windows\system32\spool\prtprocs|dll;true;true;true /FP
%systemroot%\system32\drivers\*.sys /5
%systemroot%\system32\drivers\*.sys /X
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\*.* /5
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\config\*.sav
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\*.* /U /s
%systemroot%\*. /mp /s
%ALLUSERSPROFILE%\Data Aplikací\*.*
%ALLUSERSPROFILE%\Data Aplikací\*.exe /s
%ALLUSERSPROFILE%\Dáta aplikácií\*.*
%ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s
%APPDATA%\*.
%APPDATA%\*.*
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe


HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5 
- zaškrtněte okénko Pro všechny uživatele.
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#37 Příspěvek od civrs »

OTL logfile created on: 8.3.2012 14:31:09 - Run 1
OTL by OldTimer - Version 3.2.36.1 Folder = C:\Documents and Settings\Admin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,50 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 78,62% Memory free
4,84 Gb Paging File | 4,20 Gb Available in Paging File | 86,89% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68,36 Gb Total Space | 18,04 Gb Free Space | 26,39% Space Free | Partition Type: NTFS
Drive E: | 164,52 Gb Total Space | 47,93 Gb Free Space | 29,14% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 120,09 Gb Free Space | 25,78% Space Free | Partition Type: NTFS

Computer Name: ADMIN-71E0702F0 | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.03.08 14:29:42 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\OTL.exe
PRC - [2012.02.22 23:00:52 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.02.22 18:29:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012.02.02 02:44:30 | 003,329,824 | ---- | M] (Akamai Technologies, Inc) -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe
PRC - [2011.11.28 19:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011.11.28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011.08.09 16:56:40 | 000,417,112 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011.08.09 16:40:34 | 000,763,224 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011.08.09 16:38:38 | 000,328,536 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011.08.04 13:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2010.05.07 17:06:04 | 000,719,688 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2010.05.07 17:04:20 | 001,051,976 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2008.11.10 20:26:26 | 000,554,264 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006.05.31 22:55:42 | 001,368,064 | ---- | M] (FlashGet.com) -- C:\Program Files\FlashGet\flashget.exe
PRC - [2005.01.14 08:32:38 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe


========== Modules (No Company Name) ==========

MOD - [2012.03.07 19:10:33 | 001,721,856 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12030701\algo.dll
MOD - [2012.02.22 23:00:51 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.12.07 09:42:26 | 000,213,552 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.04.11 18:48:06 | 000,327,680 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2010.03.15 11:28:24 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008.04.14 04:21:47 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2005.01.14 08:32:38 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2012.02.22 18:29:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011.11.28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011.08.09 16:38:38 | 000,328,536 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2011.08.04 13:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.06.12 10:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.08.17 18:08:03 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010.05.07 17:04:20 | 001,051,976 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010.05.07 17:01:04 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010.03.29 07:53:22 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2010.01.26 11:41:08 | 000,652,800 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.11.10 20:26:26 | 000,554,264 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005.01.14 08:32:38 | 000,053,248 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PAStiSvc.exe -- (STI Simulator)
SRV - [2001.01.22 23:20:54 | 001,089,536 | ---- | M] () [Auto | Stopped] -- C:/apache/mysql/bin/mysqld-nt.exe -- (MySql)
SRV - [2000.10.10 19:56:16 | 000,020,480 | ---- | M] () [Auto | Stopped] -- C:\apache\Apache.exe -- (Apache)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (Video3D)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (upperdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (RTL2831UUSB)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (RTL2831UBDA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | Auto | Stopped] -- -- (EIO)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (EagleNT)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (catchme)
DRV - File not found [Kernel | System | Stopped] -- -- (asusgsb)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (aozhlcl4)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (an37u9sn)
DRV - [2011.11.28 18:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011.11.28 18:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011.11.28 18:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011.11.28 18:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011.11.28 18:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011.11.28 18:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011.11.28 18:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011.08.20 13:10:25 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2010.04.18 12:07:17 | 000,639,224 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.02.25 10:18:08 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.11.26 21:52:48 | 000,540,000 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2009.11.26 21:52:48 | 000,044,704 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2009.11.26 21:51:45 | 000,971,232 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\tdrpm147.sys -- (tdrpman147) Acronis Try&Decide and Restore Points filter (build 147)
DRV - [2009.11.26 21:51:27 | 000,134,272 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
DRV - [2009.01.20 19:45:39 | 000,015,600 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2008.09.03 06:02:58 | 003,300,864 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008.08.26 08:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.07.02 20:38:14 | 000,089,600 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2008.02.27 00:22:00 | 000,007,040 | ---- | M] (Compro Tech., Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ComproHID.sys -- (ComproHID)
DRV - [2007.09.05 10:31:30 | 004,611,072 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.06.28 12:46:42 | 000,020,480 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007.06.28 12:46:40 | 000,045,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006.12.26 13:54:35 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006.11.11 02:25:20 | 000,066,944 | ---- | M] (TOSHIBA Corporation) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\thdudf.sys -- (thdudf)
DRV - [2006.07.01 21:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.04.08 09:46:18 | 000,162,176 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc027.sys -- (PAC207)
DRV - [2004.07.09 03:26:38 | 000,015,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2003.07.23 10:44:18 | 000,018,848 | ---- | M] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\MLPTDR_Q.SYS -- (MLPTDR_Q)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKLM\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 1FD06B81EA}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTer ... 1fd06b81ea
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q ... &ch_id=osd
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... Page}&rlz=
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2645238
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{E52BE12D-A44A-4f51-9DC1-34F37A488CC7}: "URL" = http://search.videodownload-toolbar.com ... arch-field
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 1FD06B81EA}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Security Customized Web Search"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.9.4
FF - prefs.js..extensions.enabledItems: {003D3EDC-99B9-4a34-9C20-60CB94F7E829}:2010.25.36
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2
FF - prefs.js..extensions.enabledItems: wrc@avast.com:20110101
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/firefox"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011.12.07 09:44:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.22 23:00:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.02.22 18:29:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

[2009.01.20 19:22:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Extensions
[2012.03.08 10:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions
[2012.02.14 08:03:11 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009.09.06 16:17:41 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
[2009.09.02 10:53:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(2)
[2010.01.07 09:10:36 | 000,000,000 | ---D | M] (CookieCuller) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2009.01.27 14:25:49 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
[2011.10.24 11:14:28 | 000,000,939 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\searchplugins\conduit.xml
[2012.03.02 18:08:50 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\searchplugins\icqplugin.xml
[2009.06.26 19:33:54 | 000,000,986 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\searchplugins\subbiee.xml
[2011.12.23 11:03:24 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\searchplugins\sweetim.xml
[2012.02.22 19:43:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.02.22 19:43:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LZHODMMD.DEFAULT\EXTENSIONS\{1018E4D6-728F-4B20-AD56-37578A4DE76B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LZHODMMD.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LZHODMMD.DEFAULT\EXTENSIONS\{99B98C2C-7274-45A3-A640-D9DF1A1C8460}
[2012.02.22 23:00:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009.08.03 14:07:42 | 000,373,104 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
[2012.01.28 09:20:35 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.02.22 23:00:46 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.02.22 23:00:46 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.11.02 16:54:31 | 000,003,803 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml
[2012.02.22 23:00:46 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.02.22 23:00:46 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.02.22 23:00:46 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTer ... 1fd06b81ea
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: Office Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
CHR - Extension: Gmail = C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012.02.17 10:11:59 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O2 - BHO: (IeCatch5 Class) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\Jccatch.dll (FlashGet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O3 - HKLM\..\Toolbar: (FlashGet Bar) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Bonus.SSR.FR11] C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe (ABBYY.)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - Startup: C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění\FlashGet.lnk = C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm ()
O8 - Extra context menu item: &Stáhnout všechno FlashGetem - C:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: Add to AMV/AVI Video Converter... - C:\Program Files\Media Player Utilities 4.22\AMVConverter\grab.html ()
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Od&eslat do aplikace OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O8 - Extra context menu item: Stahnou vse FlashGet3 - C:\Documents and Settings\Admin\Data aplikací\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: Stahnout FlashGet3 - C:\Documents and Settings\Admin\Data aplikací\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: Stáhnout pomocí FlashGet - C:\Program Files\FlashGet\jc_link.htm ()
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - C:\Program Files\FlashGet\jc_all.htm ()
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O15 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 2454824570 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 82.100.29.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C74E05C-8AF8-410E-80C2-CB6D7CAAEA42}: DhcpNameServer = 192.168.0.1 82.100.29.65
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2012.03.08 14:29:36 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\OTL.exe
[2012.03.06 17:46:23 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.03.06 17:06:04 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.03.06 17:06:04 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.03.06 17:06:04 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.03.06 17:06:04 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.03.06 17:01:53 | 004,427,148 | R--- | C] (Swearware) -- C:\Documents and Settings\Admin\Plocha\ComboFix.exe
[2012.03.05 14:09:49 | 155,355,040 | ---- | C] (Check Point Software Technologies LTD) -- C:\Documents and Settings\Admin\Plocha\zaSetup_101_079_000.exe
[2012.03.05 13:58:40 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin\Recent
[2012.03.04 23:08:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012.03.04 23:08:09 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.03.04 21:43:38 | 000,000,000 | ---D | C] -- C:\Program Files\ZoneAlarm_Security
[2012.03.04 09:48:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Plocha\kerndlova_tereza__schody_z_nebe
[2012.02.28 13:49:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Dokumenty\LOCO
[2012.02.28 10:37:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Nero
[2012.02.28 10:37:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Dokumenty\NeroVideo
[2012.02.27 14:28:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\NabÝdka Start
[2012.02.27 13:38:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai
[2012.02.26 13:27:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Nero
[2012.02.26 13:27:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2012.02.26 10:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Nero 7 Premium
[2012.02.24 20:44:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Plocha\Alkehol - 20 let na tahu (CZ 2CD 2012)
[2012.02.24 20:44:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Plocha\SKWOR - Drsnej kraj (2011)
[2012.02.22 19:50:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Sun
[2012.02.22 19:43:08 | 000,224,136 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.02.22 19:43:08 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.02.22 19:43:08 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.02.22 18:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.02.22 18:29:44 | 000,637,848 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2012.02.22 18:28:49 | 000,141,312 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012.02.22 18:28:29 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.02.20 22:52:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikacĂ­
[2012.02.20 22:37:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\CheckPoint
[2012.02.20 19:12:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Kaspersky SDK
[2012.02.19 10:29:09 | 000,000,000 | ---D | C] -- C:\rsit
[2012.02.18 22:52:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Plocha\UDG
[2012.02.12 16:04:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\CrashRpt
[2010.11.03 11:33:35 | 000,695,296 | ---- | C] (AnjoCaido) -- C:\Documents and Settings\Admin\Data aplikací\MinecraftSP.exe

========== Files - Modified Within 30 Days ==========

[2012.03.08 14:33:20 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.03.08 14:29:42 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\OTL.exe
[2012.03.08 10:29:03 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2012.03.08 10:27:20 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012.03.08 10:24:28 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2012.03.08 10:24:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.03.08 10:24:08 | 000,045,668 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2012.03.07 22:10:42 | 734,581,440 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Kokain-CZ-dabing---Krimi--Drama,-USA,-2001-(nejlepsi-filmy.mypage.cz).avi
[2012.03.06 17:02:31 | 004,427,148 | R--- | M] (Swearware) -- C:\Documents and Settings\Admin\Plocha\ComboFix.exe
[2012.03.06 16:38:10 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.03.05 14:13:58 | 155,355,040 | ---- | M] (Check Point Software Technologies LTD) -- C:\Documents and Settings\Admin\Plocha\zaSetup_101_079_000.exe
[2012.03.04 21:45:22 | 000,415,797 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2012.03.04 21:21:13 | 000,271,200 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2012.03.04 11:05:54 | 000,000,161 | ---- | M] () -- C:\Documents and Settings\Admin\default.pls
[2012.03.01 23:17:22 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Zástupce - iw4mp.lnk
[2012.03.01 11:13:39 | 000,003,048 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2012.02.29 13:07:17 | 000,138,160 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2012.02.29 13:06:50 | 000,271,200 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.ex0
[2012.02.28 21:47:11 | 000,137,216 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.02.28 21:37:55 | 000,000,229 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012.02.28 10:03:59 | 000,479,154 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.02.28 10:03:59 | 000,475,166 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.02.28 10:03:59 | 000,090,428 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.02.28 10:03:59 | 000,077,936 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.02.23 09:18:36 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012.02.22 21:14:32 | 000,000,642 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Easy CD-DA Extractor.lnk
[2012.02.22 18:29:32 | 000,224,136 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.02.22 18:29:32 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.02.22 18:29:32 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.02.22 18:29:32 | 000,141,312 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012.02.22 18:29:31 | 000,637,848 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2012.02.22 18:29:31 | 000,567,696 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012.02.22 17:51:59 | 000,230,432 | ---- | M] () -- C:\StiImg.dat
[2012.02.19 10:21:52 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.02.19 10:17:48 | 000,032,926 | ---- | M] () -- C:\Documents and Settings\Admin\Dokumenty\cc_20120219_101624.reg
[2012.02.19 10:13:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.02.17 10:11:59 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.02.14 11:26:50 | 000,000,293 | RHS- | M] () -- C:\boot.ini
[2012.02.14 08:55:27 | 004,122,825 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Luštěla---Patnactiny.mp3
[2012.02.13 15:52:00 | 000,591,360 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Utopenci_+_hermelinci.pps
[2012.02.12 16:05:08 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\steam_md4.dat
[2012.02.10 22:25:51 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Madagaskar 2(TM).lnk

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#38 Příspěvek od civrs »

========== Files Created - No Company Name ==========

[2012.03.08 14:33:20 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.03.07 21:27:44 | 734,581,440 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\Kokain-CZ-dabing---Krimi--Drama,-USA,-2001-(nejlepsi-filmy.mypage.cz).avi
[2012.03.06 17:06:04 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.03.06 17:06:04 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.03.06 17:06:04 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.03.06 17:06:04 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.03.06 17:06:04 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.03.04 21:45:22 | 000,415,797 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2012.03.01 23:17:28 | 000,000,944 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\Zástupce - iw4mp.lnk
[2012.02.28 11:46:58 | 000,288,582 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1614895754-220523388-1801674531-1004-0.dat
[2012.02.28 11:46:57 | 000,288,582 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
[2012.02.22 21:14:32 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Easy CD-DA Extractor.lnk
[2012.02.22 20:56:08 | 000,270,142 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop
[2012.02.19 10:16:27 | 000,032,926 | ---- | C] () -- C:\Documents and Settings\Admin\Dokumenty\cc_20120219_101624.reg
[2012.02.15 08:05:51 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.15 08:05:51 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012.02.13 20:08:14 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění\FlashGet.lnk
[2012.02.13 15:52:00 | 000,591,360 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\Utopenci_+_hermelinci.pps
[2012.02.12 16:05:08 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\steam_md4.dat
[2012.02.10 22:25:51 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Madagaskar 2(TM).lnk
[2012.01.11 22:13:16 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.05 16:37:48 | 000,000,044 | ---- | C] () -- C:\WINDOWS\Visit MumboJumbo.com.url
[2011.10.10 21:29:37 | 000,000,281 | ---- | C] () -- C:\WINDOWS\game.ini
[2011.09.22 23:11:17 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2011.05.08 07:40:26 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011.04.16 17:53:31 | 000,000,064 | ---- | C] () -- C:\WINDOWS\GPlrLanc.dat
[2010.12.12 10:54:40 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\SRDownloader.nast
[2010.10.28 15:46:09 | 002,601,752 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_moh.exe
[2010.08.31 14:53:17 | 000,038,468 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\Hodnoty oddělené čárkami (Windows).ADR
[2010.06.30 22:36:59 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\PnkBstrK.sys
[2010.05.30 20:46:52 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\SI.bin

========== LOP Check ==========

[2012.03.05 13:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\.minecraft
[2010.08.28 21:26:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Acronis
[2009.08.30 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Allstar
[2010.07.28 20:22:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Any Video Converter Professional
[2012.01.28 09:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Babylon
[2010.02.14 11:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\BITS
[2009.10.04 18:26:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Braid
[2012.02.20 22:25:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CheckPoint
[2009.01.21 23:25:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.09.06 15:23:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\DMCache
[2009.07.07 15:33:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\EleFun Games
[2009.01.21 19:15:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ESET
[2009.01.27 15:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Expert SoftWorks
[2010.02.14 11:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FlashGet
[2010.02.14 11:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FlashGetBHO
[2009.06.09 18:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FLVPlayer4Free
[2009.07.07 15:40:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Gaijin Ent
[2009.11.29 14:48:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\GARMIN
[2009.07.04 09:14:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\GlarySoft
[2010.11.29 16:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\gtk-2.0
[2012.02.05 18:33:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\HLSW
[2009.09.14 18:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2009.09.06 16:17:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\IDM
[2011.12.03 19:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\IObit
[2011.05.12 20:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\LangSoft
[2010.11.11 14:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Leadertech
[2010.11.07 15:09:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mobile Atlas Creator
[2009.07.29 16:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Monotea
[2010.11.02 16:56:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\MyHeritage
[2010.06.10 11:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia
[2009.07.14 22:00:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PC Suite
[2011.03.14 19:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PlayFirst
[2010.08.30 20:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\SPORE
[2010.01.06 16:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\TMNT
[2009.01.21 21:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\TuneUp Software
[2010.04.18 12:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Ubisoft
[2011.02.12 08:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Uniblue
[2011.09.01 16:46:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Unity
[2011.12.28 23:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\uTorrent
[2011.07.02 10:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\VisualShape
[2012.02.19 10:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Vso
[2011.01.03 22:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Zoner
[2012.01.22 12:02:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\GlarySoft
[2009.10.04 18:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\2DBoy
[2009.06.08 14:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2011.07.02 10:51:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2010.02.13 21:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2012.01.28 09:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Babylon
[2011.09.29 10:49:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Big Fish Games
[2012.02.20 22:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CheckPoint
[2010.10.28 15:48:28 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\DSS
[2011.01.16 12:14:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EA Core
[2012.02.22 21:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Easy CD-DA Extractor
[2011.01.16 12:14:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2009.01.21 19:11:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2011.04.16 17:53:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Frag Games
[2009.09.14 18:26:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.07.14 21:53:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2012.01.28 09:20:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\InstallMate
[2011.12.03 20:21:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2012.02.20 19:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Kaspersky SDK
[2011.05.12 20:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LangSoft
[2012.02.20 18:32:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Monotea
[2011.11.05 16:38:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MumboJumbo
[2010.11.11 11:10:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MyHeritage
[2011.03.14 19:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MythPeople
[2010.06.09 19:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\OviInstallerCache
[2009.07.14 22:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2011.12.23 09:53:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Premium
[2011.10.20 19:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Solidshield
[2012.01.01 19:14:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2012.02.22 21:15:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.08.16 22:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2010.04.18 12:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
[2011.07.02 10:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\VisualShape
[2009.11.18 18:21:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vivendi Universal Games
[2009.10.11 16:12:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\vsosdk
[2009.11.26 21:59:54 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2010.08.16 22:01:04 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2009.01.22 15:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2010.08.17 18:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\TuneUp Software
[2012.03.08 10:24:28 | 000,000,270 | ---- | M] () -- C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2012.03.08 10:27:20 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Advanced SystemCare 4" = C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe -- [2011.08.09 16:56:40 | 000,417,112 | ---- | M] (IObit)
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2007.01.05 20:57:50 | 000,204,288 | ---- | M] (Microsoft Corporation)
"Akamai NetSession Interface" = "C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe" -- [2012.02.02 02:44:30 | 003,329,824 | ---- | M] (Akamai Technologies, Inc)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)

< >


< MD5 for: AGP440.SYS >
[2006.03.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2006.03.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2006.03.02 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2006.03.02 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2006.03.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2006.03.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: CSRSS.EXE >
[2006.03.02 13:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=490E6E57E54FAF5F23F658EA188405A1 -- C:\WINDOWS\$NtServicePackUninstall$\csrss.exe
[2008.04.14 04:22:17 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\ServicePackFiles\i386\csrss.exe
[2008.04.14 04:22:17 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\csrss.exe

< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2006.03.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: FASTFAT.SYS >
[2006.03.02 13:00:00 | 000,143,360 | ---- | M] (Microsoft Corporation) MD5=3117F595E9615E04F05A54FC15A03B20 -- C:\WINDOWS\$NtServicePackUninstall$\fastfat.sys
[2008.04.13 20:14:29 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\ServicePackFiles\i386\fastfat.sys
[2008.04.13 20:14:29 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\system32\drivers\fastfat.sys

< MD5 for: HAL.DLL >
[2006.03.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 19:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.03.02 13:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2006.03.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys

< MD5 for: ISAPNP.SYS >
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2009.01.20 14:12:46 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2006.03.02 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2006.03.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2006.03.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2006.03.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: NTFS.SYS >
[2008.04.13 20:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
[2008.04.13 20:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
[2006.03.02 13:00:00 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys

< MD5 for: SCECLI.DLL >
[2006.03.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2006.03.02 13:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 04:22:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 04:22:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SMSS.EXE >
[2006.03.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 14:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2006.03.02 13:00:00 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=21B6FAA88044A41640E03EBB68BE93E8 -- C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2008.04.14 04:22:48 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008.04.14 04:22:48 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2006.03.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=4AFB3B0919649F95C1964AA1FAD27D73 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 13:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2006.03.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2006.03.02 13:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2006.03.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< >

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003.07.23 10:44:18 | 000,010,240 | ---- | M] (Zenographics, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_Q.DLL
[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 13:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2008.04.14 04:21:36 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008.04.14 04:21:36 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008.04.14 04:21:36 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008.04.14 04:21:36 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008.04.14 04:21:36 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008.04.14 04:21:36 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008.04.14 04:21:36 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008.09.03 02:17:56 | 000,053,248 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2erec.dll
[2004.07.17 11:36:24 | 000,064,352 | ---- | M] () -- C:\WINDOWS\system32\drivers\ativmc20.cod
[2008.04.14 04:21:37 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008.04.14 04:21:37 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008.04.14 04:21:37 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008.04.14 04:21:37 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008.04.14 04:21:37 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008.04.14 04:21:38 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2004.07.17 22:55:24 | 000,129,045 | ---- | M] () -- C:\WINDOWS\system32\drivers\cxthsfs2.cty
[2006.03.02 13:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2006.03.02 13:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
[2009.07.14 21:39:41 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009.07.14 22:00:36 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2009.07.14 22:01:13 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_user_01_07_00.Wdf
[2009.07.14 21:39:47 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2009.07.14 22:00:37 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
[2009.07.14 22:01:19 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
[2004.07.17 11:35:00 | 000,067,866 | ---- | M] () -- C:\WINDOWS\system32\drivers\netwlan5.img
[2007.05.27 21:57:28 | 000,001,732 | ---- | M] () -- C:\WINDOWS\system32\drivers\nvphy.bin
[2008.04.14 04:21:55 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008.04.14 04:22:04 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.04.18 12:07:17 | 000,639,224 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2012.03.08 10:24:08 | 000,045,668 | ---- | M] () -- C:\WINDOWS\system32\ativvaxx.cap
[2012.03.04 21:21:13 | 000,271,200 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.xtr
[2012.03.04 21:45:22 | 000,415,797 | ---- | M] () -- C:\WINDOWS\system32\vsconfig.xml
[2012.03.06 16:38:10 | 000,012,598 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\config\*.sav >
[2009.01.20 20:20:03 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009.01.20 20:20:03 | 000,638,976 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009.01.20 20:20:03 | 000,458,752 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[2 C:\WINDOWS\system32\CatRoot\*.tmp files -> C:\WINDOWS\system32\CatRoot\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2009.01.20 20:23:06 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2010.09.21 19:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\Reader\9.3\ARM\12697\AcrobatUpdater.exe
[2010.09.21 19:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\Reader\9.3\ARM\12697\AdobeARM.exe
[2010.09.21 19:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\Reader\9.3\ARM\12697\ReaderUpdater.exe
[2012.01.03 18:46:15 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\Setup\{AC76BA86-7AD7-1029-7B44-A95000000001}\Setup.exe
[2011.08.19 05:31:14 | 015,548,856 | ---- | M] (Big Fish Games) -- C:\Documents and Settings\All Users\Data Aplikací\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe
[2011.08.19 05:31:20 | 000,144,504 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\BigFishGamesCache\Upgrade\stub\luxor-5th-passage_s1_l1_gF6032T1L1_d1475154403.exe
[2011.08.19 05:31:20 | 000,144,504 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\BigFishGamesCache\Upgrade\stub\luxor2_s1_l1_gF1214T1L1_d1473395529.exe
[2011.08.19 05:31:20 | 000,144,504 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\BigFishGamesCache\Upgrade\stub\zumas-revenge-adventure_s1_l1_gF5701T1L1_d1473712708.exe
[2011.09.29 10:48:45 | 015,608,136 | ---- | M] (Big Fish Games) -- C:\Documents and Settings\All Users\Data Aplikací\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe
[2001.09.05 02:23:24 | 000,056,320 | ---- | M] (InstallShield Software Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\Frag Games\Setup.exe
[2009.07.14 21:53:14 | 033,921,368 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_cze_web.exe
[2009.07.14 21:53:40 | 000,095,232 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
[2009.07.14 21:53:40 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
[2009.07.14 21:53:40 | 000,010,240 | ---- | M] (Nokia) -- C:\Documents and Settings\All Users\Data Aplikací\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
[2009.07.14 21:53:40 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
[2012.01.06 08:31:54 | 000,015,496 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Data Aplikací\InstallMate\{365E2145-FF2B-BF95-82D7-7AAAD2B98D5D}\Setup.exe
[2011.12.17 05:10:35 | 000,015,496 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Data Aplikací\InstallMate\{DBB02F63-2284-42AA-B1BC-F2912BC5B32B}\Setup.exe
[2011.05.12 20:50:58 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\LangSoft\OETRN.EXE
[2009.10.24 09:46:37 | 000,424,448 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMS Sender 2009\Update\219\smszdarma219.exe
[2009.10.27 16:01:59 | 000,424,448 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMS Sender 2009\Update\220\smszdarma220.exe
[2010.05.23 15:58:21 | 003,849,337 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\225\update.exe
[2010.06.30 14:42:34 | 003,829,957 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\226\update.exe
[2010.07.21 21:03:26 | 003,833,330 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\301\update.exe
[2010.09.30 14:28:50 | 000,524,288 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\303\update.exe
[2010.11.05 16:10:21 | 003,835,089 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\304\update.exe
[2010.11.15 14:42:56 | 004,205,111 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\305\update.exe
[2010.11.19 15:27:55 | 000,979,320 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\306\update.exe
[2010.12.15 20:36:39 | 000,981,353 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\307\update.exe
[2012.01.25 18:32:55 | 004,869,855 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\311\update.exe
[2012.01.26 18:00:06 | 004,884,187 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\312\update.exe
[2012.02.05 20:09:42 | 004,885,452 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\313\update.exe
[2012.02.16 11:43:26 | 001,250,000 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\316\update.exe
[2012.02.20 18:32:50 | 005,122,382 | ---- | M] (David Kořínek ) -- C:\Documents and Settings\All Users\Data Aplikací\Monotea\All Users\SMSS3\Update\317\update.exe
[2009.06.08 13:36:09 | 000,281,625 | R--- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Norton\Norton2009Reset.exe
[2010.06.09 19:46:56 | 098,366,952 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Nokia_Ovi_Suite_PCS_Update.exe
[2010.06.09 21:07:27 | 000,050,000 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\pcswpc.exe
[2010.06.09 21:07:27 | 000,077,824 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\Run_XML6_SP1.exe
[2010.06.09 21:07:27 | 000,058,880 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMF11Runx64.exe
[2010.06.09 21:07:28 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMF11Runx86.exe
[2010.06.09 21:07:31 | 013,930,312 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
[2010.06.09 21:07:34 | 012,212,040 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
[2009.07.25 15:50:34 | 000,428,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype Extras\Plugins\7A35F6B8E3B747518F5737995988E6FB\rubit.exe
[2009.07.25 15:50:34 | 005,687,296 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype Extras\Plugins\7A35F6B8E3B747518F5737995988E6FB\callburner\CallBurner.exe
[2009.07.25 15:50:34 | 000,428,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7A35F6B8E3B747518F5737995988E6FB\rubit.exe
[2009.07.25 15:50:34 | 005,687,296 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7A35F6B8E3B747518F5737995988E6FB\callburner\CallBurner.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2012.03.05 13:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\.minecraft
[2011.09.20 20:05:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ABBYY
[2010.08.28 21:26:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Acronis
[2012.02.03 18:48:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Adobe
[2009.01.25 12:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Ahead
[2009.08.30 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Allstar
[2010.07.28 20:22:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Any Video Converter Professional
[2012.01.28 09:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Babylon
[2010.02.14 11:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\BITS
[2009.10.04 18:26:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Braid
[2012.02.20 22:25:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CheckPoint
[2009.01.21 23:25:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.09.06 15:23:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\DMCache
[2009.07.07 15:33:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\EleFun Games
[2009.01.21 19:15:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ESET
[2009.01.27 15:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Expert SoftWorks
[2010.02.14 11:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FlashGet
[2010.02.14 11:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FlashGetBHO
[2009.06.09 18:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\FLVPlayer4Free
[2009.07.07 15:40:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Gaijin Ent
[2009.11.29 14:48:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\GARMIN
[2009.07.04 09:14:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\GlarySoft
[2009.11.07 20:09:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Google
[2010.11.29 16:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\gtk-2.0
[2011.06.15 17:03:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Hamachi
[2009.10.04 13:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Help
[2012.02.05 18:33:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\HLSW
[2009.09.14 18:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2009.01.20 19:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Identities
[2009.09.06 16:17:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\IDM
[2009.01.20 19:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\InstallShield
[2011.12.03 19:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\IObit
[2011.05.12 20:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\LangSoft
[2010.11.11 14:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Leadertech
[2009.01.21 17:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Macromedia
[2010.02.13 12:43:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
[2011.04.18 15:18:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Media Player Classic
[2012.02.27 14:44:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Admin\Data aplikací\Microsoft
[2010.11.08 19:16:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Microsoft Games
[2010.11.07 15:09:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mobile Atlas Creator
[2009.07.29 16:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Monotea
[2009.01.20 19:22:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mozilla
[2010.11.02 16:56:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\MyHeritage
[2012.02.28 10:33:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nero
[2010.06.10 11:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia
[2009.07.14 22:00:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PC Suite
[2011.03.14 19:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PlayFirst
[2009.09.21 16:19:03 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Admin\Data aplikací\SecuROM
[2012.03.08 14:29:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Skype
[2011.06.23 17:02:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\skypePM
[2010.08.30 20:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\SPORE
[2009.06.09 09:13:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Sun
[2010.01.06 16:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\TMNT
[2009.01.21 21:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\TuneUp Software
[2010.04.18 12:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Ubisoft
[2011.02.12 08:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Uniblue
[2011.09.01 16:46:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Unity
[2011.12.28 23:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\uTorrent
[2011.07.02 10:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\VisualShape
[2012.02.19 10:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Vso
[2011.01.23 14:23:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\WinRAR
[2011.01.03 22:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Zoner

< %APPDATA%\*.* >
[2009.01.20 20:23:06 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Admin\Data aplikací\desktop.ini
[2010.11.04 22:19:14 | 000,038,468 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Hodnoty oddělené čárkami (Windows).ADR
[2009.01.24 20:29:24 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\inst.exe
[2010.10.20 15:00:02 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Documents and Settings\Admin\Data aplikací\MinecraftSP.exe
[2009.01.24 20:29:24 | 000,007,887 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\pcouffin.cat
[2009.01.24 20:29:24 | 000,001,144 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\pcouffin.inf
[2009.01.24 20:29:32 | 000,000,034 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\pcouffin.log
[2009.01.24 20:29:24 | 000,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\Admin\Data aplikací\pcouffin.sys
[2011.10.10 21:30:00 | 000,022,328 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\PnkBstrK.sys
[2012.02.12 16:05:08 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\steam_md4.dat
[2011.12.25 15:15:26 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\vso_ts_preview.xml

< %APPDATA%\*.exe /s >
[2009.01.24 20:29:24 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\inst.exe
[2010.10.20 15:00:02 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Documents and Settings\Admin\Data aplikací\MinecraftSP.exe
[2011.04.01 14:35:10 | 000,123,674 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\.minecraft\MinecraftLauncher.exe
[2011.05.08 12:48:38 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Documents and Settings\Admin\Data aplikací\.minecraft\Minecraft_beta.exe
[2010.01.01 14:12:21 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_2CB28812C6987905FED019.exe
[2010.01.01 14:12:20 | 000,001,518 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_3CF308077C90516B1F4B38.exe
[2010.01.01 14:12:21 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_426B928B2B076954171F35.exe
[2010.01.01 14:12:20 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_6FEFF9B68218417F98F549.exe
[2010.01.01 14:12:21 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_B3CD640DEBF0644E1183FA.exe
[2010.01.01 14:12:21 | 000,002,550 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_C6CC5DBCD6C60EDD4AD668.exe
[2012.03.07 16:22:55 | 000,172,336 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\lzhodmmd.default\FlashGot.exe
[2010.07.09 09:42:45 | 069,222,840 | ---- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe

< %SYSTEMDRIVE%\*.exe >

< >

< >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-06 15:41:26

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s >
"StateIndex" = 1

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
PENDINGFILERENAMEOPERATIONS REG_MULTI_SZ \??\C:\DOCUME~1\Admin\LOCALS~1\Temp\i4jdel0.exe\0\0\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\e4j4F.tmp_dir\MinecraftSP.jar\0\0\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\e4j4F.tmp_dir\0\0\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\i4jdel0.exe\0\0\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\ide50.tmp\0\0\0

< >

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=3
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.03.08 14:33:20 | 000,000,512 | ---- | M] () MD5=D85824C04DB0681BAD1F7BCDC0C75F7E -- C:\PhysicalMBR.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 6144 bytes -> C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1493A0EF

< End of report >

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#39 Příspěvek od civrs »

OTL Extras logfile created on: 8.3.2012 14:31:09 - Run 1
OTL by OldTimer - Version 3.2.36.1 Folder = C:\Documents and Settings\Admin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,50 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 78,62% Memory free
4,84 Gb Paging File | 4,20 Gb Available in Paging File | 86,89% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68,36 Gb Total Space | 18,04 Gb Free Space | 26,39% Space Free | Partition Type: NTFS
Drive E: | 164,52 Gb Total Space | 47,93 Gb Free Space | 29,14% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 120,09 Gb Free Space | 25,78% Space Free | Partition Type: NTFS

Computer Name: ADMIN-71E0702F0 | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
https [open] -- Reg Error: Key error.
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"5985:TCP" = 5985:TCP:*:Disabled:Vzdálená správa systému Windows
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Služba Windows Media Player Network Sharing

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget -- (FlashGet.com)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"F:\PC HRY INSTAL\Need for Speed Hot Pursuit (2010) CZ\NFS11.exe" = F:\PC HRY INSTAL\Need for Speed Hot Pursuit (2010) CZ\NFS11.exe:*:Enabled:Need for Speed(TM) Hot Pursuit Application -- (Electronic Arts)
"F:\PC HRY INSTAL\iw3mpHAMACHI 1.7.exe" = F:\PC HRY INSTAL\iw3mpHAMACHI 1.7.exe:*:Enabled:iw3mpHAMACHI 1.7 -- ()
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"F:\PC HRY INSTAL\COD4\iw3mp.exe" = F:\PC HRY INSTAL\COD4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) -- ()
"F:\PC HRY INSTAL\Need for Speed Hot Pursuit (2010) CZ\Launcher.exe" = F:\PC HRY INSTAL\Need for Speed Hot Pursuit (2010) CZ\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit -- (Electronic Arts)
"C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe" = C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface -- (Akamai Technologies, Inc)
"F:\PC HRY INSTAL\LOcO\Alaplaya\System\LOCO.exe" = F:\PC HRY INSTAL\LOcO\Alaplaya\System\LOCO.exe:*:Enabled:LOCO -- ()
"E:\download\Call of Duty Modern Warfare 2 MP Works 100%\call of duty modern warfare 2\iw4mp.dat" = E:\download\Call of Duty Modern Warfare 2 MP Works 100%\call of duty modern warfare 2\iw4mp.dat:*:Enabled:iw4mp -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{129DDEC1-A6A3-3D60-AABE-76E6E5334922}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - CSY
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217003FF}" = Java(TM) 7 Update 3
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37C8899D-FD70-481F-94AA-1F1B08765E22}" = Acronis True Image Home
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"{47E16407-05D3-4D2A-B2B9-C30700B7C2AD}" = LogMeIn Hamachi
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52E5D8A7-B129-4A29-AD4B-EBB749DCC3A3}_is1" = GamePark klient 2.0.9.0
"{5DB65884-C963-4454-AABA-4CA3089281FA}" = NVIDIA PhysX
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6FE8B722-4D7E-3CD7-BB3A-3AD1684B1295}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - CSY
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7397EDED-F38A-4654-B669-BF61065803D0}" = PC Connectivity Solution
"{74DCC43B-33C9-3389-BD0D-33EB37973657}" = Microsoft .NET Framework 3.5 Language Pack - csy
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.2.3.81
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83A606F5-BF6F-42ED-9F33-B9F74297CDED}" = Need for Speed(TM) Hot Pursuit
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = Media Player Utilities 4.22
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{90140000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 14
"{90140000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0015-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0016-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0018-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-0019-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001A-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001B-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{2304F942-79D2-46F7-A512-269A7F5B7EFC}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-001F-041B-0000-0000000FF1CE}_Office14.PROPLUSR_{A162C5E6-7778-4D5B-9F0A-38F0122DD859}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-002C-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{8148DB19-71B1-4415-8B26-DF5B9E873FC3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-0044-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-006E-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{EEF3E2C0-135B-44DC-BEDD-7F01CFBEFF46}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00A1-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{90140000-00BA-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9E976BE0-B8C1-4DF2-AA84-7048F3075158}" = VideoMate Pure DVB-T USB Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}" = SweetIM Toolbar for Internet Explorer 4.2
"{A81A974F-8A22-43E6-9243-5198FF758DA1}" = SweetIM for Messenger 3.6
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1029-7B44-A95000000001}" = Adobe Reader 9.5.0 - Czech
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D323A4C4-A02D-4B8C-AE50-DFAE5BC8C7F0}_is1" = Monotea SMS Posílač 3 verze 3.17
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{F1100000-0008-0000-0001-074957833700}" = ABBYY FineReader 11
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F14B8ECC-BDA0-4987-9201-D7B7DBE11029}" = Nero 7 Ultra Edition
"{F8C02517-4AC3-4026-8292-ACF23E98A7D7}" = Activision(R)
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"µTorrent CZ_is1" = µTorrent CZ 1.8.1 (build 12639)
"3FA1705966809259F916AF817C59B4F389F4572C" = Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Absolute Uninstaller_is1" = Absolute Uninstaller 2.4
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"ATI Display Driver" = ATI Display Driver
"avast" = avast! Free Antivirus
"BabylonToolbar" = Babylon toolbar on IE
"BFGC" = Big Fish Games: Game Manager
"CCleaner" = CCleaner
"CloneCD" = CloneCD
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2010-10-10
"Cool's_Codec_pack_4.12" = Codec Pack - VobSub 5.0.4.7
"Čeština do Daemon tools 4.08HE" = Čeština do Daemon tools 4.08HE
"Defraggler" = Defraggler
"Drakensang Online" = Drakensang Online
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.1.2.0
"Easy CD-DA Extractor 12" = Easy CD-DA Extractor 12
"ESET Online Scanner" = ESET Online Scanner v3
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"FlashGet(JetCar)" = FlashGet(JetCar)
"FLVPlayer4Free Free FLV Player_is1" = FLVPlayer4Free Free FLV Player 3.4.0.0
"GameParkClient_is1" = GamePark
"Hardlock Device Driver" = Hardlock Device Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{12AF2BD8-797C-426F-8FCA-79716DBA4B10}" = FLOCK!
"InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"InstallShield_{F8C02517-4AC3-4026-8292-ACF23E98A7D7}" = Madagaskar 2(TM)
"JDownloader" = JDownloader
"KONICA MINOLTA PagePro 1350W" = KONICA MINOLTA PagePro 1350W
"Kreslení pro děti (doporučená instalace)" = Kreslení pro děti (doporučená instalace)
"LOCO" = LOCO EVOLUTION
"LogMeIn Hamachi" = LogMeIn Hamachi
"Luxor - Quest for the Afterlife" = Luxor - Quest for the Afterlife (remove only)
"Luxor 3" = Luxor 3 (remove only)
"Luxor: Amun Rising" = Luxor: Amun Rising (remove only)
"Microsoft .NET Framework 3.5 Language Pack - csy" = Microsoft .NET Framework 3.5 Language Pack - CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0.1 (x86 cs)" = Mozilla Firefox 8.0.1 (x86 cs)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Predplacenky.cz 2.0.1" = Predplacenky.cz 2.0.1
"PunkBusterSvc" = PunkBuster Services
"Share Rapid Uploader_is1" = Uploader 1.0
"Táta hrdina" = Táta hrdina
"The Treasures Of Montezuma" = The Treasures Of Montezuma
"Totalcmd" = Total Commander (Remove or Repair)
"TS PRAVOPIS" = TS PRAVOPIS
"TuneUp Utilities" = TuneUp Utilities
"Uloz.to Uploader" = Uloz.to Uploader 1.1.1.122
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"Video Download Toolbar" = Video Download Toolbar
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"xvid" = XviD MPEG-4 Video Codec
"ZonerPhotoStudio13_CZ_is1" = Zoner Photo Studio 13
"Zuma Deluxe RA" = Zuma Deluxe RA

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5.3.2012 8:29:58 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> Apache:
could not open document config file c:/apache/conf/httpd.conf <<< before the error.log
file could be opened. More information may be available in the error.log file.
.

Error - 5.3.2012 9:06:16 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> fopen:
No such file or directory <<< before the error.log file could be opened. More information
may be available in the error.log file. .

Error - 5.3.2012 9:06:16 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> Apache:
could not open document config file c:/apache/conf/httpd.conf <<< before the error.log
file could be opened. More information may be available in the error.log file.
.

Error - 6.3.2012 11:38:31 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> fopen:
No such file or directory <<< before the error.log file could be opened. More information
may be available in the error.log file. .

Error - 6.3.2012 11:38:31 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> Apache:
could not open document config file c:/apache/conf/httpd.conf <<< before the error.log
file could be opened. More information may be available in the error.log file.
.

Error - 6.3.2012 12:15:24 | Computer Name = ADMIN-71E0702F0 | Source = crypt32 | ID = 131080
Description = Načtení automatické aktualizace pořadového čísla kořenového seznamu
jiného výrobce z: <http://www.download.windowsupdate.com/m ... ootseq.txt>
se nezdařilo. Chyba: The server name or address could not be resolved

Error - 7.3.2012 11:10:17 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> fopen:
No such file or directory <<< before the error.log file could be opened. More information
may be available in the error.log file. .

Error - 7.3.2012 11:10:17 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> Apache:
could not open document config file c:/apache/conf/httpd.conf <<< before the error.log
file could be opened. More information may be available in the error.log file.
.

Error - 8.3.2012 5:24:38 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> fopen:
No such file or directory <<< before the error.log file could be opened. More information
may be available in the error.log file. .

Error - 8.3.2012 5:24:38 | Computer Name = ADMIN-71E0702F0 | Source = Apache Service | ID = 3299
Description = The Apache service named Apache reported the following error: >>> Apache:
could not open document config file c:/apache/conf/httpd.conf <<< before the error.log
file could be opened. More information may be available in the error.log file.
.

[ OSession Events ]
Error - 26.7.2009 9:26:22 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 5.9.2009 7:57:48 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 7.9.2009 10:42:56 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 29.9.2009 6:36:50 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 14.10.2009 9:40:12 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 2.6.2011 0:49:41 | Computer Name = ADMIN-71E0702F0 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:24:29 | Computer Name = ADMIN-71E0702F0 | Source = sptd | ID = 262148
Description = Ovladač zjistil interní chybu ve vlastní struktuře dat u .

Error - 8.3.2012 5:25:03 | Computer Name = ADMIN-71E0702F0 | Source = Service Control Manager | ID = 7000
Description = Služba EIO neuspěla při spuštění v důsledku následující chyby: %%2

Error - 8.3.2012 5:26:27 | Computer Name = ADMIN-71E0702F0 | Source = Service Control Manager | ID = 7022
Description = Služba Apache přestala během spouštění reagovat.

Error - 8.3.2012 5:26:27 | Computer Name = ADMIN-71E0702F0 | Source = Service Control Manager | ID = 7034
Description = Služba Apache byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error - 8.3.2012 5:26:27 | Computer Name = ADMIN-71E0702F0 | Source = Service Control Manager | ID = 7034
Description = Služba MySql byla neočekávaně ukončena. Tento stav nastal již 1krát.

[ TuneUp Events ]
Error - 6.1.2010 7:35:32 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 10.1.2010 16:56:11 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 10.1.2010 17:07:56 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 13.2.2010 7:43:32 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 13.2.2010 7:44:27 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 13.2.2010 7:44:37 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 13.2.2010 7:56:56 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 13.2.2010 17:00:32 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 15.2.2010 11:17:24 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 5.11.2011 16:41:45 | Computer Name = ADMIN-71E0702F0 | Source = TuneUp.UtilitiesSvc | ID = 300
Description =


< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#40 Příspěvek od motji »

Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
@Alternate Data Stream - 6144 bytes -> C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1493A0EF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&st=1&q={searchTerms}&barid={5489CFB8-2D4D-11E1-AEB4-001FD06B81EA}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=100888&babsrc=SP_ss&mntrId=b0514483000000000000001fd06b81ea
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2645238
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{E52BE12D-A44A-4f51-9DC1-34F37A488CC7}: "URL" = http://search.videodownload-toolbar.com ... Q&ts=ne&w={searchTerms}&csrc=search-field
IE - HKU\S-1-5-21-1614895754-220523388-1801674531-1004\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&st=1&q={searchTerms}&barid={5489CFB8-2D4D-11E1-AEB4-001FD06B81EA}
O4 - HKU\S-1-5-21-1614895754-220523388-1801674531-1004..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)


:files
 C:\Documents and Settings\Admin\Data aplikací\Babylon
C:\Documents and Settings\All Users\Data aplikací\SweetIM


klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :) .
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#41 Příspěvek od civrs »

Log je tu ale PC se nerestartovalo

========== OTL ==========
ADS C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:1493A0EF deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{E52BE12D-A44A-4f51-9DC1-34F37A488CC7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E52BE12D-A44A-4f51-9DC1-34F37A488CC7}\ not found.
Registry key HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry value HKEY_USERS\S-1-5-21-1614895754-220523388-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully.
C:\Documents and Settings\Admin\Local Settings\Data aplikací\Akamai\netsession_win.exe moved successfully.
========== FILES ==========
C:\Documents and Settings\Admin\Data aplikací\Babylon folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Toolbars\Internet Explorer\cache folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Toolbars\Internet Explorer folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Toolbars folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\update folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\logs folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\packages\FailDialog folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\packages folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\contentdb folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\Bars\Default\400 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\Bars\Default\200 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\Bars\Default\100 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\Bars\Default folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data\Bars folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\data folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\conf\users folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger\conf folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM\Messenger folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\SweetIM folder moved successfully.

OTL by OldTimer - Version 3.2.36.1 log created on 03102012_163454

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#42 Příspěvek od motji »

Omlouvám se, byla jsem u pc bez návodů a zapoměla jsem dát příkaz k restartu.
Jak je na tom počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#43 Příspěvek od civrs »

Jj,to je v pohodě,Pc ale furt takové pomalejší.Start + - 3-4min.Mozilla už zdá se v poho,o dost rychlejší

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pls o kontrolu

#44 Příspěvek od motji »

:arrow: Ještě znovu spustte OTL, klikněte na tlačítko vyčisti, uklidí po sobě :)

Zkuste ještě defragmentovat disk.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Pls o kontrolu

#45 Příspěvek od civrs »

Vyčištěno,defragmentováno a zdá se to lepší,mockrát děkuji :worship:

Odpovědět