Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

o preventivku prosim

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
heges
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 12 črc 2010 12:27

o preventivku prosim

#1 Příspěvek od heges »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2012-10-24 14:12:54
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 14 GB (25%) free of 55 GB
Total RAM: 1012 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:13:15, on 24.10.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vetrak\a1ctl.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Tomas\Local Settings\Data aplikací\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\Tomas.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: a1ctl.lnk = C:\Program Files\Vetrak\a1ctl.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: a1ctl.lnk = C:\Program Files\Vetrak\a1ctl.exe (User 'Default user')
O4 - Startup: a1ctl.lnk = C:\Program Files\Vetrak\a1ctl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 3736929687
O17 - HKLM\System\CCS\Services\Tcpip\..\{570A04B3-381A-4138-824E-C18F858E809D}: NameServer = 94.142.233.120,94.142.233.140
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

--
End of file - 4353 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default

prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, wrc@avast.com:7.0.1466, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
npnul32.dll
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions\
staged-xpis
{20a82645-c095-46ed-80e3-08825760534b}
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-11-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-08-21 4282728]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1044480]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 6749512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2008-02-29 166424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSR Service"=2
"JavaQuickStarterService"=2
"TermService"=3
"TapiSrv"=3
"mnmsrvc"=3
"Fax"=2
"FastUserSwitchingCompatibility"=3
"RDSessMgr"=3
"RasMan"=3
"RasAuto"=3
"QDLService"=2
"ImapiService"=3
"idsvc"=3
"IDriverT"=3
"gupdatem"=3
"gupdate"=2
"FontCache3.0.0.0"=3

C:\Documents and Settings\Tomas\Nabídka Start\Programy\Po spuštění
a1ctl.lnk - C:\Program Files\Vetrak\a1ctl.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Pidgin\pidgin.exe"="C:\Program Files\Pidgin\pidgin.exe:*:Disabled:Pidgin"
"C:\Program Files\OperaTor\Opera\opera.exe"="C:\Program Files\OperaTor\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\WinPcap\rpcapd.exe"="C:\Program Files\WinPcap\rpcapd.exe:*:Enabled:Remote Packet Capture Daemon"
"E:\Tor Browser\Start Tor Browser.exe"="E:\Tor Browser\Start Tor Browser.exe:*:Enabled:Start Tor Browser"
"E:\Tor Browser\App\TOR.EXE"="E:\Tor Browser\App\TOR.EXE:*:Enabled:tor"
"C:\Documents and Settings\Tomas\Plocha\Tor Browser\App\tor.exe"="C:\Documents and Settings\Tomas\Plocha\Tor Browser\App\tor.exe:*:Enabled:tor"
"D:\Tor Browser\App\tor.exe"="D:\Tor Browser\App\tor.exe:*:Enabled:tor"
"C:\Program Files\Vidalia Bundle\Tor\tor.exe"="C:\Program Files\Vidalia Bundle\Tor\tor.exe:*:Enabled:tor"
"C:\Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\buddy-ng.exe"="C:\Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\buddy-ng.exe:*:Enabled:buddy-ng"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"W:\xChat\xchat.exe"="W:\xChat\xchat.exe:*:Disabled:XChat IRC Client"
"Q:\Tor Browser\App\tor.exe"="Q:\Tor Browser\App\tor.exe:*:Enabled:tor"
"C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe"="C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.WMV3"=wmv9vcm.dll

======List of files/folders created in the last 1 month======

2012-10-24 14:12:54 ----D---- C:\rsit
2012-10-23 09:24:03 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-10-12 20:37:36 ----D---- C:\WINDOWS\Minidump
2012-09-25 14:54:55 ----D---- C:\Program Files\CommViewWiFi

======List of files/folders modified in the last 1 month======

2012-10-24 14:13:07 ----D---- C:\Program Files\trend micro
2012-10-24 14:12:54 ----D---- C:\WINDOWS\Prefetch
2012-10-24 13:41:42 ----D---- C:\Documents and Settings\Tomas\Data aplikací\uTorrent
2012-10-24 13:27:09 ----D---- C:\WINDOWS\Temp
2012-10-24 13:13:31 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-24 00:21:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-10-23 09:24:03 ----AD---- C:\WINDOWS\system32
2012-10-22 21:20:00 ----D---- C:\Program Files\Mozilla Firefox
2012-10-16 19:03:59 ----AD---- C:\WINDOWS
2012-10-16 10:37:40 ----HD---- C:\WINDOWS\inf
2012-10-12 22:41:31 ----D---- C:\WINDOWS\Debug
2012-10-12 19:56:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-10-12 19:54:39 ----AD---- C:\WINDOWS\system32\drivers
2012-10-12 19:54:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-10-10 20:44:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-10-10 20:44:20 ----AD---- C:\I386
2012-10-10 20:31:00 ----HD---- C:\WINDOWS\$hf_mig$
2012-10-10 10:17:07 ----D---- C:\Program Files\uTorrent
2012-10-04 10:24:16 ----RD---- C:\Program Files
2012-10-04 10:22:43 ----D---- C:\Program Files\images
2012-10-04 10:17:46 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-04 10:14:24 ----RSD---- C:\WINDOWS\Fonts
2012-09-28 00:32:12 ----A---- C:\WINDOWS\system32\MRT.exe
2012-09-25 23:24:44 ----D---- C:\Hry

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-03-11 97760]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-08-21 25256]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2012-08-21 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-03-11 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-03-11 31704]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2011-06-15 60156]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-11-28 231248]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-08-21 97608]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-08 16896]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-01-07 4968448]
R3 M3000Srv;Acer Crystal Eye webcam Driver; C:\WINDOWS\System32\Drivers\M3000KNT.sys [2008-08-06 151936]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-10-31 117888]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-04-25 225024]
R3 TS_AR5416;[CommView] Atheros AR5008 Wireless Network Adapter Service 7.7; C:\WINDOWS\system32\DRIVERS\ts_athw.sys [2011-09-05 1630056]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 WINIO;WINIO; \??\C:\Program Files\Vetrak\winio.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-20 1312576]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 int15.sys;int15.sys; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
S3 JMCR;JMCR; C:\WINDOWS\system32\DRIVERS\jmcr.sys [2008-07-08 96856]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2011-07-01 26624]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-08-21 44808]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-03-11 1983232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S4 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S4 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 QDLService;Qualcomm Gobi Download Service; C:\QUALCOMM\QDLService\QDLService.exe [2008-08-06 345336]

-----------------EOF-----------------


děkuji

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: o preventivku prosim

#2 Příspěvek od Márty84 »

Zdravim :)

Log vypada cisty. Je s pc nejaky problem?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

heges
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 12 črc 2010 12:27

Re: o preventivku prosim

#3 Příspěvek od heges »

jen pomalu nabiha po uspornem rezimu a po zapnuti
a diky za kontrolu :)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: o preventivku prosim

#4 Příspěvek od Márty84 »

OK, podivame se hloubeji.


:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte.
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).




:arrow: Stahnete crystal disk info http://www.slunecnice.cz/sw/crystaldiskinfo/
Nainstalujte a spustte. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

heges
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 12 črc 2010 12:27

Re: o preventivku prosim

#5 Příspěvek od heges »

z crystadisc

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.5 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows XP Home Edition SP3 [5.1 Build 2600] (x86)
Date : 2012/10/25 9:40:56

-- Controller Map ----------------------------------------------------------
+ Intel(R) 82801GBM/GHM (ICH7-M Family) Serial ATA Storage Controller - 27C4 [ATA]
+ Primární kanál IDE (0)
- Hitachi HTS542580K9SA00
- Sekundární kanál IDE (1)

-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS542580K9SA00 : 80,0 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) Hitachi HTS542580K9SA00
----------------------------------------------------------------------------
Model : Hitachi HTS542580K9SA00
Firmware : BBBOC31P
Serial Number : 081010BB6B00WFE1WLNF
Disk Size : 80,0 GB (8,4/80,0/80,0)
Buffer Size : 7229 KB
Queue Depth : 32
# of Sectors : 156301488
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 3f
Transfer Mode : SATA/150
Power On Hours : 3318 hod.
Power On Count : 1694 krát
Temparature : 32 C (89 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 253 253 _33 000800000000 Čas na roztočení ploten
04 _99 _99 __0 0000000006AB Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _93 _93 __0 000000000CF6 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _99 _99 __0 00000000069E Počet cyklů zapnutí zařízení
BF 100 100 __0 000000010000 Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 000000000030 Počet vypnutí disku
C1 _99 _99 __0 00000000457D Počet cyklů načítání/vymazání
C2 171 171 __0 003100090020 Teplota
C4 100 100 __0 000000000020 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 045A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 3038 3130 3130 4242 3642 3030 5746 4531 574C 4E46
020: 0003 387B 0004 4242 424F 4333 3150 4869 7461 6368
030: 6920 4854 5335 3432 3538 304B 3953 4130 3020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 0F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: F8B0 0950 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1702 0000 005E 0000
080: 01FC 0042 746B 7F69 6163 7469 BC49 6163 207F 0016
090: 0017 4080 FFFE 0000 80FE 0000 0000 0000 0000 0000
100: F8B0 0950 0000 0000 0000 0000 0000 8848 5000 CCA5
110: 35DD 0AFE 0000 0000 0000 0000 0000 0000 0000 4004
120: 4004 0000 0000 0000 0000 0000 0000 0000 0029 000B
130: 04CA 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 4001 0000
150: 8000 0000 4250 0000 0000 9999 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 100F 0021 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 43A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05
010: 00 64 64 00 00 00 00 00 00 00 03 07 00 FD FD 00
020: 00 00 00 08 00 00 04 12 00 63 63 AB 06 00 00 00
030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B
040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00
050: 00 00 00 00 00 00 09 12 00 5D 5D F6 0C 00 00 00
060: 00 00 0A 13 00 64 64 00 00 00 00 00 00 00 0C 32
070: 00 63 63 9E 06 00 00 00 00 00 BF 0A 00 64 64 00
080: 00 01 00 00 00 00 C0 32 00 64 64 30 00 00 00 00
090: 00 00 C1 12 00 63 63 7D 45 00 00 00 00 00 C2 02
0A0: 00 AB AB 20 00 09 00 31 00 00 C4 32 00 64 64 20
0B0: 00 00 00 00 00 00 C5 22 00 64 64 00 00 00 00 00
0C0: 00 00 C6 08 00 64 64 00 00 00 00 00 00 00 C7 0A
0D0: 00 C8 C8 00 00 00 00 00 00 00 DF 0A 00 64 64 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 85 02 01 5B
170: 03 00 01 00 02 2E 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 3E 00 00 00 00 00 00 00 00 00 00 02 28
010: 00 00 00 00 00 00 00 00 00 00 03 21 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43
040: 00 00 00 00 00 00 00 00 00 00 08 28 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00
070: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00
080: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00
090: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00
0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
0D0: 00 00 00 00 00 00 00 00 00 00 DF 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 89



a tady z OTL

OTL logfile created on: 25.10.2012 9:38:35 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Tomas\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1011,88 Mb Total Physical Memory | 526,05 Mb Available Physical Memory | 51,99% Memory free
2,37 Gb Paging File | 1,89 Gb Available in Paging File | 79,75% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53,63 Gb Total Space | 13,33 Gb Free Space | 24,86% Space Free | Partition Type: NTFS
Drive Q: | 9,99 Gb Total Space | 7,19 Gb Free Space | 72,00% Space Free | Partition Type: FAT32

Computer Name: PRCEK | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.10.25 09:36:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomas\Plocha\OTL.exe
PRC - [2012.08.31 22:07:47 | 000,874,896 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2012.08.21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012.05.07 06:36:06 | 000,039,100 | ---- | M] (The Pidgin developer community) -- Q:\PidginPortable\App\Pidgin\pidgin-portable.exe
PRC - [2012.04.07 02:48:40 | 000,137,328 | ---- | M] (PortableApps.com) -- Q:\PidginPortable\PidginPortable.exe
PRC - [2012.03.11 21:13:22 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2012.03.11 21:13:02 | 006,749,512 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2010.11.28 00:31:19 | 001,496,528 | ---- | M] (TrueCrypt Foundation) -- C:\Program Files\TrueCrypt\TrueCrypt.exe
PRC - [2009.08.04 17:30:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Vetrak\a1ctl.exe
PRC - [2008.04.14 15:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2012.10.25 09:31:06 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\Tomas\Local Settings\Temp\nsw3.tmp\System.dll
MOD - [2012.10.25 09:31:06 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\Tomas\Local Settings\Temp\nsw3.tmp\newadvsplash.dll
MOD - [2012.10.25 00:39:25 | 001,821,696 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12102500\algo.dll
MOD - [2012.08.31 22:08:18 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2012.08.31 22:08:17 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2012.08.31 22:08:17 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2012.08.31 22:08:16 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2012.08.31 22:08:16 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dll
MOD - [2012.08.31 22:08:15 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2012.08.31 22:08:15 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012.08.31 22:08:15 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2012.08.31 22:08:14 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012.08.31 22:08:14 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2012.08.31 22:08:14 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012.08.31 22:08:14 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2012.08.31 22:08:13 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll
MOD - [2012.05.07 16:55:52 | 000,456,013 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libcairo-2.dll
MOD - [2012.05.07 16:55:52 | 000,306,912 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\freetype6.dll
MOD - [2012.05.07 16:55:52 | 000,276,024 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libgio-2.0-0.dll
MOD - [2012.05.07 16:55:52 | 000,162,835 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libfontconfig-1.dll
MOD - [2012.05.07 16:55:52 | 000,124,073 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libpng14-14.dll
MOD - [2012.05.07 16:55:52 | 000,071,125 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libpangocairo-1.0-0.dll
MOD - [2012.05.07 16:55:52 | 000,068,344 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\libexpat-1.dll
MOD - [2012.05.07 16:55:52 | 000,058,240 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll
MOD - [2012.05.07 16:55:52 | 000,034,304 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\Gtk\bin\zlib1.dll
MOD - [2012.05.07 06:36:08 | 000,020,196 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\xmppdisco.dll
MOD - [2012.05.07 06:36:08 | 000,015,997 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\xmppconsole.dll
MOD - [2012.05.07 06:36:08 | 000,014,247 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\themeedit.dll
MOD - [2012.05.07 06:36:08 | 000,014,239 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\winprefs.dll
MOD - [2012.05.07 06:36:08 | 000,013,866 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\ticker.dll
MOD - [2012.05.07 06:36:08 | 000,012,661 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\win2ktrans.dll
MOD - [2012.05.07 06:36:08 | 000,010,783 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\timestamp_format.dll
MOD - [2012.05.07 06:36:08 | 000,009,493 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\timestamp.dll
MOD - [2012.05.07 06:36:06 | 000,149,144 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libjabber.dll
MOD - [2012.05.07 06:36:06 | 000,115,911 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libmsn.dll
MOD - [2012.05.07 06:36:06 | 000,112,657 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\liboscar.dll
MOD - [2012.05.07 06:36:06 | 000,089,986 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libymsg.dll
MOD - [2012.05.07 06:36:06 | 000,075,680 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libgg.dll
MOD - [2012.05.07 06:36:06 | 000,065,928 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libsilc.dll
MOD - [2012.05.07 06:36:06 | 000,057,988 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libmxit.dll
MOD - [2012.05.07 06:36:06 | 000,047,803 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libsametime.dll
MOD - [2012.05.07 06:36:06 | 000,039,908 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libmyspace.dll
MOD - [2012.05.07 06:36:06 | 000,039,402 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libnovell.dll
MOD - [2012.05.07 06:36:06 | 000,037,791 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libirc.dll
MOD - [2012.05.07 06:36:06 | 000,035,696 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libbonjour.dll
MOD - [2012.05.07 06:36:06 | 000,027,389 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\spellchk.dll
MOD - [2012.05.07 06:36:06 | 000,023,844 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libsimple.dll
MOD - [2012.05.07 06:36:06 | 000,019,541 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\log_reader.dll
MOD - [2012.05.07 06:36:06 | 000,012,638 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\pidginrc.dll
MOD - [2012.05.07 06:36:06 | 000,012,174 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\ssl-nss.dll
MOD - [2012.05.07 06:36:06 | 000,012,095 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\notify.dll
MOD - [2012.05.07 06:36:06 | 000,011,334 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libyahoo.dll
MOD - [2012.05.07 06:36:06 | 000,010,866 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\convcolors.dll
MOD - [2012.05.07 06:36:06 | 000,010,863 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libxmpp.dll
MOD - [2012.05.07 06:36:06 | 000,009,785 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\markerline.dll
MOD - [2012.05.07 06:36:06 | 000,009,432 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\history.dll
MOD - [2012.05.07 06:36:06 | 000,009,319 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libyahoojp.dll
MOD - [2012.05.07 06:36:06 | 000,008,987 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\autoaccept.dll
MOD - [2012.05.07 06:36:06 | 000,008,091 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libicq.dll
MOD - [2012.05.07 06:36:06 | 000,007,573 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\offlinemsg.dll
MOD - [2012.05.07 06:36:06 | 000,007,569 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\joinpart.dll
MOD - [2012.05.07 06:36:06 | 000,007,545 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\idle.dll
MOD - [2012.05.07 06:36:06 | 000,007,515 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\relnot.dll
MOD - [2012.05.07 06:36:06 | 000,007,276 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\extplacement.dll
MOD - [2012.05.07 06:36:06 | 000,007,131 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\sendbutton.dll
MOD - [2012.05.07 06:36:06 | 000,006,648 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\libaim.dll
MOD - [2012.05.07 06:36:06 | 000,006,528 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\statenotify.dll
MOD - [2012.05.07 06:36:06 | 000,006,442 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\psychic.dll
MOD - [2012.05.07 06:36:06 | 000,006,233 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\gtkbuddynote.dll
MOD - [2012.05.07 06:36:06 | 000,005,975 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\iconaway.dll
MOD - [2012.05.07 06:36:06 | 000,005,542 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\newline.dll
MOD - [2012.05.07 06:36:06 | 000,005,339 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\buddynote.dll
MOD - [2012.05.07 06:36:06 | 000,005,114 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\ssl.dll
MOD - [2012.05.07 06:36:04 | 000,267,776 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\exchndl.dll
MOD - [2012.05.07 06:36:04 | 000,153,532 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\spellcheck\libgtkspell-0.dll
MOD - [2012.05.07 06:35:14 | 000,229,597 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\sqlite3.dll
MOD - [2012.05.07 06:35:12 | 001,012,054 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libsilc-1-1-2.dll
MOD - [2012.05.07 06:35:12 | 000,406,898 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libsilcclient-1-1-2.dll
MOD - [2012.05.07 06:35:12 | 000,060,141 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libmeanwhile-1.dll
MOD - [2012.05.07 06:35:08 | 000,587,457 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\libxml2-2.dll
MOD - [2009.08.04 17:30:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Vetrak\a1ctl.exe
MOD - [2008.06.15 21:56:44 | 000,201,216 | ---- | M] () -- Q:\PidginPortable\App\Pidgin\plugins\pidgin-otr.dll
MOD - [2008.04.14 15:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.03.11 21:13:22 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2008.08.06 03:15:32 | 000,345,336 | ---- | M] (QUALCOMM, Inc.) [Disabled | Stopped] -- C:\QUALCOMM\QDLService\QDLService.exe -- (QDLService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\NSNDIS5.SYS -- (NSNDIS5)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012.08.21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.08.21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.08.21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.08.21 11:13:14 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012.08.21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012.08.21 11:13:13 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012.08.21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.03.11 21:13:48 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\inspect.sys -- (Inspect)
DRV - [2012.03.11 21:13:46 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012.03.11 21:13:46 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.09.05 14:02:36 | 001,630,056 | ---- | M] (TamoSoft) [CommView] Atheros AR5008 Wireless Network Adapter Service 7.7 [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ts_athw.sys -- (TS_AR5416)
DRV - [2011.07.01 04:46:40 | 000,026,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2011.06.15 10:23:56 | 000,060,156 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010.11.28 00:31:19 | 000,231,248 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2009.01.07 04:00:08 | 004,968,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008.10.31 06:14:20 | 000,117,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008.08.06 16:54:14 | 000,151,936 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\M3000KNT.sys -- (M3000Srv)
DRV - [2008.07.08 05:16:26 | 000,096,856 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\jmcr.sys -- (JMCR)
DRV - [2008.05.20 18:31:26 | 001,312,576 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2008.04.14 15:00:00 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2002.03.02 00:21:00 | 000,004,944 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Vetrak\winio.sys -- (WINIO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=i ... lz=1I7ACAW


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=i ... 1I7ACAW_cs
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: wrc@avast.com:7.0.1466
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..network.proxy.http: "142.150.238.12"
FF - prefs.js..network.proxy.type: 1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Tomas\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012.08.23 12:03:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.04 10:15:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.01 10:52:04 | 000,000,000 | ---D | M]

[2010.05.31 15:54:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Extensions
[2012.10.22 21:10:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions
[2010.05.31 16:00:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.10.22 21:09:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012.10.22 21:10:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions\staged-xpis
[2012.10.22 21:10:21 | 000,020,591 | ---- | M] () (No name found) -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\wp6s87w2.default\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b}\tmp.xpi
[2010.05.31 15:54:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\TOMAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\WP6S87W2.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}
[2012.08.23 12:03:36 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2009.11.04 01:07:05 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.05.12 18:51:16 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.05.12 18:51:16 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.05.12 18:51:16 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.05.12 18:51:16 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2012.07.31 15:43:32 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - Startup: C:\Documents and Settings\Tomas\Nabídka Start\Programy\Po spuštění\a1ctl.lnk = C:\Program Files\Vetrak\a1ctl.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 3736929687 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.200.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42DB0995-79F0-4379-8527-F36CAD3A7B3E}: DhcpNameServer = 192.168.200.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{570A04B3-381A-4138-824E-C18F858E809D}: NameServer = 94.142.233.120,94.142.233.140
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - Unable to read "AutoRun" value or value not present!
O32 - AutoRun File - [2009.01.22 09:15:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2012.10.25 09:39:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CrystalDiskInfo
[2012.10.25 09:39:51 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2012.10.25 09:36:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tomas\Plocha\OTL.exe
[2012.10.24 15:23:26 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Tomas\Recent
[2012.10.24 14:12:54 | 000,000,000 | ---D | C] -- C:\rsit
[2012.10.21 10:31:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomas\Plocha\Plany
[2012.10.12 20:37:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2012.09.25 15:09:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win
[2012.09.25 14:55:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CommView for WiFi
[2012.09.25 14:54:55 | 000,000,000 | ---D | C] -- C:\Program Files\CommViewWiFi
[2012.09.02 15:14:21 | 001,069,056 | ---- | C] (ToMMTi-Systems) -- C:\Program Files\dat3.000
[2012.09.02 15:14:21 | 000,765,952 | ---- | C] (ToMMTi-Systems) -- C:\Program Files\dat1.000
[2012.09.02 15:14:21 | 000,208,896 | ---- | C] (ToMMTi-Systems (http://www.tommti-systems.com)) -- C:\Program Files\3DAnalyze.exe
[2012.09.02 15:14:21 | 000,090,112 | ---- | C] (ToMMTi-Systems) -- C:\Program Files\hook_3DA.dll
[2012.09.02 15:14:21 | 000,052,736 | ---- | C] (ToMMTi-Systems) -- C:\Program Files\ForceDLL.dll

========== Files - Modified Within 30 Days ==========

[2012.10.25 09:42:39 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.10.25 09:36:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomas\Plocha\OTL.exe
[2012.10.25 09:22:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.10.25 09:22:25 | 000,270,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.10.25 09:22:24 | 1061,105,664 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.22 18:14:03 | 000,142,080 | ---- | M] () -- C:\Documents and Settings\Tomas\Plocha\bazen--hodiny-pro-verejnost-22.10.-28.10_1000x706.jpg
[2012.10.15 12:17:45 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.10.12 19:56:43 | 000,483,358 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.10.12 19:56:43 | 000,478,714 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.10.12 19:56:43 | 000,093,504 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.10.12 19:56:43 | 000,080,762 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.09.25 14:55:05 | 000,001,540 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CommView for WiFi.lnk

========== Files Created - No Company Name ==========

[2012.10.25 09:42:39 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.10.25 09:22:25 | 000,270,984 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.10.22 18:14:03 | 000,142,080 | ---- | C] () -- C:\Documents and Settings\Tomas\Plocha\bazen--hodiny-pro-verejnost-22.10.-28.10_1000x706.jpg
[2012.09.25 14:55:05 | 000,001,540 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CommView for WiFi.lnk
[2012.09.02 15:14:21 | 000,987,136 | ---- | C] () -- C:\Program Files\dat2.000
[2012.09.02 15:14:21 | 000,039,532 | ---- | C] () -- C:\Program Files\help.html
[2012.09.02 15:14:21 | 000,000,311 | ---- | C] () -- C:\Program Files\scroll.css
[2012.03.08 00:53:45 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Tomas\.recently-used.xbel
[2012.02.21 22:13:49 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.04.26 16:05:05 | 000,000,160 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2011.01.26 16:42:30 | 000,000,057 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010.12.07 23:30:50 | 000,000,053 | ---- | C] () -- C:\WINDOWS\Eraser.INI
[2009.12.26 22:47:07 | 000,152,576 | ---- | C] () -- C:\Documents and Settings\Tomas\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.15 10:49:33 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Tomas\Local Settings\Data aplikací\fusioncache.dat
[2008.04.29 00:30:20 | 000,022,371 | ---- | C] () -- C:\Documents and Settings\Tomas\welcome.htm
[2008.04.29 00:30:20 | 000,000,173 | -H-- | C] () -- C:\Documents and Settings\Tomas\operator.ini

========== ZeroAccess Check ==========

[2009.01.22 09:19:04 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 15:00:00 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:56:05 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 15:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010.09.17 20:25:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2009.07.15 18:12:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\eSobi
[2011.01.24 16:01:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\QUALCOMM
[2009.07.15 13:48:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\SACore
[2012.05.09 21:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\.purple
[2010.12.01 22:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer
[2009.07.15 17:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer Pro
[2012.01.14 16:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Empire XP
[2009.07.23 16:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\eSobi
[2010.12.07 22:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\gnupg
[2012.09.23 11:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\gtk-2.0
[2009.08.03 11:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\InterVideo
[2009.11.22 17:31:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\OpenOffice.org
[2009.07.15 13:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Opera
[2010.02.15 17:30:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Soldat
[2010.12.01 18:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\TrueCrypt
[2010.12.28 18:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Uniblue
[2012.06.08 20:54:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Unity
[2012.10.24 23:13:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\uTorrent
[2009.11.12 16:46:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\vghd
[2012.02.11 00:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\X-Chat 2

========== Purity Check ==========



========== Custom Scans ==========

< >
[2008.04.14 15:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2009.01.22 11:21:14 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.08.23 12:03:48 | 000,000,318 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job

< >

< MD5 for: AGP440.SYS >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:AGP440.sys
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:atapi.sys
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 15:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 15:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\I386\AUTOCHK.EXE
[2008.04.14 15:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 15:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:cdrom.sys
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 15:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2008.04.14 15:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 15:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 15:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 15:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 15:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 15:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:hal.dll
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 15:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:Changer.sys
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:isapnp.sys
[2008.04.14 15:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 08:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 08:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 15:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\isapnp.sys

< MD5 for: LSASS.EXE >
[2008.04.14 15:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 15:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 15:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 15:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2008.04.14 15:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 15:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 15:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 15:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2008.04.14 15:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 15:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 15:00:00 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=F209B5C79A87A9521DC0BD88B039EEE3 -- C:\I386\SYSTEM32\SMSS.EXE

< MD5 for: SVCHOST.EXE >
[2008.04.14 15:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 15:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 15:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 15:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 15:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 15:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2008.04.14 15:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 15:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< >

< %systemroot%*.* /U /s >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.05.09 21:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\.purple
[2012.07.09 23:42:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Adobe
[2010.12.01 22:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer
[2009.07.15 17:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer Pro
[2011.10.31 22:57:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\dvdcss
[2012.01.14 16:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Empire XP
[2009.07.23 16:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\eSobi
[2010.12.07 22:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\gnupg
[2012.09.23 11:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\gtk-2.0
[2009.07.15 18:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Identities
[2009.07.15 18:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\InstallShield
[2009.08.03 11:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\InterVideo
[2010.09.17 20:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Macromedia
[2010.09.17 21:40:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Media Player Classic
[2012.07.09 23:42:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Tomas\Data aplikací\Microsoft
[2011.04.30 16:48:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Mozilla
[2009.11.22 17:31:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\OpenOffice.org
[2009.07.15 13:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Opera
[2010.02.14 20:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Real
[2010.12.23 03:15:55 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Tomas\Data aplikací\SecuROM
[2010.02.15 17:30:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Soldat
[2009.11.04 00:58:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Sun
[2012.05.13 14:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\tor
[2010.12.01 18:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\TrueCrypt
[2010.12.28 18:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Uniblue
[2012.06.08 20:54:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Unity
[2012.10.24 23:13:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\uTorrent
[2009.11.12 16:46:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\vghd
[2011.09.14 16:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\Vidalia
[2011.05.10 14:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\vlc
[2012.02.11 00:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomas\Data aplikací\X-Chat 2

< %APPDATA%\*.exe /s >
[2009.08.11 21:21:26 | 000,087,552 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 21:21:30 | 000,090,112 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 14:52:04 | 000,697,690 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\AC3 Filter\unins000.exe
[2010.02.23 17:01:52 | 001,185,871 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\FFDShow\unins000.exe
[2010.08.14 10:42:54 | 000,113,152 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 10:45:10 | 000,358,400 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 10:42:06 | 000,137,728 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 15:30:22 | 000,042,305 | ---- | M] () -- C:\Documents and Settings\Tomas\Data aplikací\BSplayer\Haali media splitter\uninstall.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009.01.22 10:06:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2009.01.22 10:06:30 | 001,069,056 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2009.01.22 10:06:30 | 000,471,040 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.10.25 09:22:25 | 000,270,984 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 15:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.10.25 09:42:39 | 000,000,512 | ---- | M] () MD5=4A4104B2020B540EB89F0F46AEF6391D -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2009.09.06 18:38:10 | 000,045,056 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\Aircrack-ng GUI.exe
[2010.04.25 01:26:38 | 001,758,258 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\aircrack-ng.exe
[2010.04.24 21:06:16 | 000,004,934 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\manpages\aircrack-ng.1
[2010.04.09 15:50:14 | 000,123,048 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\aircrack-ng.c
[2009.06.13 23:49:08 | 000,007,537 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\aircrack-ng.h
[2009.05.03 00:43:50 | 000,017,975 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\aircrack-ptw-lib.c
[2009.01.22 23:18:02 | 000,002,219 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\aircrack-ptw-lib.h
[2008.12.06 19:53:26 | 000,000,922 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\GUI\Aircrack-ng.sln
[2008.12.06 19:53:26 | 000,003,341 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\GUI\Aircrack-ng\Aircrack-ng.csproj
[2008.12.06 19:53:26 | 000,000,538 | ---- | M] () -- \Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\src\GUI\Aircrack-ng\Aircrack-ng.csproj.user
[2012.09.02 13:10:27 | 489,029,632 | ---- | M] () -- \Hry\lego star wars\Lego Starwars Pc Game Crack.iso
[2009.02.11 22:33:38 | 000,072,262 | ---- | M] () -- \Hry\Soldat\Maps\CrackedBoot.PMS
[2005.11.26 19:31:50 | 000,000,423 | ---- | M] () -- \Hry\Soldat\Scenery-gfx\m_crack2-sk.png
[2006.07.23 00:06:56 | 000,000,670 | ---- | M] () -- \Hry\Soldat\Scenery-gfx\m_crack3-sk.png
[2007.05.08 13:03:22 | 000,000,853 | ---- | M] () -- \Hry\Soldat\Scenery-gfx\m_crack5-sk.png
[2002.11.02 18:23:36 | 000,017,264 | ---- | M] () -- \Hry\Soldat\Sfx\bonecrack.wav
[2002.09.28 20:58:58 | 000,021,094 | ---- | M] () -- \Hry\Soldat\Sfx\firecrack.wav

< *keygen* /s >

< *loader* /s >
[2012.08.31 00:12:25 | 000,040,660 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Data aplikací\Opera\Opera\widgets\fastesttube-youtube-video-downloader-1.5.4-1.oex
[2008.04.14 15:00:00 | 000,017,421 | ---- | M] () -- \I386\DMLOADER.DL_
[2008.04.14 15:00:00 | 000,115,367 | ---- | M] () -- \I386\OSLOADER.EX_
[2008.04.14 15:00:00 | 000,133,029 | ---- | M] () -- \I386\OSLOADER.NT_
[2002.09.25 22:05:38 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2009.03.02 15:57:58 | 000,023,757 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\bin\gdk-pixbuf-query-loaders.exe
[2009.03.02 15:57:58 | 000,003,657 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\etc\gtk-2.0\gdk-pixbuf.loaders
[2009.03.02 15:56:44 | 000,028,560 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ani.dll
[2009.03.02 15:56:42 | 000,027,492 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-bmp.dll
[2009.03.02 15:56:42 | 000,041,827 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-gif.dll
[2009.03.02 15:56:40 | 000,020,750 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-icns.dll
[2009.03.02 15:56:44 | 000,027,004 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ico.dll
[2009.03.02 15:56:42 | 000,033,364 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-jpeg.dll
[2009.03.02 15:56:44 | 000,021,329 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-pcx.dll
[2009.03.02 15:56:42 | 000,035,326 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-png.dll
[2009.03.02 15:56:44 | 000,023,528 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-pnm.dll
[2009.03.02 15:56:42 | 000,018,354 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ras.dll
[2009.03.02 15:56:44 | 000,023,858 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-tga.dll
[2009.03.02 15:56:44 | 000,028,334 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-tiff.dll
[2009.03.02 15:56:42 | 000,017,895 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-wbmp.dll
[2009.03.02 15:56:42 | 000,023,851 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-xbm.dll
[2009.03.02 15:56:42 | 000,041,060 | ---- | M] () -- \Program Files\Common Files\GTK\2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-xpm.dll
[2008.10.05 15:17:34 | 000,006,308 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2008.10.05 00:00:58 | 000,015,872 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2008.10.05 16:02:04 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2008.10.04 17:50:10 | 000,021,504 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2008.10.04 23:22:34 | 000,003,871 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2010.12.23 03:03:50 | 000,000,990 | ---- | M] () -- \WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[2008.04.14 15:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2008.04.14 15:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll
[2011.02.02 15:35:38 | 000,009,622 | ---- | M] () -- \WINDOWS\system32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >

< *activator* /s >

< *serial* /s >
[2008.04.14 15:00:00 | 000,024,957 | ---- | M] () -- \I386\DPSERIAL.DL_
[2008.04.14 15:00:00 | 000,030,259 | ---- | M] () -- \I386\SERIAL.SY_
[2008.04.14 15:00:00 | 000,006,549 | ---- | M] () -- \I386\SERIALUI.DL_
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2009.01.22 09:20:08 | 000,011,776 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap.resources\1.0.5000.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.01.22 09:21:02 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.01.24 15:23:22 | 000,011,776 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2012.06.14 15:30:37 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.01.24 15:23:44 | 000,090,112 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2010.06.08 23:05:27 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2012.05.11 22:39:54 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll
[2012.05.11 23:47:29 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a644ec04e18202b60f9d828bc207972b\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.05.11 23:51:08 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\6a37764b2df9b3f9c7775701027ef779\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.05.11 23:50:51 | 002,637,312 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\9bfda0add366eea12ea0402e60d01e84\System.Runtime.Serialization.ni.dll
[2011.07.30 12:54:27 | 000,017,840 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2012.06.14 15:22:58 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.07.30 12:54:24 | 000,099,208 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2012.06.14 15:22:50 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2004.07.15 15:31:54 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
[2003.04.07 20:24:52 | 000,011,776 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2008.09.10 18:46:28 | 000,011,776 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2010.06.15 02:33:16 | 000,017,840 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.06.15 02:33:16 | 000,099,208 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2008.04.14 15:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2008.04.14 15:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2008.04.14 15:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2008.04.14 15:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 15:00:00 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys

< *w7lxe* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}

< End of report >

heges
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 12 črc 2010 12:27

Re: o preventivku prosim

#6 Příspěvek od heges »

OTL Extras logfile created on: 25.10.2012 9:38:35 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Tomas\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1011,88 Mb Total Physical Memory | 526,05 Mb Available Physical Memory | 51,99% Memory free
2,37 Gb Paging File | 1,89 Gb Available in Paging File | 79,75% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53,63 Gb Total Space | 13,33 Gb Free Space | 24,86% Space Free | Partition Type: NTFS
Drive Q: | 9,99 Gb Total Space | 7,19 Gb Free Space | 72,00% Space Free | Partition Type: FAT32

Computer Name: PRCEK | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"C:\Program Files\Pidgin\pidgin.exe" = C:\Program Files\Pidgin\pidgin.exe:*:Disabled:Pidgin
"C:\Program Files\OperaTor\Opera\opera.exe" = C:\Program Files\OperaTor\Opera\opera.exe:*:Enabled:Opera Internet Browser
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\WinPcap\rpcapd.exe" = C:\Program Files\WinPcap\rpcapd.exe:*:Enabled:Remote Packet Capture Daemon
"E:\Tor Browser\Start Tor Browser.exe" = E:\Tor Browser\Start Tor Browser.exe:*:Enabled:Start Tor Browser
"E:\Tor Browser\App\TOR.EXE" = E:\Tor Browser\App\TOR.EXE:*:Enabled:tor
"C:\Documents and Settings\Tomas\Plocha\Tor Browser\App\tor.exe" = C:\Documents and Settings\Tomas\Plocha\Tor Browser\App\tor.exe:*:Enabled:tor
"D:\Tor Browser\App\tor.exe" = D:\Tor Browser\App\tor.exe:*:Enabled:tor
"C:\Program Files\Vidalia Bundle\Tor\tor.exe" = C:\Program Files\Vidalia Bundle\Tor\tor.exe:*:Enabled:tor
"C:\Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\buddy-ng.exe" = C:\Documents and Settings\Tomas\Plocha\aircrack-ng-1.1-win\bin\buddy-ng.exe:*:Enabled:buddy-ng -- ()
"C:\WINDOWS\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"W:\xChat\xchat.exe" = W:\xChat\xchat.exe:*:Disabled:XChat IRC Client
"Q:\Tor Browser\App\tor.exe" = Q:\Tor Browser\App\tor.exe:*:Enabled:tor -- ()
"C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe" = C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{18026153-83A4-40E0-96B6-41E441607518}" = Eraser 6.0.9.2343
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.224_Foxconn Installation Program
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{56A648C2-D185-46A9-BBFF-78AE7A503000}" = Acer Crystal Eye webcam
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Czech
"{BE8BE32F-F595-4693-9F82-1E0A5A047BB6}" = OpenOffice.org 3.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C73B5B3B-F974-48CA-8B91-3E8A432AEA5B}" = Microsoft Works
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDED9EF0-D072-11DF-2EA6-0104A00B0BB3}" = CommView for WiFi
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}" = COMODO Internet Security
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DE17C30D-F339-4EEC-8893-F3BD78027EFD}" = Qualcomm Gobi Driver Package for Acer
"{E914A24F-2412-4374-B420-86D21D6D444A}" = LEGO Star Wars
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7952CA2-A925-4CA1-A934-A46E8EC9CA18}" = Acer Crystal Eye Webcam
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Aspell Czech Dictionary_is1" = Aspell Czech Dictionary-0.50-2
"avast" = avast! Free Antivirus
"BSPlayerf" = BS.Player FREE
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CrystalDiskInfo_is1" = CrystalDiskInfo 5.0.5
"Fallout" = Fallout
"GNU Aspell_is1" = GNU Aspell 0.50-3
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (odstranit)
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{E914A24F-2412-4374-B420-86D21D6D444A}" = LEGO Star Wars
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.5.1 (Standard)
"LManager" = Launch Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Opera 12.02.1578" = Opera 12.02
"pidgin-otr" = pidgin-otr 3.2.0-1
"PowerISO" = PowerISO
"Speccy" = Speccy
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TrueCrypt" = TrueCrypt
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.9
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"xchat" = XChat 2 (remove only)
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2.5.2011 18:49:47 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace Speccy.exe, verze 1.7.0.205, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 6.5.2011 17:10:51 | Computer Name = PRCEK | Source = Application Error | ID = 1000
Description = Chybující aplikace pidgin.exe, verze 2.7.11.0, chybující modul libglib-2.0-0.dll,
verze 2.20.5.0, adresa chyby 0x0001c68a.

Error - 7.5.2011 17:26:49 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace soffice.bin, verze 3.0.9358.500, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 7.5.2011 17:26:50 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace soffice.bin, verze 3.0.9358.500, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 9.5.2011 15:05:50 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace soffice.bin, verze 3.0.9358.500, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 11.5.2011 10:25:23 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace vlc.exe, verze 1.1.9.0, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

Error - 11.5.2011 10:25:24 | Computer Name = PRCEK | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace vlc.exe, verze 1.1.9.0, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

Error - 16.5.2011 12:03:00 | Computer Name = PRCEK | Source = Application Error | ID = 1000
Description = Chybující aplikace vidalia.exe, verze 0.2.12.0, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x00000000.

Error - 19.5.2011 17:23:35 | Computer Name = PRCEK | Source = Application Error | ID = 1000
Description = Chybující aplikace pidgin.exe, verze 2.7.11.0, chybující modul libglib-2.0-0.dll,
verze 2.20.5.0, adresa chyby 0x00048640.

Error - 21.5.2011 11:49:41 | Computer Name = PRCEK | Source = Application Error | ID = 1000
Description = Chybující aplikace speccy.exe, verze 1.7.0.205, chybující modul speccy.exe,
verze 1.7.0.205, adresa chyby 0x00005b74.


< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: o preventivku prosim

#7 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:otl
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.




:arrow: Stahnete TFC http://oldtimer.geekstogo.com/TFC.exe , ulozte a spustte
Kliknete na START a pote OK - Po uklidu dojde k restartu pc.
Po pouziti muzete programek smazat



:arrow: Defragmentujte disk(y)
Stahnete napriklad program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci pozor na toolbar. Pokud vam ho nabidne, zruste zatrzitko.
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

heges
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 12 črc 2010 12:27

Re: o preventivku prosim

#8 Příspěvek od heges »

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Tomas
->Temp folder emptied: 326904 bytes
->Temporary Internet Files folder emptied: 33129 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 23124994 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 456 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 23,00 mb


[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: Tomas
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-1666224640-2261209305-3600520123-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1666224640-2261209305-3600520123-1006\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
ADS C:\WINDOWS\system32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57} deleted successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 10262012_163136

Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: o preventivku prosim

#9 Příspěvek od Márty84 »

Nastala nejaka zmena?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Odpovědět