Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, děkuju moc!

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Prosím o kontrolu, děkuju moc!

#1 Příspěvek od visis »

Dobrý den, mám následující problém.
Často (téměř vždy) se stává, že po zasunutí flešky mi kaspersky hlásí že na flešce jsou trojani v souborech autorun a nějakých dalších souborech .exe, které se vždy jmenujou jinak a jsou v kořenovém adresáři na flešce. Ty soubory se tam podle mě tvoří nějak náhodně.
Nevím jestli v mém počítači nemám nějakou havěť a ta mi infikuje flešky, protože je to pořád dokola a nemůžu se toho zbavit.
Proto zde vkládám svůj log a prosím o kontrolu.
Díky :-)

Logfile of random's system information tool 1.06 (written by random/random)
Run by Honza at 2010-03-09 15:08:15
Microsoft« Windows VistaÖ Ultimate Service Pack 1
System drive C: has 9 GB (6%) free of 150 GB
Total RAM: 2559 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:08:22, on 9.3.2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\totalcmd\TOTALCMD.EXE
D:\RSIT.exe
C:\Program Files (x86)\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Pomocnß slu×ba pro p°ihlßÜenÝ ke slu×bý Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATKMEDIA] "C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: CCC.lnk = ?
O4 - Startup: Lingea Update Center.lnk = C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Network Server.lnk = C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: P°evÚst cÝl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: P°evÚst do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: P°idat do Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: P°ipojit cÝl vazby k existujÝcÝmu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: P°ipojit k existujÝcÝmu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: &VirtußlnÝ klßvesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files (x86)\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Unknown owner - C:\Windows\System32\StkCSrv.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - Unknown owner - C:\Windows\System32\TuneUpDefragService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - Unknown owner - C:\Windows\System32\TUProgSt.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Slu×ba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12906 bytes

======Scheduled tasks folder======

C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\Ad-Aware Update (Daily 1).job
C:\Windows\tasks\Ad-Aware Update (Daily 2).job
C:\Windows\tasks\Ad-Aware Update (Daily 3).job
C:\Windows\tasks\Ad-Aware Update (Daily 4).job
C:\Windows\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnß slu×ba pro p°ihlßÜenÝ ke slu×bý Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-08-27 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21 349640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440]
"RemoteControl8"=C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240]
"PDVD8LanguageShortcut"=C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [2008-10-27 91432]
"AdobeCS4ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2009-03-11 611712]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-12-21 640440]
"Adobe_ID0ENQBO"=C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE [2008-08-15 378224]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"AVP"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2007-10-19 286720]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-18 1555968]
""= []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"AlcoholAutomount"=C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe [2007-08-01 222592]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-18 138240]
"AnyDVD"=C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [2009-03-19 2300864]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
Lingea Update Center.lnk - C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"ForceActiveDesktopOn"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{21f4a992-bd52-11de-ad7c-0018f32faa1c}]
shell\AutoRun\command - G:\ej10fkdo.bat
shell\open\command - G:\ej10fkdo.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{384f5868-d058-11dd-a7d3-0018f32faa1c}]
shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e393fbc3-2c2e-11de-8c47-0018f32faa1c}]
shell\AutoRun\command - G:\WDSetup.exe


======File associations======

.js - edit - C:\Windows\SysWOW64\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS4\Dreamweaver.exe","%1"
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-03-09 15:08:15 ----D---- C:\rsit
2010-03-02 14:42:22 ----A---- C:\Windows\system32\jscript.dll
2010-03-02 14:41:44 ----A---- C:\Windows\system32\tzres.dll
2010-03-02 14:40:49 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-03-02 14:40:49 ----A---- C:\Windows\system32\RMActivate.exe
2010-03-02 14:40:47 ----A---- C:\Windows\system32\secproc.dll
2010-03-02 14:40:47 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-03-02 14:40:47 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-03-02 14:40:46 ----A---- C:\Windows\system32\secproc_isv.dll
2010-03-02 14:40:43 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-03-02 14:40:43 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-03-02 14:40:43 ----A---- C:\Windows\system32\msdrm.dll
2010-02-14 11:13:12 ----D---- C:\ProgramData\ACD Systems
2010-02-10 14:15:39 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 14:15:35 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 14:15:34 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 14:15:34 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 14:15:33 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 14:15:33 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 14:15:32 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 14:15:32 ----A---- C:\Windows\system32\avicap32.dll
2010-02-10 14:15:31 ----A---- C:\Windows\system32\msvfw32.dll
2010-02-10 14:15:31 ----A---- C:\Windows\system32\avifil32.dll

======List of files/folders modified in the last 1 months======

2010-03-09 15:08:22 ----D---- C:\Windows\Temp
2010-03-09 15:08:22 ----D---- C:\Windows\Prefetch
2010-03-09 15:08:18 ----D---- C:\Program Files (x86)\trend micro
2010-03-09 15:07:32 ----D---- C:\Windows\Tasks
2010-03-09 15:04:50 ----D---- C:\ProgramData\Kaspersky Lab
2010-03-09 15:03:59 ----AD---- C:\Windows
2010-03-09 14:56:18 ----D---- C:\Windows\System32
2010-03-09 14:56:18 ----D---- C:\Windows\inf
2010-03-09 14:37:46 ----D---- C:\Rapidshare
2010-03-09 14:17:16 ----SHD---- C:\System Volume Information
2010-03-09 14:01:20 ----A---- C:\Windows\NeroDigital.ini
2010-03-03 22:53:03 ----D---- C:\Users\Honza\AppData\Roaming\Skype
2010-03-03 21:55:53 ----D---- C:\Users\Honza\AppData\Roaming\skypePM
2010-03-02 19:31:37 ----D---- C:\Windows\rescache
2010-03-02 18:08:18 ----D---- C:\Windows\SysWOW64
2010-03-02 18:08:18 ----D---- C:\Windows\system32\cs-CZ
2010-03-02 18:08:08 ----RSD---- C:\Windows\Fonts
2010-03-02 14:49:32 ----D---- C:\Windows\winsxs
2010-02-14 11:15:07 ----SHD---- C:\Windows\Installer
2010-02-14 11:13:24 ----D---- C:\Program Files (x86)\Common Files\ACD Systems
2010-02-14 11:13:12 ----HD---- C:\ProgramData
2010-02-10 17:21:34 ----D---- C:\Program Files (x86)\Windows Mail
2010-02-10 14:21:40 ----D---- C:\Windows\Debug
2010-02-10 14:20:45 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys []
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys []
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys []
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys []
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys []
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl [2008-02-01 32240]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2009-06-04 86584]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\Windows\SYSTEM32\DRIVERS\WibuKey64.sys []
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2008-12-02 119744]
R3 CmBatt;OvladaŔ baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys []
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys []
R3 NETw3v64;OvladaŔ adaptÚru Intel(R) PRO/Wireless 3945ABG pro Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\NETw3v64.sys []
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys []
R3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys []
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys []
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys []
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam; C:\Windows\System32\Drivers\StkCMini.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
R3 toshidpt;Bluetooth HID Port; C:\Windows\system32\drivers\Toshidpt.sys []
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys []
R3 Tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys []
R3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys []
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys []
R3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys []
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys []
R3 WCPU;WCPU; \??\C:\Program Files\P4G\WCPU.sys [2006-12-21 12656]
S1 eusk2par;EUTRON SmartKey Parallel Driver; \??\C:\Windows\system32\Drivers\eusk2par.sys [2004-11-18 24786]
S2 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\Honza\AppData\Local\Temp\HWInfo\HWiNFO64A.SYS []
S3 agvbyyh3;agvbyyh3; C:\Windows\system32\drivers\agvbyyh3.sys []
S3 BthEnum;OvladaŔ pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys []
S3 BthPan;Za°ÝzenÝ Bluetooth (sÝŁ PAN); C:\Windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;OvladaŔ portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;OvladaŔ rozhranÝ USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys []
S3 drmkaud;DekodÚr zvuk¨ DRM jßdra spoleŔnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys []
S3 HdAudAddService;OvladaŔ funkce Microsoft 1.1 UAA pro slu×bu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys []
S3 MMIOPORT;MMIOPORT; \??\C:\Windows\system32\drivers\MMIOPORT.sys [2000-03-03 7424]
S3 MSKSSRV;Server proxy slu×by datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Server proxy hodin datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Server proxy sprßvce kvality datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Konvertor jÝmka-jÝmka typu T datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSTEE.sys []
S3 NETw4v64;OvladaŔ adaptÚru Intel(R) Wireless WiFi Link pro systÚm Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\NETw4v64.sys []
S3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\NETw5v64.sys []
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys []
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys []
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RFCOMM;Za°ÝzenÝ Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\WNt500x64\Sandra.sys [2008-07-29 22432]
S3 SIVDRIVER;SIV Kernel Driver; \??\C:\Windows\system32\Drivers\SIVX64.sys []
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys []
S3 usb_rndisx;AdaptÚr USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys []
S3 usbscan;OvladaŔ skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys []
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\system32\DRIVERS\wceusbsh.sys []
S3 WINUSB;OvladaŔ WinUsb; C:\Windows\system32\DRIVERS\WinUSB.SYS []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe [2007-02-05 94208]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
R2 AVP;Kaspersky Internet Security; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
R2 BBDemon;Backbone Service; C:\Program Files (x86)\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe [2007-07-03 36864]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 97432]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-02-05 1181328]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service; C:\Windows\System32\StkCSrv.exe []
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 153088]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe []
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 2297216]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2009-03-12 288112]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-10-26 85096]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-07-27 93184]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe []
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-06-04 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-06-04 655624]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-18 19968]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe [2008-09-01 98488]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe []

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu, děkuju moc!

#2 Příspěvek od motji »

Dobrý večer :)
Máte na jednotce G infekci. Zkusíme jeden prográmek, jestli funguje na 64 b vistách, pokud ne, popereme se s tím ručně :)

:arrow: Zapojte do pc všechny usb klíče, flashky...co používáte

:arrow: Stáhněte na plochu UsbFix
-spusťte, zvolte jazyk E - potvrdťe enter
-klikněte na volbu 2 - enter
- po skenu sem vložte log , pokud na Vás nevyskočí, najdete ho C:\UsbFix.txt
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#3 Příspěvek od visis »

No, ten prográmek dělal spoustu věcí, restartoval počítač, potom hodně pracoval a ve výsledku naběhly windowsy a neustále se objevuje hláška "Průzkumník windows přestal pracovat" a chce to restartovat program. To je ale do nekonečna a bez výsledku se objevuje pořád ta samá hláška.
Nevíte co s tím ????? HELP :cry:

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#4 Příspěvek od visis »

Log u usb fixu je zde:
visty ale defacto nepracují :(


############################## | UsbFix V6.099 |

User : Honza (Administrators) # HONZA-PC
Update on 09/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 22:58:31 | 9.3.2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz
Microsoft« Windows VistaÖ Ultimate (6.0.6001 64-bit) # Service Pack 1
Internet Explorer 8.0.6001.18882
Windows Firewall Status : Disabled

C:\ -> Local Fixed Disk # 146,48 Go (16,95 Go free) # NTFS
D:\ -> Local Fixed Disk # 86,4 Go (208,84 Mo free) # NTFS
E:\ -> CD-ROM Disc
F:\ -> CD-ROM Disc

################## | Files # Infected Folders |

Deleted ! C:\$Recycle.Bin\S-1-5-21-3950918805-3815427779-4285382183-1000
Deleted ! C:\$Recycle.Bin\S-1-5-21-3991871189-2232181320-2112149827-500
Deleted ! D:\$Recycle.Bin\S-1-5-21-3950918805-3815427779-4285382183-1000

################## | Registry |

Deleted ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]

################## | Mountpoints2 |

Deleted ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{21f4a992-bd52-11de-ad7c-0018f32faa1c}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{384f5868-d058-11dd-a7d3-0018f32faa1c}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{e393fbc3-2c2e-11de-8c47-0018f32faa1c}\Shell\AutoRun\Command

################## | Listing of the present files |

[09.03.2010 22:57|--a------|7388] C:\aaw7boot.log
[18.01.2008 22:45|-rahs----|333203] C:\bootmgr
[17.10.2008 20:22|-ra-s----|8192] C:\BOOTSECT.BAK
[17.10.2008 19:40|-rahs----|171136] C:\grldr
[?|?|?] C:\hiberfil.sys
[02.12.2006 04:37|--a------|904704] C:\msdia80.dll
[?|?|?] C:\pagefile.sys
[03.03.2010 21:50|---h-----|83791] C:\treeinfo.wc
[09.03.2010 23:05|--a------|1889] C:\UsbFix.txt
[05.05.2009 18:23|--a------|1098] C:\WirelessDiagLog.csv
[17.12.2007 19:44|--a------|496953] D:\cacheprinter.jar
[17.01.2010 10:41|--a------|42634] D:\cc_20100117_104025.reg
[20.07.2008 21:51|--a------|408064] D:\diplomka.doc
[27.08.2009 09:28|--a------|30090228] D:\GEOGRAFIA_pre_2.rocnik_Gymnazii.pdf
[20.04.2008 12:48|--a------|57998] D:\kontakty 2008.spd
[20.04.2008 12:48|--a------|7571] D:\kontakty 2008.txt
[27.05.2009 18:42|--a------|3326976] D:\Kralovehradeckykraj.pps
[21.01.2010 18:20|--a------|5115824] D:\mbam-setup.exe
[09.12.2009 23:24|--a------|10170341] D:\Mozigo.12.2.22.exe
[17.11.2008 23:25|--a------|830255] D:\měření teplot.pptx
[27.05.2009 18:43|--a------|15350784] D:\Pardubickykraj.pps
[21.01.2010 09:47|--a------|781909] D:\RSIT.exe
[01.01.2009 19:39|--a------|86016] D:\s.xls
[22.01.2010 10:44|--a------|1245341] D:\saa.exe
[20.04.2008 13:38|--a------|719174] D:\sms 2005-2008.spd

################## | Vaccination |

# C:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
# D:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).

################## | Upload |

Please send the file : C:\UsbFix_Upload_Me_Honza-PC.zip : http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution .

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#5 Příspěvek od visis »

Vůbec mi při startu windows nenaběhne kaspersky, ani se nespustí postaní panel vist...
Co se stalo ???

EDIT:
Už mi windowsy naběhly. Asi planý poplach, natvrdo jsem to restartoval a pomohlo to. Uff, ale fakt jsem se leknul :all_coholic:

Můžete se prosím podívat na ten log z usbfixu?
Děkuju moc :-)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu, děkuju moc!

#6 Příspěvek od motji »

Nemyslím si, že by za to mohl zrovna tento program :o Nebo si myslíte, že se to zhoršilo právě po jeho použití? :o
Můžete ještě zkusit obnovu systému k datu, kdy tyto problémy nebyly.


:arrow: Tyto soubory znáte?
D:\s.xls
D:\saa.exe
D:\sms 2005-2008.spd

:arrow: Běžte do nouzového režimu (po restartu mačkejte F8 - nouzový režim s prací v síti).


:arrow: Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
- otevře se okno, v něm zaškrtněte Scan All Users , ,
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\viamraid.sys /s /md5
%SYSTEMDRIVE%\nvata.sys /s /md5
CREATERESTOREPOINT
-klikněte na tlačítko Run scan.
-proběhne sken a objeví se dva logy, obsah obou vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#7 Příspěvek od visis »

Asi stačil ten tvrdý restart, takže počítač už běží jak má. Spadl mi kámen ze srdce :-)
Ještě než začnu další procedury, chci se zeptat na jednu věc. Když běžel ten usbfix, tak jsem měl flešku v počítači. potom se restartoval a já jí vytáhnul. Udělal jsem to správně, nebo jsem jí tam měl nechat zasunutou? Protože po restartu se usbfix spustil automaticky a dál proskenovával pc.
Díky :-)

D:\s.xls - to je OK
D:\saa.exe - nevím, raději jsem to smazal (ale možná to k něčemu bylo)
D:\sms 2005-2008.spd - to je taky OK

Jestli jsem to dobře pochopil, tak ten OTL mám spustit v nouzovém režimu???

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu, děkuju moc!

#8 Příspěvek od motji »

Mě taky spadl kámen ze srdce :D .

Jestli je fleška jednotka G, tak na ní máte mršku a bohužel tam stále je, tím že jste flešku vytáhl, tak se opravdu nesmazala.
Nechte ji zasunutou v pc ted, když budeme dělat skeny a mazat. Mám pocit, že Usbfix na 64b systému nefunguje korektně, aspon podle toho, co jste psal, takže ho už raději používat nebudeme.

Ne, do nouzového režimu nemusíte, pokud počítač už pracuje normálně. To mělo být kvůli tomu, že se v normálním režimu nedalo pracovat :)

K tomu souboru Saa.exe - nemáte program Satellite Antenna Alignment? A nemusíte všechno co neznáme hned mazat, soubory můžeme otestovat na virustotalu. :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#9 Příspěvek od visis »

Máte pravdu :) saa = Satellite Antena....
Ale už je smazanej :)

Takže zasouvam flešku (G: je opravdu fleška) a spouštim OTL...

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#10 Příspěvek od visis »

1. část logu z OTL.txt (musel jsem to dát do dvou příspěvků, mělo to moc znaků)


OTL logfile created on: 10.3.2010 10:03:32 - Run 1
OTL by OldTimer - Version 3.1.36.0 Folder = C:\Users\Honza\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 41,00% Memory free
5,00 Gb Paging File | 3,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,48 Gb Total Space | 16,95 Gb Free Space | 11,57% Space Free | Partition Type: NTFS
Drive D: | 86,40 Gb Total Space | 0,05 Gb Free Space | 0,05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 991,22 Mb Total Space | 48,20 Mb Free Space | 4,86% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HONZA-PC
Current User Name: Honza
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - File not found -- C:\Windows\SysWow64\StkCSrv.exe
PRC - [2010.03.10 10:02:36 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Honza\Desktop\OTL.exe
PRC - [2010.02.05 21:21:49 | 001,181,328 | ---- | M] (Lavasoft) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.01.27 15:21:29 | 000,788,880 | ---- | M] (Lavasoft) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.01.22 14:11:28 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009.12.21 18:35:18 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2009.10.20 19:39:28 | 000,340,456 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
PRC - [2009.09.24 07:50:10 | 003,520,256 | ---- | M] (Ghisler Software GmbH) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2009.05.19 11:41:56 | 000,275,736 | ---- | M] (Lingea) -- C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
PRC - [2009.03.19 10:55:29 | 002,300,864 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
PRC - [2008.10.27 18:14:51 | 000,091,432 | ---- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
PRC - [2008.03.20 20:23:22 | 000,083,240 | ---- | M] (Cyberlink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2007.07.03 06:21:12 | 000,036,864 | ---- | M] (Dassault Systemes) -- C:\Program Files (x86)\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe
PRC - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007.05.22 15:57:26 | 002,756,608 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2007.04.26 13:53:38 | 000,274,432 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2007.04.13 08:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
PRC - [2007.02.27 19:21:10 | 000,278,528 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2007.02.27 18:57:56 | 000,278,528 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
PRC - [2007.02.09 15:40:34 | 000,225,280 | ---- | M] (ATK0100) -- C:\Program Files (x86)\ATK Hotkey\HControl.exe
PRC - [2007.02.05 17:13:14 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe
PRC - [2007.01.17 18:26:36 | 007,708,672 | ---- | M] () -- C:\Program Files\ATKOSD2\ATKOSD2.exe
PRC - [2006.12.18 16:26:26 | 002,420,736 | ---- | M] () -- C:\Program Files (x86)\ATK Hotkey\ATKOSD.exe
PRC - [2006.12.04 15:00:10 | 000,069,632 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
PRC - [2006.11.22 06:20:00 | 003,768,320 | ---- | M] (WIBU-SYSTEMS AG) -- C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
PRC - [2006.11.02 07:27:32 | 000,061,440 | ---- | M] (ASUSTeK Computer INC.) -- C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
PRC - [2006.10.26 12:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
PRC - [2006.01.23 22:14:10 | 000,069,632 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe


========== Modules (SafeList) ==========

MOD - [2010.03.10 10:02:36 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Honza\Desktop\OTL.exe
MOD - [2008.12.13 12:21:05 | 000,117,696 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp.dll
MOD - [2008.01.18 22:34:00 | 000,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008.01.18 22:26:36 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009.06.04 13:35:02 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009.03.30 17:19:56 | 002,297,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV:64bit: - [2008.11.27 12:55:49 | 000,840,960 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV:64bit: - [2008.11.27 12:54:52 | 000,506,112 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV:64bit: - [2008.11.12 16:44:18 | 000,034,560 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2008.09.01 16:43:18 | 000,098,488 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV:64bit: - [2008.01.18 23:06:52 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008.01.18 23:04:22 | 000,252,928 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2008.01.18 23:01:12 | 000,598,016 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2008.01.18 23:00:54 | 000,195,584 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2008.01.18 23:00:44 | 001,147,904 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:64bit: - [2008.01.18 23:00:18 | 000,689,152 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\fxssvc.exe -- (Fax)
SRV:64bit: - [2007.02.07 17:44:50 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\StkCSrv.exe -- (StkSSrv)
SRV:64bit: - [2006.12.21 09:41:00 | 000,717,824 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\Ati2evxx.exe -- (Ati External Event Utility)
SRV:64bit: - [2006.11.02 12:16:35 | 000,051,200 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\bthserv.dll -- (BthServ)
SRV - [2010.02.05 21:21:49 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009.10.20 19:39:28 | 000,340,456 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -- (AVP)
SRV - [2009.06.04 13:29:33 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.03.12 19:28:40 | 000,288,112 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2008.11.12 16:44:18 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.10.26 20:02:41 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2008.08.07 11:17:30 | 000,575,488 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.07.27 19:01:49 | 000,093,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2007.07.03 06:21:12 | 000,036,864 | ---- | M] (Dassault Systemes) [Auto | Running] -- C:\Program Files (x86)\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe -- (BBDemon)
SRV - [2007.05.31 10:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 10:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007.04.13 08:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2007.02.05 17:13:14 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2007.02.02 13:58:06 | 000,153,088 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006.11.02 14:34:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2006.11.02 07:35:15 | 000,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2006.11.02 07:35:15 | 000,055,846 | ---- | M] () [On_Demand | Running] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)
SRV - [2006.10.26 12:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010.02.03 10:56:34 | 000,082,816 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\pcouffin.sys -- (pcouffin)
DRV:64bit: - [2010.01.20 21:09:51 | 000,069,152 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\SysNative\DRIVERS\Lbd.sys -- (Lbd)
DRV:64bit: - [2009.11.16 03:13:26 | 000,271,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:64bit: - [2009.11.11 16:35:26 | 000,353,296 | ---- | M] () [File_System | System | Running] -- C:\Windows\SysNative\DRIVERS\klif.sys -- (KLIF)
DRV:64bit: - [2009.11.03 16:33:44 | 000,027,152 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\klim6.sys -- (KLIM6)
DRV:64bit: - [2009.10.14 20:18:38 | 000,040,464 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\klbg.sys -- (KLBG)
DRV:64bit: - [2009.10.02 18:39:32 | 000,021,008 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2009.09.01 14:29:56 | 000,157,712 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\kl1.sys -- (kl1)
DRV:64bit: - [2009.06.04 17:44:18 | 000,086,584 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2009.05.05 11:20:34 | 001,202,688 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\smserial.sys -- (smserial)
DRV:64bit: - [2009.01.14 20:53:40 | 000,058,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SIVX64.sys -- (SIVDRIVER)
DRV:64bit: - [2008.12.02 08:56:20 | 000,119,744 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2008.11.12 11:30:52 | 000,867,064 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd)
DRV:64bit: - [2008.10.17 22:40:15 | 000,276,480 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BTHport.sys -- (BTHPORT)
DRV:64bit: - [2008.10.17 22:40:15 | 000,034,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BTHUSB.sys -- (BTHUSB)
DRV:64bit: - [2008.10.17 22:40:15 | 000,023,040 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\BthEnum.sys -- (BthEnum)
DRV:64bit: - [2008.07.29 13:35:18 | 000,022,432 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\WNt500x64\sandra.sys -- (SANDRA)
DRV:64bit: - [2008.07.21 13:11:56 | 000,032,200 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2008.06.06 09:25:44 | 000,008,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2008.05.07 07:40:02 | 000,008,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys -- (UsbserFilt)
DRV:64bit: - [2008.05.07 07:39:44 | 000,023,552 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdcx64)
DRV:64bit: - [2008.05.07 07:39:44 | 000,018,432 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcdx64)
DRV:64bit: - [2008.01.18 23:10:44 | 000,161,848 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\fvevol.sys -- (fvevol)
DRV:64bit: - [2008.01.18 21:47:14 | 000,046,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2008.01.18 21:38:18 | 000,024,064 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MODEMCSA.sys -- (MODEMCSA)
DRV:64bit: - [2008.01.18 21:38:18 | 000,011,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM)
DRV:64bit: - [2008.01.18 21:37:04 | 000,019,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2008.01.18 21:34:20 | 000,115,712 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\bthpan.sys -- (BthPan) Zařízení Bluetooth (síť PAN)
DRV:64bit: - [2008.01.18 21:34:14 | 000,062,976 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\rfcomm.sys -- (RFCOMM) Zařízení Bluetooth (RFCOMM protokol TDI)
DRV:64bit: - [2008.01.18 21:34:00 | 000,032,768 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2008.01.18 21:33:58 | 000,036,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\WinUSB.SYS -- (WINUSB)
DRV:64bit: - [2008.01.18 21:02:44 | 000,017,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CmBatt.sys -- (CmBatt)
DRV:64bit: - [2008.01.18 20:55:42 | 000,460,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2007.10.18 23:29:42 | 003,196,416 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys -- (NETw4v64) Ovladač adaptéru Intel(R)
DRV:64bit: - [2007.09.17 15:53:34 | 000,029,184 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2007.04.24 18:37:00 | 000,051,456 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tosrfusb.sys -- (Tosrfusb)
DRV:64bit: - [2007.04.24 12:20:34 | 000,143,104 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tosrfbd.sys -- (Tosrfbd)
DRV:64bit: - [2007.03.16 01:23:14 | 000,119,552 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wceusbsh.sys -- (wceusbsh)
DRV:64bit: - [2007.03.01 15:53:40 | 000,087,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Tosrfhid.sys -- (Tosrfhid)
DRV:64bit: - [2007.02.13 11:41:28 | 001,462,144 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\StkCMini.sys -- (StkCMini)
DRV:64bit: - [2007.01.22 09:43:26 | 000,055,296 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfsnd.sys -- (TosRfSnd)
DRV:64bit: - [2007.01.15 16:44:04 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys -- (NuidFltr)
DRV:64bit: - [2006.12.21 20:01:30 | 000,012,656 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Program Files\P4G\WCPU.sys -- (WCPU)
DRV:64bit: - [2006.12.21 09:51:10 | 002,795,520 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (R300)
DRV:64bit: - [2006.12.19 08:14:04 | 002,583,040 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw3v64.sys -- (NETw3v64) Ovladač adaptéru Intel(R)
DRV:64bit: - [2006.11.22 12:48:58 | 000,297,272 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
DRV:64bit: - [2006.11.22 06:20:00 | 000,107,008 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\WibuKey64.sys -- (WIBUKEY)
DRV:64bit: - [2006.11.20 16:56:04 | 000,044,672 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tosrfbnp.sys -- (tosrfbnp)
DRV:64bit: - [2006.11.02 06:28:10 | 000,273,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
DRV:64bit: - [2006.10.27 20:01:08 | 000,013,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ATK64AMD.sys -- (MTsensor)
DRV:64bit: - [2006.10.11 15:31:00 | 000,050,688 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tosporte.sys -- (tosporte)
DRV:64bit: - [2005.08.01 15:45:00 | 000,102,016 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\tosrfcom.sys -- (Tosrfcom)
DRV:64bit: - [2005.07.12 13:43:00 | 000,028,160 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tosrfnds.sys -- (tosrfnds)
DRV:64bit: - [2005.07.11 17:59:00 | 000,003,584 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2009.06.04 17:44:18 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\adfs.sys -- (adfs)
DRV - [2008.12.02 08:56:20 | 000,119,744 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2008.11.19 18:21:47 | 000,093,128 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysWOW64\ElbyCDIO.dll -- (ElbyCDIO)
DRV - [2008.10.17 23:31:57 | 000,001,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)
DRV - [2008.10.17 19:25:23 | 000,000,000 | ---D | M] [Kernel | System | Running] -- C:\Windows\CSC -- (CSC)
DRV - [2008.02.01 17:24:06 | 000,032,240 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl -- ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054})
DRV - [2008.01.18 22:36:58 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\winusb.dll -- (WINUSB)
DRV - [2007.02.07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
DRV - [2006.09.18 22:36:40 | 000,003,066 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
DRV - [2004.11.18 11:49:14 | 000,024,786 | ---- | M] (EUTRON) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\eusk2par.sys -- (eusk2par)
DRV - [2000.03.03 04:16:52 | 000,007,424 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\MMIOPORT.SYS -- (MMIOPORT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D5 3B D9 96 67 61 CA 01 [binary data]
IE - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.2
FF - prefs.js..extensions.enabledItems: max@subfighter.com:1.0.3
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.2
FF - prefs.js..extensions.enabledItems: {11483926-db67-4190-91b1-ef20fcec5f33}:0.4
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.5.1
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.463
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {003D3EDC-99B9-4a34-9C20-60CB94F7E829}:2009
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.1


FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.01.27 19:32:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.01.27 19:32:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010.01.12 14:34:05 | 000,000,000 | ---D | M]

[2008.10.17 23:10:26 | 000,000,000 | ---D | M] -- C:\Users\Honza\AppData\Roaming\Mozilla\Extensions
[2010.03.09 23:19:35 | 000,000,000 | ---D | M] -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions
[2008.11.12 11:42:19 | 000,000,000 | ---D | M] (WebTran) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
[2010.02.09 23:30:29 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.02.02 19:37:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010.02.09 23:30:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{11483926-db67-4190-91b1-ef20fcec5f33}
[2009.06.24 17:17:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.01.22 14:13:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{269FB356-C69F-7349-D092-AB28AF836D0E}
[2010.02.02 19:37:18 | 000,000,000 | ---D | M] (IE View) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010.01.22 14:13:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{9864f3b8-68ba-463e-9589-20a4da429bb7}
[2010.01.22 14:13:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{9864f3b8-68ba-463e-9589-20a4da429bb7}-trash
[2009.10.26 18:40:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010.01.22 14:13:18 | 000,000,000 | ---D | M] -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\CrystalFox_Qute@BigRedBrent
[2010.02.02 19:37:18 | 000,000,000 | ---D | M] -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\max@subfighter.com
[2010.01.22 14:14:33 | 000,000,000 | ---D | M] -- C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\dk7rtte6.default\extensions\personas@christopher.beard
[2010.03.09 23:19:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009.10.20 14:30:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2009.02.21 07:24:52 | 000,660,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npOGAPlugin.dll
[2010.01.22 14:11:40 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.22 14:11:40 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.22 14:11:40 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.22 14:11:40 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.22 14:11:40 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2009.06.04 11:58:19 | 000,000,748 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (Pomocná služba pro přihlášení ke službě Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Pomocná služba pro přihlášení ke službě Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe ()
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Lingea Update Center.lnk = C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe (Lingea)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O8:64bit: - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Přidat do Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: Připojit cíl vazby k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Připojit k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Připojit k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 147.228.52.11 147.228.10.15 147.228.150.5
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\sbhook64.dll (Kaspersky Lab)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\kloehk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\sbhook.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll ()
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll ()
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.03.09 23:05:40 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.09 23:05:40 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*

NetSvcs:64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll ()
NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008.10.20 15:28:16 | 000,000,000 | ---D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll ()
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll ()
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll ()
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008.10.20 15:28:52 | 000,000,000 | ---D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#11 Příspěvek od visis »

2. část logu z OTL.txt:

========== Files/Folders - Created Within 30 Days ==========

[2010.03.10 10:02:27 | 000,554,496 | ---- | C] (OldTimer Tools) -- C:\Users\Honza\Desktop\OTL.exe
[2010.03.09 23:05:40 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.03.09 22:54:56 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.03.09 15:08:15 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.02 14:42:22 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2010.03.02 14:40:49 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2010.03.02 14:40:49 | 000,511,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2010.03.02 14:40:47 | 000,472,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2010.03.02 14:40:47 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2010.03.02 14:40:47 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010.03.02 14:40:46 | 000,472,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2010.03.02 14:40:43 | 000,329,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdrm.dll
[2010.03.02 14:40:43 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010.03.02 14:40:43 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2010.02.14 11:13:12 | 000,000,000 | ---D | C] -- C:\ProgramData\ACD Systems
[2010.02.10 14:15:39 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2010.02.10 14:15:32 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll
[2010.02.10 14:15:32 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avicap32.dll
[2010.02.10 14:15:31 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvfw32.dll
[2010.02.10 14:15:31 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
[2010.02.03 10:56:34 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Honza\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2010.03.10 10:09:02 | 003,932,160 | -HS- | M] () -- C:\Users\Honza\NTUSER.DAT
[2010.03.10 10:06:14 | 001,402,454 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.03.10 10:06:14 | 000,602,092 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010.03.10 10:06:14 | 000,590,082 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.03.10 10:06:14 | 000,116,204 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010.03.10 10:06:14 | 000,102,094 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.03.10 10:02:36 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Honza\Desktop\OTL.exe
[2010.03.10 10:00:03 | 000,000,498 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job
[2010.03.10 09:54:13 | 000,000,040 | -HS- | M] () -- C:\ProgramData\.zreglib
[2010.03.10 09:53:12 | 000,003,776 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.03.10 09:53:12 | 000,003,776 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.03.10 09:53:06 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.03.10 09:52:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.03.10 09:52:46 | 2683,691,008 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.10 00:42:31 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010.03.10 00:42:20 | 000,524,288 | -HS- | M] () -- C:\Users\Honza\NTUSER.DAT{a7bdf3ed-6a85-11db-b5ae-f1534be43d84}.TMContainer00000000000000000001.regtrans-ms
[2010.03.10 00:42:20 | 000,065,536 | -HS- | M] () -- C:\Users\Honza\NTUSER.DAT{a7bdf3ed-6a85-11db-b5ae-f1534be43d84}.TM.blf
[2010.03.10 00:41:53 | 003,514,417 | -H-- | M] () -- C:\Users\Honza\AppData\Local\IconCache.db
[2010.03.09 23:05:42 | 000,001,707 | ---- | M] () -- C:\UsbFix_Upload_Me_Honza-PC.zip
[2010.03.09 22:54:43 | 001,775,657 | ---- | M] () -- C:\Users\Honza\Desktop\UsbFix.exe
[2010.03.09 18:31:19 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010.03.03 21:55:40 | 000,002,431 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.03.03 21:50:39 | 000,083,791 | -H-- | M] () -- C:\treeinfo.wc
[2010.03.02 19:06:31 | 000,136,216 | ---- | M] () -- C:\Users\Honza\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.03.02 19:04:07 | 003,315,992 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.03.01 17:27:37 | 000,002,617 | ---- | M] () -- C:\Users\Honza\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010.02.28 20:55:41 | 000,020,480 | ---- | M] () -- C:\Users\Honza\Desktop\Zeměpisná olympiáda Klatovy.xls
[2010.02.28 20:48:59 | 000,002,613 | ---- | M] () -- C:\Users\Honza\Desktop\Microsoft Office Excel 2007.lnk
[2010.02.16 19:50:21 | 000,256,063 | ---- | M] () -- C:\Users\Honza\Desktop\alza.jpg
[2010.02.16 14:47:38 | 000,052,736 | ---- | M] () -- C:\Users\Honza\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.14 11:16:19 | 000,002,751 | ---- | M] () -- C:\Users\Public\Desktop\ACDSee Pro 2.5.lnk
[2010.02.10 22:44:54 | 002,572,800 | ---- | M] () -- C:\Users\Honza\Desktop\prezentace_new1.ppt
[2010.02.10 14:48:33 | 000,010,632 | ---- | M] () -- C:\Users\Honza\Desktop\ERIN 2010 abstrakt.docx
[2010.02.10 14:44:28 | 000,002,699 | ---- | M] () -- C:\Users\Honza\Desktop\Microsoft Office Word 2007.lnk
[2010.02.09 11:12:25 | 002,361,082 | ---- | M] () -- C:\Users\Honza\Desktop\PPPP.pptx
[2010.02.08 18:45:01 | 000,131,584 | ---- | M] () -- C:\Users\Honza\Desktop\podnikatelsk_plan.doc

========== Files Created - No Company Name ==========

[2010.03.09 23:05:42 | 000,001,707 | ---- | C] () -- C:\UsbFix_Upload_Me_Honza-PC.zip
[2010.03.09 22:54:22 | 001,775,657 | ---- | C] () -- C:\Users\Honza\Desktop\UsbFix.exe
[2010.03.02 14:42:23 | 000,817,664 | ---- | C] () -- C:\Windows\SysNative\jscript.dll
[2010.03.02 14:41:44 | 000,002,048 | ---- | C] () -- C:\Windows\SysNative\tzres.dll
[2010.03.02 14:40:49 | 000,594,944 | ---- | C] () -- C:\Windows\SysNative\RMActivate_isv.exe
[2010.03.02 14:40:49 | 000,594,432 | ---- | C] () -- C:\Windows\SysNative\RMActivate.exe
[2010.03.02 14:40:48 | 000,413,696 | ---- | C] () -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010.03.02 14:40:47 | 000,535,040 | ---- | C] () -- C:\Windows\SysNative\secproc.dll
[2010.03.02 14:40:47 | 000,534,016 | ---- | C] () -- C:\Windows\SysNative\secproc_isv.dll
[2010.03.02 14:40:47 | 000,409,600 | ---- | C] () -- C:\Windows\SysNative\RMActivate_ssp.exe
[2010.03.02 14:40:44 | 000,159,232 | ---- | C] () -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2010.03.02 14:40:44 | 000,158,720 | ---- | C] () -- C:\Windows\SysNative\secproc_ssp.dll
[2010.03.02 14:40:43 | 000,457,216 | ---- | C] () -- C:\Windows\SysNative\msdrm.dll
[2010.02.28 20:55:40 | 000,020,480 | ---- | C] () -- C:\Users\Honza\Desktop\Zeměpisná olympiáda Klatovy.xls
[2010.02.16 19:50:20 | 000,256,063 | ---- | C] () -- C:\Users\Honza\Desktop\alza.jpg
[2010.02.14 11:13:31 | 000,002,751 | ---- | C] () -- C:\Users\Public\Desktop\ACDSee Pro 2.5.lnk
[2010.02.10 14:48:32 | 000,010,632 | ---- | C] () -- C:\Users\Honza\Desktop\ERIN 2010 abstrakt.docx
[2010.02.10 14:15:39 | 001,570,816 | ---- | C] () -- C:\Windows\SysNative\quartz.dll
[2010.02.10 14:15:37 | 000,054,272 | ---- | C] () -- C:\Windows\SysNative\iyuv_32.dll
[2010.02.10 14:15:37 | 000,038,400 | ---- | C] () -- C:\Windows\SysNative\msvidc32.dll
[2010.02.10 14:15:37 | 000,025,600 | ---- | C] () -- C:\Windows\SysNative\msyuv.dll
[2010.02.10 14:15:36 | 000,013,824 | ---- | C] () -- C:\Windows\SysNative\tsbyuv.dll
[2010.02.10 14:15:35 | 000,015,872 | ---- | C] () -- C:\Windows\SysNative\msrle32.dll
[2010.02.10 14:15:30 | 000,143,360 | ---- | C] () -- C:\Windows\SysNative\msvfw32.dll
[2010.02.10 14:15:29 | 000,108,544 | ---- | C] () -- C:\Windows\SysNative\avifil32.dll
[2010.02.10 14:15:29 | 000,093,184 | ---- | C] () -- C:\Windows\SysNative\mciavi32.dll
[2010.02.10 14:15:29 | 000,076,800 | ---- | C] () -- C:\Windows\SysNative\avicap32.dll
[2010.02.10 14:15:12 | 000,464,384 | ---- | C] () -- C:\Windows\SysNative\drivers\srv.sys
[2010.02.10 14:15:12 | 000,141,824 | ---- | C] () -- C:\Windows\SysNative\drivers\srvnet.sys
[2010.02.10 14:14:59 | 000,134,656 | ---- | C] () -- C:\Windows\SysNative\drivers\mrxsmb.sys
[2010.02.10 14:14:58 | 000,273,408 | ---- | C] () -- C:\Windows\SysNative\drivers\mrxsmb10.sys
[2010.02.10 14:12:29 | 004,691,032 | ---- | C] () -- C:\Windows\SysNative\ntoskrnl.exe
[2010.02.10 14:12:16 | 001,418,840 | ---- | C] () -- C:\Windows\SysNative\drivers\tcpip.sys
[2010.02.08 19:35:31 | 002,361,082 | ---- | C] () -- C:\Users\Honza\Desktop\PPPP.pptx
[2010.02.08 18:44:37 | 000,131,584 | ---- | C] () -- C:\Users\Honza\Desktop\podnikatelsk_plan.doc
[2010.02.03 11:00:19 | 000,000,034 | ---- | C] () -- C:\Users\Honza\AppData\Roaming\pcouffin.log
[2010.02.03 10:56:34 | 000,099,384 | ---- | C] () -- C:\Users\Honza\AppData\Roaming\inst.exe
[2010.02.03 10:56:34 | 000,007,859 | ---- | C] () -- C:\Users\Honza\AppData\Roaming\pcouffin.cat
[2010.02.03 10:56:34 | 000,001,167 | ---- | C] () -- C:\Users\Honza\AppData\Roaming\pcouffin.inf
[2009.12.10 13:06:16 | 000,223,704 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL90SP1_KB973924MSI080A.txt
[2009.12.10 13:06:16 | 000,011,884 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL90SP1_KB973924UI080A.txt
[2009.12.10 13:04:31 | 000,524,046 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL80SP1_KB973923MSI06B3.txt
[2009.12.10 13:04:31 | 000,011,804 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL80SP1_KB973923UI06B3.txt
[2009.12.10 13:04:13 | 000,525,560 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL80SP1_KB973923MSI0679.txt
[2009.12.10 13:04:13 | 000,011,868 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_ATL80SP1_KB973923UI0679.txt
[2009.12.10 11:34:52 | 000,000,098 | ---- | C] () -- C:\Windows\WirelessFTP.INI
[2009.11.06 10:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009.10.01 19:32:10 | 000,000,104 | ---- | C] () -- C:\Windows\APCBT.ini
[2009.08.27 09:04:16 | 000,000,089 | ---- | C] () -- C:\Windows\MyHeritage.INI
[2009.08.27 09:02:13 | 000,454,656 | ---- | C] () -- C:\Windows\SysWow64\PaintX.dll
[2009.08.10 21:19:46 | 000,000,548 | ---- | C] () -- C:\Users\Honza\AppData\Roaming\AutoGK.ini
[2009.06.24 09:46:58 | 000,424,076 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_vcredistMSI5B07.txt
[2009.06.24 09:46:58 | 000,011,382 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_vcredistUI5B07.txt
[2009.06.19 19:06:22 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2009.06.19 19:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2009.05.20 09:28:42 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.05.05 19:05:06 | 000,000,000 | ---- | C] () -- C:\Windows\tosOBEX.INI
[2009.03.19 10:42:26 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2009.03.07 21:54:52 | 000,000,093 | ---- | C] () -- C:\Windows\DIDAKTA.INI
[2009.03.06 18:52:23 | 000,793,550 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_NET_Framework35_LangPack_MSI69D8.txt
[2009.03.06 18:51:51 | 000,033,023 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
[2009.03.06 18:51:44 | 000,000,002 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_dotnetfx35error_lp.txt
[2009.03.06 18:51:43 | 000,075,814 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_dotnetfx35install_lp.txt
[2009.02.21 07:25:20 | 000,667,136 | ---- | C] () -- C:\Windows\SysWow64\OGACheckControl.dll
[2009.01.25 22:10:48 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.01.09 00:01:22 | 000,679,936 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009.01.08 20:55:47 | 000,001,852 | ---- | C] () -- C:\Windows\cyklopruvodce.INI
[2008.12.27 14:56:05 | 001,421,864 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2008.12.17 22:14:16 | 007,917,568 | ---- | C] () -- C:\ProgramData\sandra.mda
[2008.11.12 12:37:15 | 000,052,736 | ---- | C] () -- C:\Users\Honza\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.11.12 11:41:46 | 000,002,719 | ---- | C] () -- C:\Windows\TRNCOM.INI
[2008.11.04 19:26:17 | 000,028,246 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_depcheckdotnetfx30.txt
[2008.11.04 19:25:56 | 000,000,654 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_dotnetfx3error.txt
[2008.11.04 19:25:55 | 000,032,584 | ---- | C] () -- C:\Users\Honza\AppData\Local\dd_dotnetfx3install.txt
[2008.11.04 19:25:55 | 000,003,480 | ---- | C] () -- C:\Users\Honza\AppData\Local\uxeventlog.txt
[2008.10.23 09:10:40 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll
[2008.10.22 22:23:01 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2008.10.20 14:38:23 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2008.10.20 14:37:09 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008.10.20 07:30:29 | 000,023,552 | ---- | C] () -- C:\Windows\SysWow64\SYNSOACC.dll
[2008.10.20 07:28:56 | 000,000,571 | ---- | C] () -- C:\Windows\SysWow64\FeMakro.ini
[2008.10.20 07:28:56 | 000,000,497 | ---- | C] () -- C:\Windows\SysWow64\FeAnim.ini
[2008.10.17 20:19:57 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2008.06.12 20:36:38 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2007.03.29 23:00:40 | 000,203,264 | R--- | C] () -- C:\Windows\SysWow64\CddbCdda.dll
[2006.12.05 12:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\TosBtAcc.dll
[2005.11.10 02:52:42 | 000,059,392 | ---- | C] () -- C:\Windows\sm56spn.dll
[2005.11.10 02:52:42 | 000,059,392 | ---- | C] () -- C:\Windows\sm56itl.dll
[2005.11.10 02:52:42 | 000,059,392 | ---- | C] () -- C:\Windows\sm56eng.dll
[2005.11.10 02:52:42 | 000,059,392 | ---- | C] () -- C:\Windows\sm56brz.dll
[2005.11.10 02:52:42 | 000,053,248 | ---- | C] () -- C:\Windows\sm56ger.dll
[2005.11.10 02:52:42 | 000,053,248 | ---- | C] () -- C:\Windows\sm56fra.dll
[2005.11.10 02:52:42 | 000,045,056 | ---- | C] () -- C:\Windows\sm56jpn.dll
[2005.11.10 02:52:42 | 000,040,960 | ---- | C] () -- C:\Windows\sm56cht.dll
[2005.11.10 02:52:42 | 000,040,960 | ---- | C] () -- C:\Windows\sm56chs.dll
[2005.07.22 20:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\TosCommAPI.dll
[2002.10.15 23:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2000.03.03 04:16:52 | 000,007,424 | R--- | C] () -- C:\Windows\SysWow64\drivers\MMIOPORT.SYS

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2008.01.18 22:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
[2008.01.18 22:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
[2008.01.18 23:03:56 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2008.01.18 22:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2008.01.18 22:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
[2008.01.18 22:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
[2008.01.18 23:03:02 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2008.01.18 22:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 12:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[2008.01.18 23:08:52 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2008.10.17 22:46:09 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=BB55C79E0595D8CFBE4A80A3C9EB77EA -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\atapi.sys
[2008.10.17 22:46:09 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=05001E1FACCE49DB895B8526B05C7302 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_37cb142cf6008bc1\atapi.sys
[2008.01.18 23:07:48 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.01.18 23:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >

< %SYSTEMDRIVE%\viamraid.sys /s /md5 >

< %SYSTEMDRIVE%\nvata.sys /s /md5 >

========== Alternate Data Streams ==========

@Alternate Data Stream - 1239 bytes -> C:\ProgramData\Microsoft:MlOw0V7reNaRzHWg2swyxJVZ
@Alternate Data Stream - 1227 bytes -> C:\Program Files (x86)\Common Files\System:Zun6fX2GqQKGgoJCZVDsAvr1t1vF
@Alternate Data Stream - 1066 bytes -> C:\ProgramData\Microsoft:jwMIX95OZ5msAkrhTjRMtOQ
< End of report >

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#12 Příspěvek od visis »

Log z Extras.txt:

OTL Extras logfile created on: 10.3.2010 10:03:32 - Run 1
OTL by OldTimer - Version 3.1.36.0 Folder = C:\Users\Honza\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 41,00% Memory free
5,00 Gb Paging File | 3,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,48 Gb Total Space | 16,95 Gb Free Space | 11,57% Space Free | Partition Type: NTFS
Drive D: | 86,40 Gb Total Space | 0,05 Gb Free Space | 0,05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 991,22 Mb Total Space | 48,20 Mb Free Space | 4,86% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HONZA-PC
Current User Name: Honza
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3950918805-3815427779-4285382183-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [ACDSee Pro 2.5.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee Pro\2.5\ACDSeeQVPro25.exe" "%1" (ACD Systems)
Directory [cmd] -- cmd.exe /s /k pushd "%V" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Pro 2.5.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee Pro\2.5\ACDSeeQVPro25.exe" "%1" (ACD Systems)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 18 EE 9E 41 C1 32 C9 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04628782-1064-4C61-BEFD-FD1AA44FC0F3}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{05CD7267-790B-4875-B49B-0B310F9BDC66}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{0C1C46D3-956D-470C-A0CB-3F2FEF5D9A67}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1A31403D-C3BC-4AF9-9C5F-7A9243BF4EA3}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{2019E60E-A0DE-4F99-A6B1-792A7C312A06}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{28B171C2-3A46-4A6A-B34E-6D2A02BEB17B}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra professional business 2009\wnt500x64\rpcsandrasrv.exe |
"{32222BB1-5F77-4059-B8F3-6B58A2A21E77}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{37372CFE-4E1D-4AF3-A6EB-344F7BF0F5E1}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{384F92E4-2F25-44CC-88E5-A90EEA99D341}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{40627CEE-9DAC-45E7-808E-9F62E014CA52}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{5A024C60-91A4-4B90-877B-C823D457499C}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra professional business 2009\rpcagentsrv.exe |
"{6536FBC3-72DD-4BAD-843C-3870DD059F7A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6BA91EED-63AA-40B3-A2B4-3D8889BA35A7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{75EE94C0-8444-4D80-9A40-686C7F8498A8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{76AF692D-E87B-4E72-B903-9AE520AB907E}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{79EA2DB9-AD1D-4CD5-8367-07B4D1B260A7}" = rport=10243 | protocol=6 | dir=out | app=system |
"{874B662B-6326-4611-A037-5856BDAF05D3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8C853F17-D4FD-4FDF-944D-342179FA253B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A88F4477-E6B9-44DA-9D26-2F7D8F438864}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{A94732BF-0A45-41A4-81BD-BCF5D09543A7}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AD626AE7-BA64-41A3-B366-91558D63A15D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BA0D91A2-4206-4015-ABAF-5A1D7AC8A06D}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{C2518BBC-3F64-4BE4-BDEA-AE079BA04781}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{CD7B7DFC-D0A3-4354-BAB7-A66D6687CBBD}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{CF083F6E-8884-4836-AFAC-51B0DC8FCDEC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D71EF680-D5F8-43F1-A90F-27F86E12A5A2}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{F4A2EFCC-A0E1-4F9C-9212-13CCA26A8A6C}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F81C7713-63D0-45EC-912E-78B1C64A560F}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F889C8AD-F228-422E-86C4-B6686A684C86}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{016842B8-502B-48E0-83AE-B7ADD3DE2DE3}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{020FBD1E-3190-4675-B6D8-61A91A167B0A}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{02E04C25-FC08-4E2C-A0E9-2E068F2E4214}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0803C377-B09E-4EC5-9C21-5EC7BAA3D720}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{09B5906F-297C-4D57-A7CA-3958AA01B04A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B2CD913-C15D-4438-8B5C-1300CE8ED669}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd8\powerdvd8.exe |
"{0BE6F00F-D421-4D72-B3CD-237F3497E361}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{10DFA8B7-8096-4082-AEE0-B5FCFC6986E5}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) |
"{141920A0-87DF-4B54-969F-91E1E749E2F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{18DBFD9A-FDF3-4E76-A1E6-D2C8B8FF7BBE}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{217FA30C-46C0-469A-AECB-2BF6FE870541}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{265F9794-B9B8-4C2E-A278-FDC14C2E7468}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2BAD2F9E-3248-448F-AB9C-8DFEE37199B3}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{2C58F7C3-296B-43C3-BF99-C84370F4F238}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{3352FB8E-1E81-46AD-82D1-D38B10963FA8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{342575F2-9B10-4E50-A077-3FED064E7BD7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{365A3F22-5B34-462D-88D0-AED34C771A21}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{36A2EF2D-2992-4A2E-99A4-5B3AC122E04B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{36EDEA34-8E42-475A-B02D-933A8B5D8DEE}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{380B9F51-E931-47DB-B47B-EB210C25834B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{3DC6D1B8-43E0-4575-9EB7-52B526C51374}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{41ADEE8A-44A5-4899-BBBB-F36DF1AA5AF2}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4258C44D-AC5E-4696-BA25-32B8EA440143}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{48A54501-DD5D-4261-996A-85C0680E3446}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4BC21D85-F0D3-466F-9EC8-D6548FA9E233}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{4C62CC44-273C-4CAB-B1BF-F889C59498D4}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4E0795EC-08A0-4426-AB65-F07D7F7A15E2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4E4A8FB4-4FB0-40A2-8871-340E5770D250}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{504949AF-466D-486F-979B-FE691E9EE828}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5A1313C2-BC4B-43B1-B1AC-B23F654C265C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5A8E9762-4903-4425-8B5F-528DA342AEC0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5C75EA67-863F-4526-A934-6A82B59DCFCF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5F20A1BD-62EE-4228-AB56-155948C61062}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{619A48C9-C6A2-43BC-87A2-1BCE3A3FCEA1}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{62F621AE-E938-430B-A8F0-032F75044BBD}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{67FF2AFA-5F95-4C6F-839F-0464DA1758F6}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{69AA763E-2328-44D0-A63A-76F96889331F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{70CDD606-BB5F-45BC-9974-D0A537EFFF02}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{70FF2E85-7078-441C-873E-5D3D31A26459}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{74123EB3-30E5-4500-A068-C06AC099F7B9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{78D7A8DE-1FE0-4B3A-AF49-450947CA0108}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7B392302-EF5A-47A3-995D-B602E092B698}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7CB8ED95-9B54-4BAE-9B8B-D787CA0DD9E5}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7D3FCE88-3CAD-4A7A-85BA-EA4059B25C37}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7E5AEF7B-A69E-4E1C-8843-7ED22A4A3A2B}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8038A074-E1E1-436C-9C43-8B2A5F6FF59F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8416176A-AC0E-4CE8-B46F-9AD5426BDB4B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{881083A6-3C0A-4D38-9751-D9D617F656B6}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{89CCFC3C-55A8-42E1-A331-DDC6517F23D6}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8BA64694-1961-4208-84D0-CABFBDD82788}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8E6EA4AA-1986-4AD8-BA04-4D848489830F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8E7880D1-FB7B-4EDC-A7F1-A651F659B920}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{96B09287-2ACC-471A-A55F-032629472695}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{976D1511-EDA6-4478-92D3-7B66CCD77FE4}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{99046EC9-0C66-41BA-8292-562544C2B22D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9BADEEA4-9432-46E7-B571-623246E40178}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9F63F5C8-3217-4D70-921A-BFC447D472DF}" = protocol=6 | dir=out | app=system |
"{AC46F2FE-AF99-42D6-AD4E-4BE43B64BF7F}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AD2D2022-99C2-47DC-B22C-FC51E2F42ED9}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AF31C07D-08B2-4F09-82EC-D6D881883C91}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B214D243-DF35-4100-9D80-6744CABEACE2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B29164CE-C42B-41D6-A2EF-AA5CB067B5E2}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B3342BCE-FBD1-442B-9FCB-960CAC8988AA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B36A4F17-0F5A-42AA-8F05-B8684D4E78E2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B5D68A7D-1A44-41AC-A206-E670948A3608}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B802D886-DF28-46EF-BA2E-C2F059F02828}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{BBF29986-6637-4C37-8873-720399322297}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{BE29911D-C4F7-4E48-81F6-A51628D00CB1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BF87F94B-27F0-4208-91C0-20AF72432EB1}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C1BDA2BB-619B-4CB7-9B50-57596076D200}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C5878325-BA6F-4B2E-812A-F170616320F6}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{C6B7D760-41B0-423A-8D58-08BC06236AC9}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C97279D2-305B-480B-9397-0F28AEBFCC39}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C9A1BD70-054B-4F39-B80A-859B3BFC29FB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CACE54F5-9668-4AF1-84D8-E8D7AB4A4993}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CB697C0D-E187-4F1B-9D2B-ED107DCA023D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D397F1BA-4E91-4141-A31C-80A69080EA91}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D5842FB0-EF5B-46C3-8084-9C89ED030779}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D5D86891-404A-4330-B20D-0D48045EDE44}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D6D84D7D-D6A9-41B8-BFC9-C2C0342864A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DC729EEB-2EEF-4B2A-9F87-A63B3F735AAC}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{E39BB97B-6E0B-4AB1-AC0B-F0629B8A4FC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E57649CA-4EB4-4358-9506-7986B83404C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E82C7A1F-6537-492D-B0A8-4ACD38C0AE14}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E92DB134-1AF2-4CA5-9C2E-3535FC0472D3}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EC7AE1CA-AC0C-4363-BA2E-CB1379C461A8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{EF00C790-36F2-4F48-89B3-D4CC9F03A077}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EF0FCCB4-4782-4704-8AF7-319E4AD525F6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F148EC0C-1F09-49C1-85DE-08E8B1F9E8E3}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F180636C-FA63-43D7-91E5-2D2490D9487D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F5322CA7-B87C-41C4-8C06-2E987BA461C1}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F9FA2BDB-0DBC-4381-983A-0A5E4A3C54D0}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{FB89E8CF-32EC-4294-AD95-CC7114EC1B6C}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FDEBB009-72F7-4A79-B99C-D570D521FC87}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"TCP Query User{3CDBEDBB-1978-44E1-9464-5895318C37C2}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\czech\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\czech\setup.exe |
"UDP Query User{72321881-7D9B-4AC8-B609-6226D0E01501}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\czech\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\czech\setup.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00060000-0000-1004-8002-0000C06B5161}" = WIBU-KEY Setup (WIBU-KEY Remove)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX300_series" = Canon MX300 series
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{5783F2D7-7001-0405-0102-0060B0CE6BBA}" = AutoCAD 2009 - český
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Centrum zařízení Windows Mobile
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{68660049-8D48-427C-9FF7-139D8340CDC0}" = MSVC80_x64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{82B2394D-F5CC-42F0-8DC1-48B3CAA382CC}" = Dassault Systemes Software Prerequisites x86-x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{92DBCA36-9B41-4DD1-941A-AED149DD37F0}" = Aktualizace ovladače pro aplikaci Centrum zařízení Windows Mobile
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B9162E8-4274-4323-A31B-444ECA641B8A}" = Adobe Photoshop Lightroom 2 64-bit
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{B0EFB716-085B-4564-8060-212E41F5CE50}" = Pomocník pro přihlášení ke službě Windows Live ID
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1" = SiSoftware Sandra Professional Business 2009
"{C74A84EC-7C5F-4C36-A4A6-381E516D643B}" = Microsoft IntelliPoint 7.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{ED930C57-96A9-001D-9F4E-DA24889BB84C}" = ATI Catalyst Install Manager
"{EEA66F3F-34EC-2CC7-1450-BDC12C3D7635}" = ccc-utility64
"9CD348AE9C64C4B939B624E8E24F3903EFDFC82B" = Balíček ovladače systému Windows - Nokia Modem (05/22/2008 7.00.0.1)
"AutoCAD 2009 - český" = AutoCAD 2009 - český
"BatteryBar" = BatteryBar (remove only)
"BC15EA930074932BB2C4B4493C9FD4EA95087D1A" = Balíček ovladače systému Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Balíček ovladače systému Windows - Nokia Modem (05/22/2008 3.8)
"Dassault Systemes B18_0" = Dassault Systemes Software B18
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UltSounds" = Zvuková schémata systému Windows
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™
"Vista Codec x64 Components_is1" = Vista Codec x64 Components

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}" = ATK Media
"{147349F4-7B2D-4C92-86E8-6BD78BBD4F7B}" = Branding
"{1588FCDE-E779-AA74-BF76-64C8037C5C9F}" = ccc-core-static
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{197DB408-5876-CEB2-4307-492BAD8DA254}" = Catalyst Control Center Graphics Full New
"{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}" = PC Connectivity Solution
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = LifeFrame2
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15
"{26E20136-E332-4BC6-903F-ADDCAEE53263}" = ArCon 9 Profesionál
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2D95950E-6D76-43E7-94A5-D9DBA2FD29E4}" = ACDSee Pro 2.5
"{3050C7C3-DA0C-4DE8-AF7C-AB0BA152C0D7}" = Nexus Radio
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}" = ATK Hotkey
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{425AD62D-5B16-494C-8AAB-6B3D0CF2527A}" = Adobe Setup
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{47C6F987-685A-41AE-B092-E75B277AEE39}" = Adobe Flash CS4 Extension - Flash Lite STI others
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5977A284-6ADB-4CC1-BEC5-1CDE7908ACA3}" = Vista Manager
"{5B09BD67-4C99-46A1-8161-B7208CE18121}" = QuickTime
"{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}" = ATKOSD2
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5DB65884-C963-4454-AABA-4CA3089281FA}" = NVIDIA PhysX
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C381DB2-32D8-31BF-9CDF-BDF954A62692}" = Skins
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73321F78-1DE8-F60C-2882-3595D0FD2709}" = Catalyst Control Center Graphics Previews Common
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83744391-B5A4-40E3-8A7D-E8BF39CB00ED}" = Adobe Creative Suite 4 Design Premium
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{85243696-5e58-4357-9cf8-3498c609941d}" = NeroLiveGadget Help
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{88D2DA61-9D98-4284-B1D7-9A6EF6D81C13}" = DxO Optics Pro 6
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CFEBE9C-F29F-4C49-80E0-7106970F8734}" = Power4Gear eXtreme
"{900792CC-3203-356C-EC2D-C3E558991ACE}" = Home Designer Suite 8
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{91C0B95B-B83A-4828-A775-BBE2DD421029}" = Nero 7 Premium
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9578C0CD-8108-4379-9026-4601F59859A0}" = Google Earth Pro
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky internet security 2010
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{A1C962E2-2426-49C6-A38B-9A07E40D607C}" = Microsoft Games for Windows - LIVE
"{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}" = Nokia PC Suite
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-1029-4770-7760-000000000004}" = Adobe Acrobat 9 Pro - Czech, Hungarian, Polish, Slovak
"{AC76BA86-1029-4770-7760-000000000004}_930" = Adobe Acrobat 9.3.0 - CPSID_52073
"{AC76BA86-1029-4770-7760-000000000004}{AC76BA86-1029-4770-7760-000000000004}" = Adobe Acrobat 9 Pro - Czech, Hungarian, Polish, Slovak
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B7570B18-C437-1C02-54DA-806608D306FB}" = Catalyst Control Center Core Implementation
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD3374D3-C2E6-42B7-A80B-E850B6886246}" = Adobe Flash CS4 STI-other
"{BD8A0C60-1AEB-11D6-B8E1-00025521AE60}" = VBA (3821b)
"{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}" = Nokia Connectivity Cable Driver
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C61177FD-37C4-4C5F-BE6C-E04A8AC399B6}" = EclipseCrossword
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D3162DFC-7CA1-47A9-AA00-15BE80E3B1F8}" = 602XML Filler
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E51F3CCD-B4AD-87B1-13AE-A8466D595E13}" = Catalyst Control Center Graphics Light
"{E52A48FB-1422-21E3-24DF-A6702202DB02}" = Catalyst Control Center Graphics Previews Vista
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FA244D38-0FED-9304-EE5D-567C5BF7ED32}" = Catalyst Control Center Graphics Full Existing
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"001FFFFFFF12FF00FF1101F03F02F000-R1" = ArchiCAD 12 CZE
"7-Zip" = 7-Zip 4.57
"AC3Filter" = AC3Filter (remove only)
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"Adobe_b421102ce31f2649ef3785f2a17166f" = Adobe Creative Suite 4 Design Premium
"AnyDVD" = AnyDVD
"Astraware Zuma for Pocket PC" = Zuma for Pocket PC
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"AutoGK" = Auto Gordian Knot 2.55
"AviSynth" = AviSynth 2.5
"CANONIJPLM100" = PIXMA Extended Survey Program
"CCleaner" = CCleaner
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Cykloturistický průvodce_is1" = Cykloturistický průvodce ČR verze 1.4.1
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 6_is1" = DVDFab 6.2.1.8 (31/12/2009)
"Dynamic-Photo HDR 4_is1" = Dynamic-Photo HDR 4.65
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Family Tree Builder" = MyHeritage Family Tree Builder
"Fraps" = Fraps (remove only)
"HijackThis" = HijackThis 2.0.2
"InstallShield_{26E20136-E332-4BC6-903F-ADDCAEE53263}" = ArCon 9 Profesionál
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky internet security 2010
"Lexicon5" = Lingea Lexicon 5
"LingvoSoft Travel Dictionary ML23 2008 for Pocket PC" = LingvoSoft Travel Dictionary ML23 2008 for Pocket PC
"Luxor 4 Quest For The Afterlife 1.00" = Luxor 4 Quest For The Afterlife 1.00
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MoZiGo&Colorado minimalizátor&MoZi 1.1 pre PDA&R~1F71E47E_is1" = MoZiGo 2009.12.2.22
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"Nokia PC Suite" = Nokia PC Suite
"Pocket Informant" = Pocket Informant 8.51
"RAR Password Cracker" = RAR Password Cracker 4.12
"Registrace uživatele zařízení Canon MX300 series" = Registrace uživatele zařízení Canon MX300 series
"Satellite Antenna Alignment_is1" = Satellite Antenna Alignment v2.36.8
"ShockwaveFlash" = Macromedia Flash Player 8
"SolSuite_is1" = SolSuite 2008 v8.8
"SpeedFan" = SpeedFan (remove only)
"ST6UNST #1" = Didakta - Zeměpis
"Syncrosoft's License Control" = Syncrosoft's License Control
"Themen aktuell 1" = Themen aktuell 1
"Totalcmd" = Total Commander (Remove or Repair)
"UltraISO_is1" = UltraISO Premium V9.31
"USB2.0 1.3M WebCam" = USB2.0 1.3M WebCam
"VidShot Capturer_is1" = VidShot Capturer
"VobSub" = VobSub v2.23 (Remove Only)
"WinRAR archiver" = WinRAR
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"ZonerPhotoStudio12_CZ_is1" = Zoner Photo Studio 12

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9.3.2010 18:08:26 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0xf38, čas spuštění aplikace
0x01cabfd500a08ed9.

Error - 9.3.2010 18:09:33 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x668, čas spuštění aplikace
0x01cabfd52a25421d.

Error - 9.3.2010 18:13:52 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x12fc, čas spuštění aplikace
0x01cabfd5c24c19b6.

Error - 9.3.2010 18:15:10 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x5cc, čas spuštění aplikace
0x01cabfd5f0b8f3f5.

Error - 9.3.2010 18:16:07 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x117c, čas spuštění aplikace
0x01cabfd6137f6144.

Error - 9.3.2010 18:18:14 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x8b0, čas spuštění aplikace
0x01cabfd660de5ff3.

Error - 9.3.2010 18:18:36 | Computer Name = Honza-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.6001.18164, časové razítko
0x4907e242, chybující modul unknown, verze 0.0.0.0, časové razítko 0x00000000,
kód výjimky 0xc0000005, posun chyby 0x00000000, ID procesu 0x13f0, čas spuštění aplikace
0x01cabfd66e9bdde6.

Error - 9.3.2010 18:25:53 | Computer Name = Honza-PC | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll
se nezdařilo. Závislé sestavení Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 10.3.2010 4:54:04 | Computer Name = Honza-PC | Source = SideBySide | ID = 16842830
Description = Selhalo generování kontextu aktivace pro: C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe. Chyba v souboru manifestu nebo zásad na řádku
. Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která
je již aktivní. Konfliktní součásti jsou: Součást 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_152e7382f3bd50c6.manifest.
Součást
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc.manifest.

Error - 10.3.2010 4:56:42 | Computer Name = Honza-PC | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll
se nezdařilo. Závislé sestavení Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

[ OSession Events ]
Error - 19.1.2010 16:02:33 | Computer Name = Honza-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 516 seconds with 240 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 9.3.2010 18:23:55 | Computer Name = Honza-PC | Source = HTTP | ID = 15016
Description =

Error - 9.3.2010 18:24:15 | Computer Name = Honza-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9.3.2010 18:24:15 | Computer Name = Honza-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 9.3.2010 19:42:29 | Computer Name = Honza-PC | Source = DCOM | ID = 10010
Description =

Error - 10.3.2010 4:52:33 | Computer Name = Honza-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 10.3.2010 4:52:43 | Computer Name = Honza-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\Windows\SysWow64\Drivers\eusk2par.sys bylo zablokováno
kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru o kompatibilní
verzi ovladače.

Error - 10.3.2010 4:53:06 | Computer Name = Honza-PC | Source = HTTP | ID = 15016
Description =

Error - 10.3.2010 4:53:58 | Computer Name = Honza-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10.3.2010 4:53:58 | Computer Name = Honza-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 10.3.2010 4:59:38 | Computer Name = Honza-PC | Source = Dhcp | ID = 1002
Description = Zapůjčení adresy IP 10.109.132.33 pro síťovou kartu s adresou 0018F32FAA1C
byla serverem DHCP 147.228.52.200 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

[ TuneUp Events ]
Error - 21.1.2010 13:21:58 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-21 18:21:58', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','1640',0)

Error - 21.1.2010 13:22:25 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-21 18:22:25', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','2912',0)

Error - 21.1.2010 14:52:21 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-21 19:52:21', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','5364',0)

Error - 21.1.2010 16:16:21 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-21 21:16:21', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','3180',0)

Error - 28.1.2010 15:46:57 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-28 20:46:57', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','2860',0)

Error - 3.2.2010 10:37:28 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-02-03 15:37:28', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','6004',0)

Error - 2.3.2010 15:59:30 | Computer Name = Honza-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-03-02 20:59:30', '\device\harddiskvolume1\program
files (x86)\malwarebytes' anti-malware\mbam.exe','3704',0)


< End of report >

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#13 Příspěvek od visis »

Tohle jestli všechno zkontrolujete, tak před váma smekám :thumbsup:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu, děkuju moc!

#14 Příspěvek od motji »

:D

Jestli jste ten soubor smazal do koše, tak ho obnovte. Jinak budete muset proggram přeinstalovat.

:arrow: tento soubor znáte?
C:\Users\Honza\Desktop\PPPP.pptx
C:\ProgramData\sandra.mda



:arrow: Připojte flešku

:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3950918805-3815427779-4285382183-1000..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O8:64bit: - Extra context menu item: Přidat do Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll ()
O13 - gopher Prefix: missing
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll ()
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll ()
@Alternate Data Stream - 1239 bytes -> C:\ProgramData\Microsoft:MlOw0V7reNaRzHWg2swyxJVZ
@Alternate Data Stream - 1227 bytes -> C:\Program Files (x86)\Common Files\System:Zun6fX2GqQKGgoJCZVDsAvr1t1vF
@Alternate Data Stream - 1066 bytes -> C:\ProgramData\Microsoft:jwMIX95OZ5msAkrhTjRMtOQ

:files
G:\ej10fkdo.bat
C:\ej10fkdo.bat
D:\ej10fkdo.bat
C:\autorun.inf
D:\autorun.inf
G:\autorun.inf
C:\$Recycle.Bin
D:\$Recycle.Bin
G:\$Recycle.Bin
C:\UsbFix

:reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{21f4a992-bd52-11de-ad7c-0018f32faa1c}]

:COMMANDS
[Reboot]
-klikněte na tlačítko Run fix.
-Následně se pc restartuje.
- Log vložte zde :)


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


:arrow: vložte nový log ze Rsit :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

visis
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 24 dub 2007 12:21

Re: Prosím o kontrolu, děkuju moc!

#15 Příspěvek od visis »

Sandra.mda mi nic neříká. Mám to smazat?
pppp.ppt je jedna moje p rezentace. ta je v pořádku.

Začnu s vaším postupem...

Odpovědět