Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zdravim - prosim o preventivku..

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Zdravim - prosim o preventivku..

#1 Příspěvek od SIDILKO »

Po dlouhy dobe jsem zapnul noota a je to zasekany jak hovado.. dekuji..



tu je log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:38, on 13. 3. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\DeviceLock\DLService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\SIDILKO\Plocha\SIDILKO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-789336058-854245398-1016\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SPUSTIT')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3624AEC3-0D79-4900-A74B-CF3D1D6D8D9B}: NameServer = 10.1.111.254,213.169.176.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF7B0068-A644-4495-9AE6-AF5EC3960AA0}: NameServer = 10.1.111.254,213.168.176.3
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DeviceLock Service (Device Lock) - SmartLine Inc - C:\Program Files\DeviceLock\DLService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe

--
End of file - 5309 bytes
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#2 Příspěvek od Unlimited_Killer »

Dobré odpoledne. :welcome:

1) Random's System Information Tool
  • Stáhněte a uložte na Plochu RSIT.
  • Spusťte, nechte v rolovacím menu '1 month' a klikněte na 'Continue'.
  • Vyčkejte několik vteřin, než se vygeneruje log se jménem log.txt
  • Pokud nebude log vygenerován, naleznete jej v C:\rsit\log.txt
  • Obsah tohoto logu vložte do svého příspěvku.
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#3 Příspěvek od SIDILKO »

Dobre..

tady je..


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:05, on 13. 3. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\DeviceLock\DLService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\SIDILKO\Plocha\SIDILKO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-789336058-854245398-1016\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SPUSTIT')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3624AEC3-0D79-4900-A74B-CF3D1D6D8D9B}: NameServer = 10.1.111.254,213.169.176.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF7B0068-A644-4495-9AE6-AF5EC3960AA0}: NameServer = 10.1.111.254,213.168.176.3
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DeviceLock Service (Device Lock) - SmartLine Inc - C:\Program Files\DeviceLock\DLService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe

--
End of file - 5309 bytes
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#4 Příspěvek od Unlimited_Killer »

Vždyť je to opět jen HijackThis log - já chci RSIT log - vizte minulý příspěvek.
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#5 Příspěvek od SIDILKO »

stahnul jsem to z podpisu asi 4krat a je to porat hjt...
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#6 Příspěvek od Unlimited_Killer »

Otevře se Vám textový soubor log.txt?
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#7 Příspěvek od SIDILKO »

uz dobry.. mel jsem ho jeste nkde nakopirovany a poustel se hjt.. tady je..


Logfile of random's system information tool 1.06 (written by random/random)
Run by SIDILKO at 2010-03-13 15:18:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (9%) free of 20 GB
Total RAM: 191 MB (18% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:18:44, on 13. 3. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\DeviceLock\DLService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\SIDILKO\Plocha\DWNDLDS\RSIT.exe
C:\Program Files\trend micro\SIDILKO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3624AEC3-0D79-4900-A74B-CF3D1D6D8D9B}: NameServer = 10.1.111.254,213.169.176.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF7B0068-A644-4495-9AE6-AF5EC3960AA0}: NameServer = 10.1.111.254,213.168.176.3
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DeviceLock Service (Device Lock) - SmartLine Inc - C:\Program Files\DeviceLock\DLService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe

--
End of file - 5247 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2002-08-14 290816]
"CARPService"=C:\WINDOWS\system32\carpserv.exe [2003-04-15 4608]
"Display Settings"=C:\Program Files\HPQ\Notebook Utilities\hptasks.exe [2002-08-15 45056]
"QT4HPOT"=C:\Program Files\HPQ\One-Touch\OneTouch.EXE [2003-01-31 106496]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-04-19 110592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-04-19 610304]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2002-08-15 28672]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2003-02-26 180316]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2007-09-27 917504]
"COMODO Firewall Pro"=C:\Program Files\Comodo\Firewall\CPF.exe [2008-02-17 1115728]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"QIP2005"=C:\Program Files\QIP\qip.exe []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Device Lock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriver.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriver0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriverHlp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Device Lock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriver.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriver0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriverHlp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Call of Duty\CoDMP.exe"="C:\Program Files\Call of Duty\CoDMP.exe:*:Disabled:CoDMP"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Disabled:Half-Life Launcher"
"C:\Documents and Settings\All Users\Dokumenty\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe"="C:\Documents and Settings\All Users\Dokumenty\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe:*:Disabled:quake3"
"\\Notebook01\SdílenéDokum\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe"="\\Notebook01\SdílenéDokum\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe:*:Disabled:quake3"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Sierra\Counter-Strike\cstrike.exe"="C:\Sierra\Counter-Strike\cstrike.exe:*:Disabled:CounterStrike Launcher"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======File associations======

.scr - open - "%1" /S "%3"

======List of files/folders created in the last 1 months======

2010-03-13 15:18:10 ----D---- C:\Program Files\trend micro
2010-03-13 12:08:04 ----D---- C:\rsit
2010-03-12 16:55:53 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Nero
2010-03-12 16:53:14 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2010-03-12 16:40:18 ----D---- C:\Program Files\Nero
2010-03-12 16:40:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-03-12 16:40:15 ----D---- C:\Program Files\Common Files\Nero
2010-03-12 16:29:27 ----D---- C:\WINDOWS\RegisteredPackages
2010-03-12 16:24:35 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-03-12 16:24:27 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-03-09 10:46:02 ----D---- C:\WINDOWS\system32\PreInstall
2010-03-09 10:45:57 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-03-09 10:45:56 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-09 08:57:05 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-09 08:48:11 ----D---- C:\WINDOWS\Prefetch
2010-03-09 01:54:02 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-03-09 01:54:02 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-03-09 01:53:12 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-03-09 01:53:11 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-03-09 01:53:00 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-03-09 01:52:59 ----N---- C:\WINDOWS\system32\azroles.dll
2010-03-09 01:52:58 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-03-09 01:52:57 ----N---- C:\WINDOWS\system32\credssp.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-03-09 01:52:48 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-03-09 01:52:47 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-03-09 01:52:45 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-03-09 01:52:42 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-03-09 01:52:42 ----N---- C:\WINDOWS\system32\mssha.dll
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napstat.exe
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-03-09 01:52:39 ----N---- C:\WINDOWS\system32\onex.dll
2010-03-09 01:52:37 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qutil.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qagent.dll
2010-03-09 01:52:34 ----N---- C:\WINDOWS\system32\setupn.exe
2010-03-09 01:52:30 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\verclsid.exe
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-03-09 01:52:28 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-03-09 01:52:20 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-03-09 01:52:18 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-09 01:52:13 ----D---- C:\WINDOWS\l2schemas
2010-03-09 01:52:11 ----D---- C:\WINDOWS\system32\cs
2010-03-09 01:52:10 ----D---- C:\WINDOWS\system32\bits
2010-03-09 01:37:16 ----N---- C:\WINDOWS\system32\mplay32.exe
2010-03-09 01:34:22 ----D---- C:\WINDOWS\network diagnostic
2010-03-09 01:28:59 ----A---- C:\WINDOWS\005753_.tmp
2010-03-08 23:47:22 ----D---- C:\WINDOWS\ServicePackFiles
2010-03-08 23:32:25 ----A---- C:\WINDOWS\002751_.tmp
2010-03-08 23:32:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-08 23:23:39 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-03-08 22:48:27 ----HDC---- C:\WINDOWS\$MSI30UninstallMSI30-KB884016$
2010-02-16 08:49:52 ----D---- C:\WINDOWS\system32\NtmsData

======List of files/folders modified in the last 1 months======

2010-03-13 15:18:10 ----RD---- C:\Program Files
2010-03-13 15:07:50 ----D---- C:\WINDOWS\Temp
2010-03-13 15:04:57 ----D---- C:\WINDOWS
2010-03-13 15:02:12 ----D---- C:\Program Files\DeviceLock
2010-03-13 15:02:03 ----A---- C:\WINDOWS\system32\DLGPC.DLL
2010-03-13 15:02:02 ----D---- C:\WINDOWS\system32\drivers
2010-03-13 15:01:36 ----D---- C:\WINDOWS\Minidump
2010-03-12 17:04:24 ----SHD---- C:\WINDOWS\Installer
2010-03-12 16:53:14 ----D---- C:\WINDOWS\system32
2010-03-12 16:40:15 ----D---- C:\Program Files\Common Files
2010-03-12 16:39:30 ----D---- C:\WINDOWS\Cursors
2010-03-12 16:33:45 ----HD---- C:\WINDOWS\inf
2010-03-12 16:33:45 ----D---- C:\Program Files\Windows Media Player
2010-03-12 16:33:34 ----D---- C:\WINDOWS\Debug
2010-03-12 16:32:35 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-12 16:24:42 ----D---- C:\WINDOWS\system32\DirectX
2010-03-12 16:24:29 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-12 09:16:02 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-12 07:15:51 ----D---- C:\WINDOWS\WinSxS
2010-03-12 07:15:27 ----D---- C:\Program Files\Ahead
2010-03-12 01:00:18 ----SD---- C:\Documents and Settings\SIDILKO\Data aplikací\Microsoft
2010-03-11 20:34:07 ----AC---- C:\WINDOWS\ODBC.INI
2010-03-11 16:03:38 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Miranda
2010-03-11 16:02:58 ----D---- C:\Program Files\Miranda IM
2010-03-09 14:40:27 ----AC---- C:\WINDOWS\OEWABLog.txt
2010-03-09 09:00:11 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-09 08:59:44 ----D---- C:\WINDOWS\Help
2010-03-09 08:59:38 ----HD---- C:\Program Files\WindowsUpdate
2010-03-09 08:53:44 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-09 08:51:31 ----AC---- C:\WINDOWS\setuplog.txt
2010-03-09 08:47:17 ----D---- C:\WINDOWS\system32\Setup
2010-03-09 08:47:17 ----D---- C:\Program Files\Messenger
2010-03-09 08:47:16 ----D---- C:\WINDOWS\AppPatch
2010-03-09 08:47:15 ----D---- C:\WINDOWS\system32\wbem
2010-03-09 08:47:11 ----RSD---- C:\WINDOWS\Fonts
2010-03-09 02:13:25 ----D---- C:\WINDOWS\security
2010-03-09 02:07:36 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-09 02:07:11 ----A---- C:\WINDOWS\imsins.BAK
2010-03-09 01:53:17 ----D---- C:\WINDOWS\EHome
2010-03-09 01:53:10 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-09 01:53:08 ----D---- C:\WINDOWS\ime
2010-03-09 01:52:18 ----D---- C:\WINDOWS\system32\usmt
2010-03-09 01:52:14 ----D---- C:\Program Files\Internet Explorer
2010-03-09 01:52:09 ----D---- C:\WINDOWS\peernet
2010-03-09 01:52:09 ----D---- C:\Program Files\Movie Maker
2010-03-09 01:41:05 ----D---- C:\WINDOWS\system32\Restore
2010-03-09 01:41:03 ----D---- C:\WINDOWS\system32\npp
2010-03-09 01:40:53 ----D---- C:\WINDOWS\msagent
2010-03-09 01:40:41 ----D---- C:\WINDOWS\srchasst
2010-03-09 01:40:37 ----D---- C:\Program Files\NetMeeting
2010-03-09 01:40:32 ----D---- C:\WINDOWS\system32\Com
2010-03-09 01:40:23 ----D---- C:\Program Files\Outlook Express
2010-03-09 01:40:14 ----D---- C:\Program Files\Common Files\System
2010-03-09 01:39:13 ----D---- C:\WINDOWS\system32\oobe
2010-03-09 01:39:08 ----D---- C:\WINDOWS\system
2010-03-08 23:59:54 ----RASH---- C:\boot.ini
2010-03-08 23:38:20 ----RD---- C:\WINDOWS\Web
2010-03-08 23:37:27 ----RASH---- C:\NTDETECT.COM
2010-03-08 22:30:22 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Mozilla
2010-03-08 22:29:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-08 22:26:57 ----SD---- C:\WINDOWS\Tasks
2010-02-15 22:03:50 ----D---- C:\Program Files\QIP
2010-02-15 22:02:04 ----D---- C:\Program Files\Valve

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2006-08-25 2432]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2006-08-25 2560]
R1 CmdMon;Comodo Application Engine; C:\WINDOWS\System32\DRIVERS\cmdmon.sys [2008-02-17 75520]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SpyEmrg;Spy Emergency Driver; C:\WINDOWS\System32\Drivers\spyemrg.sys [2006-05-08 6304]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [2008-04-14 225664]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AMON;AMON; \??\C:\WINDOWS\System32\drivers\amon.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2003-04-15 9855]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R2 StreamDispatcher;StreamDispatcher; C:\WINDOWS\System32\DRIVERS\strmdisp.sys [2003-04-15 34224]
R3 ALiIRDA;ALi Infrared Device Driver; C:\WINDOWS\System32\DRIVERS\aliirda.sys [2001-12-17 26112]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2002-08-16 471168]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO; C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 291328]
R3 CALIHALA;CALIHALA; C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 244608]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver; C:\WINDOWS\System32\DRIVERS\DP83815.SYS [2002-08-29 16512]
R3 HPCI;HP Configuration Interface; C:\WINDOWS\System32\DRIVERS\hpci.sys [2002-07-17 14504]
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2003-04-15 1171616]
R3 HSFHWALI;HSFHWALI; C:\WINDOWS\System32\DRIVERS\HSFHWALI.sys [2003-04-15 153380]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 MxlW2k;MxlW2k; C:\WINDOWS\system32\drivers\MxlW2k.sys [2004-10-21 28164]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2003-04-15 594960]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys []
S3 aliadwdm;Ovladač WDM urychlovače zpracování zvuku ALi; C:\WINDOWS\system32\drivers\ac97ali.sys [2004-08-03 231552]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Bridge;Most MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\SIDILKO\LOCALS~1\Temp\catchme.sys []
S3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.SYS [2002-10-16 14543]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-12-02 223128]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\FA312nd5.sys [2001-08-17 16074]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\System32\DRIVERS\MSIRCOMM.sys [2008-04-14 22016]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\System32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\System32\DRIVERS\SynTP.sys [2003-04-19 270256]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VIAIRDA;Ovladač infračerveného zařízení VIA; C:\WINDOWS\System32\DRIVERS\viairda.sys [2001-08-17 24576]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 CmdAgent;Comodo Application Agent; C:\Program Files\Comodo\Firewall\cmdagent.exe [2008-02-17 361040]
R2 Device Lock;DeviceLock Service; C:\Program Files\DeviceLock\DLService.exe [2005-09-16 802816]
R2 HPConfig;HP Configuration Interface Service; C:\WINDOWS\system32\HPConfig.exe [2002-08-15 151552]
R2 HPWirelessMgr;HPWirelessMgr; C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe [2003-01-14 53248]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2007-09-27 495616]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\System32\PnkBstrA.exe [2009-06-29 66872]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#8 Příspěvek od Unlimited_Killer »

Super. :thumbsup:

1) Znáte následující IP adresy? 2) Fixnutí v HJT
  • Spusťte přejmenované HijackThis - C:\Program Files\Trend Micro\HijackThis\jmeno_uzivatele.exe
  • Následně klikněte na 'Do a system scan only'.
  • U níže uvedených položek udělejte fajfku do čtverečku a poté klikněte na 'Fix Checked'.

    Kód: Vybrat vše

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
    O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
  • Pokud by tam nějaká položka nebyla, vynechte ji.
3) Malwarebytes' Anti-Malware
  • Stáhněte MbAM a postupujte podle popisu.
  • Zatím nic nemažte, MbAM má občas falešné detekce.
  • Poté mi sem vložte log ve formě textu.
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#9 Příspěvek od SIDILKO »

to by mela bejt ip a maska podsite..
jdu na ten mbam..
SIDILKO

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#10 Příspěvek od SIDILKO »

tak je to tady. hezky.. asi odstranit co..:)


Malwarebytes' Anti-Malware 1.44
Verze databáze: 3862
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

13. 3. 2010 16:58:35
mbam-log-2010-03-13 (16-58-18).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 138316
Uplynulý čas: 31 minute(s), 3 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 7
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
HKEY_CLASSES_ROOT\alewinsecure.winsecure (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\alewinsecure.winsecure.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7be6b643-6201-4cf7-b8b1-d79ffae57cba} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{a93a1ba9-9ee8-469f-a9fe-fd1c26700bda} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a1789eb6-b263-4bd6-8830-d3daaf78949a} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{58696980-c6b3-4ad2-ab53-718f1c3c57ca} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\AleWinSecure.exe (Trojan.Agent) -> No action taken.

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#11 Příspěvek od Unlimited_Killer »

Ano, poté nový RSIT log.
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#12 Příspěvek od SIDILKO »

tady...


Logfile of random's system information tool 1.06 (written by random/random)
Run by SIDILKO at 2010-03-14 11:38:36
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (8%) free of 20 GB
Total RAM: 191 MB (15% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:04, on 14. 3. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\DeviceLock\DLService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\SIDILKO\Plocha\RSIT.exe
C:\Program Files\trend micro\SIDILKO.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3624AEC3-0D79-4900-A74B-CF3D1D6D8D9B}: NameServer = 10.1.111.254,213.169.176.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF7B0068-A644-4495-9AE6-AF5EC3960AA0}: NameServer = 10.1.111.254,213.168.176.3
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DeviceLock Service (Device Lock) - SmartLine Inc - C:\Program Files\DeviceLock\DLService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe

--
End of file - 4944 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2002-08-14 290816]
"CARPService"=C:\WINDOWS\system32\carpserv.exe [2003-04-15 4608]
"Display Settings"=C:\Program Files\HPQ\Notebook Utilities\hptasks.exe [2002-08-15 45056]
"QT4HPOT"=C:\Program Files\HPQ\One-Touch\OneTouch.EXE [2003-01-31 106496]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-04-19 110592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-04-19 610304]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2002-08-15 28672]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2003-02-26 180316]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2007-09-27 917504]
"COMODO Firewall Pro"=C:\Program Files\Comodo\Firewall\CPF.exe [2008-02-17 1115728]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Device Lock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriver.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriver0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceLockDriverHlp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Device Lock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriver.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriver0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceLockDriverHlp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Call of Duty\CoDMP.exe"="C:\Program Files\Call of Duty\CoDMP.exe:*:Disabled:CoDMP"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Disabled:Half-Life Launcher"
"C:\Documents and Settings\All Users\Dokumenty\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe"="C:\Documents and Settings\All Users\Dokumenty\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe:*:Disabled:quake3"
"\\Notebook01\SdílenéDokum\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe"="\\Notebook01\SdílenéDokum\SIDILKO (Noťas)\Quake 3 Arena\quake3.exe:*:Disabled:quake3"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Sierra\Counter-Strike\cstrike.exe"="C:\Sierra\Counter-Strike\cstrike.exe:*:Disabled:CounterStrike Launcher"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======File associations======

.scr - open - "%1" /S "%3"

======List of files/folders created in the last 1 months======

2010-03-13 16:21:57 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Malwarebytes
2010-03-13 16:21:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-13 16:21:15 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-13 15:18:10 ----D---- C:\Program Files\trend micro
2010-03-13 12:08:04 ----D---- C:\rsit
2010-03-12 16:55:53 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Nero
2010-03-12 16:53:14 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2010-03-12 16:40:18 ----D---- C:\Program Files\Nero
2010-03-12 16:40:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-03-12 16:40:15 ----D---- C:\Program Files\Common Files\Nero
2010-03-12 16:29:27 ----D---- C:\WINDOWS\RegisteredPackages
2010-03-12 16:24:35 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-03-12 16:24:27 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-03-09 10:46:02 ----D---- C:\WINDOWS\system32\PreInstall
2010-03-09 10:45:57 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-03-09 10:45:56 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-09 08:57:05 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-09 08:48:11 ----D---- C:\WINDOWS\Prefetch
2010-03-09 01:54:02 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-03-09 01:54:02 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-03-09 01:53:12 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-03-09 01:53:11 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-03-09 01:53:00 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-03-09 01:52:59 ----N---- C:\WINDOWS\system32\azroles.dll
2010-03-09 01:52:58 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-03-09 01:52:57 ----N---- C:\WINDOWS\system32\credssp.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-03-09 01:52:56 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-03-09 01:52:55 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-03-09 01:52:54 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-03-09 01:52:48 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-03-09 01:52:47 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-03-09 01:52:46 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-03-09 01:52:45 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-03-09 01:52:43 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-03-09 01:52:42 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-03-09 01:52:42 ----N---- C:\WINDOWS\system32\mssha.dll
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napstat.exe
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-03-09 01:52:41 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-03-09 01:52:39 ----N---- C:\WINDOWS\system32\onex.dll
2010-03-09 01:52:37 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qutil.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-03-09 01:52:36 ----N---- C:\WINDOWS\system32\qagent.dll
2010-03-09 01:52:34 ----N---- C:\WINDOWS\system32\setupn.exe
2010-03-09 01:52:30 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\verclsid.exe
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-03-09 01:52:29 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-03-09 01:52:28 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-03-09 01:52:27 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-03-09 01:52:20 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-03-09 01:52:18 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-09 01:52:13 ----D---- C:\WINDOWS\l2schemas
2010-03-09 01:52:11 ----D---- C:\WINDOWS\system32\cs
2010-03-09 01:52:10 ----D---- C:\WINDOWS\system32\bits
2010-03-09 01:37:16 ----N---- C:\WINDOWS\system32\mplay32.exe
2010-03-09 01:34:22 ----D---- C:\WINDOWS\network diagnostic
2010-03-09 01:28:59 ----A---- C:\WINDOWS\005753_.tmp
2010-03-08 23:47:22 ----D---- C:\WINDOWS\ServicePackFiles
2010-03-08 23:32:25 ----A---- C:\WINDOWS\002751_.tmp
2010-03-08 23:32:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-08 23:23:39 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-03-08 22:48:27 ----HDC---- C:\WINDOWS\$MSI30UninstallMSI30-KB884016$
2010-02-16 08:49:52 ----D---- C:\WINDOWS\system32\NtmsData

======List of files/folders modified in the last 1 months======

2010-03-14 11:22:36 ----D---- C:\WINDOWS\Temp
2010-03-14 11:20:00 ----D---- C:\Program Files\DeviceLock
2010-03-14 11:19:55 ----A---- C:\WINDOWS\system32\DLGPC.DLL
2010-03-14 11:19:54 ----D---- C:\WINDOWS\system32\drivers
2010-03-13 21:38:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-13 16:21:15 ----RD---- C:\Program Files
2010-03-13 16:04:04 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-13 15:04:57 ----D---- C:\WINDOWS
2010-03-13 15:01:36 ----D---- C:\WINDOWS\Minidump
2010-03-12 17:04:24 ----SHD---- C:\WINDOWS\Installer
2010-03-12 16:53:14 ----D---- C:\WINDOWS\system32
2010-03-12 16:40:15 ----D---- C:\Program Files\Common Files
2010-03-12 16:39:30 ----D---- C:\WINDOWS\Cursors
2010-03-12 16:33:45 ----HD---- C:\WINDOWS\inf
2010-03-12 16:33:45 ----D---- C:\Program Files\Windows Media Player
2010-03-12 16:33:34 ----D---- C:\WINDOWS\Debug
2010-03-12 16:32:35 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-12 16:24:42 ----D---- C:\WINDOWS\system32\DirectX
2010-03-12 07:15:51 ----D---- C:\WINDOWS\WinSxS
2010-03-12 07:15:27 ----D---- C:\Program Files\Ahead
2010-03-12 01:00:18 ----SD---- C:\Documents and Settings\SIDILKO\Data aplikací\Microsoft
2010-03-11 20:34:07 ----AC---- C:\WINDOWS\ODBC.INI
2010-03-11 16:03:38 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Miranda
2010-03-11 16:02:58 ----D---- C:\Program Files\Miranda IM
2010-03-09 14:40:27 ----AC---- C:\WINDOWS\OEWABLog.txt
2010-03-09 09:00:11 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-09 08:59:44 ----D---- C:\WINDOWS\Help
2010-03-09 08:59:38 ----HD---- C:\Program Files\WindowsUpdate
2010-03-09 08:53:44 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-09 08:51:31 ----AC---- C:\WINDOWS\setuplog.txt
2010-03-09 08:47:17 ----D---- C:\WINDOWS\system32\Setup
2010-03-09 08:47:17 ----D---- C:\Program Files\Messenger
2010-03-09 08:47:16 ----D---- C:\WINDOWS\AppPatch
2010-03-09 08:47:15 ----D---- C:\WINDOWS\system32\wbem
2010-03-09 08:47:11 ----RSD---- C:\WINDOWS\Fonts
2010-03-09 02:13:25 ----D---- C:\WINDOWS\security
2010-03-09 02:07:36 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-09 02:07:11 ----A---- C:\WINDOWS\imsins.BAK
2010-03-09 01:53:17 ----D---- C:\WINDOWS\EHome
2010-03-09 01:53:10 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-09 01:53:08 ----D---- C:\WINDOWS\ime
2010-03-09 01:52:18 ----D---- C:\WINDOWS\system32\usmt
2010-03-09 01:52:14 ----D---- C:\Program Files\Internet Explorer
2010-03-09 01:52:09 ----D---- C:\WINDOWS\peernet
2010-03-09 01:52:09 ----D---- C:\Program Files\Movie Maker
2010-03-09 01:41:05 ----D---- C:\WINDOWS\system32\Restore
2010-03-09 01:41:03 ----D---- C:\WINDOWS\system32\npp
2010-03-09 01:40:53 ----D---- C:\WINDOWS\msagent
2010-03-09 01:40:41 ----D---- C:\WINDOWS\srchasst
2010-03-09 01:40:37 ----D---- C:\Program Files\NetMeeting
2010-03-09 01:40:32 ----D---- C:\WINDOWS\system32\Com
2010-03-09 01:40:23 ----D---- C:\Program Files\Outlook Express
2010-03-09 01:40:14 ----D---- C:\Program Files\Common Files\System
2010-03-09 01:39:13 ----D---- C:\WINDOWS\system32\oobe
2010-03-09 01:39:08 ----D---- C:\WINDOWS\system
2010-03-08 23:59:54 ----RASH---- C:\boot.ini
2010-03-08 23:38:20 ----RD---- C:\WINDOWS\Web
2010-03-08 23:37:27 ----RASH---- C:\NTDETECT.COM
2010-03-08 22:30:22 ----D---- C:\Documents and Settings\SIDILKO\Data aplikací\Mozilla
2010-03-08 22:29:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-08 22:26:57 ----SD---- C:\WINDOWS\Tasks
2010-02-15 22:03:50 ----D---- C:\Program Files\QIP
2010-02-15 22:02:04 ----D---- C:\Program Files\Valve

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2006-08-25 2432]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2006-08-25 2560]
R1 CmdMon;Comodo Application Engine; C:\WINDOWS\System32\DRIVERS\cmdmon.sys [2008-02-17 75520]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SpyEmrg;Spy Emergency Driver; C:\WINDOWS\System32\Drivers\spyemrg.sys [2006-05-08 6304]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [2008-04-14 225664]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AMON;AMON; \??\C:\WINDOWS\System32\drivers\amon.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2003-04-15 9855]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R2 StreamDispatcher;StreamDispatcher; C:\WINDOWS\System32\DRIVERS\strmdisp.sys [2003-04-15 34224]
R3 ALiIRDA;ALi Infrared Device Driver; C:\WINDOWS\System32\DRIVERS\aliirda.sys [2001-12-17 26112]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2002-08-16 471168]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO; C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 291328]
R3 CALIHALA;CALIHALA; C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 244608]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver; C:\WINDOWS\System32\DRIVERS\DP83815.SYS [2002-08-29 16512]
R3 HPCI;HP Configuration Interface; C:\WINDOWS\System32\DRIVERS\hpci.sys [2002-07-17 14504]
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2003-04-15 1171616]
R3 HSFHWALI;HSFHWALI; C:\WINDOWS\System32\DRIVERS\HSFHWALI.sys [2003-04-15 153380]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 MxlW2k;MxlW2k; C:\WINDOWS\system32\drivers\MxlW2k.sys [2004-10-21 28164]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2003-04-15 594960]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys []
S3 aliadwdm;Ovladač WDM urychlovače zpracování zvuku ALi; C:\WINDOWS\system32\drivers\ac97ali.sys [2004-08-03 231552]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Bridge;Most MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\SIDILKO\LOCALS~1\Temp\catchme.sys []
S3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.SYS [2002-10-16 14543]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-12-02 223128]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\FA312nd5.sys [2001-08-17 16074]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\System32\DRIVERS\MSIRCOMM.sys [2008-04-14 22016]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\System32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\System32\DRIVERS\SynTP.sys [2003-04-19 270256]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VIAIRDA;Ovladač infračerveného zařízení VIA; C:\WINDOWS\System32\DRIVERS\viairda.sys [2001-08-17 24576]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 CmdAgent;Comodo Application Agent; C:\Program Files\Comodo\Firewall\cmdagent.exe [2008-02-17 361040]
R2 Device Lock;DeviceLock Service; C:\Program Files\DeviceLock\DLService.exe [2005-09-16 802816]
R2 HPConfig;HP Configuration Interface Service; C:\WINDOWS\system32\HPConfig.exe [2002-08-15 151552]
R2 HPWirelessMgr;HPWirelessMgr; C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe [2003-01-14 53248]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2007-09-27 495616]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\System32\PnkBstrA.exe [2009-06-29 66872]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#13 Příspěvek od Unlimited_Killer »

Pokračujeme. ↓

1) OTMoveit3
  • Stáhněte OTM3 na Plochu.
  • Spusťte ho dvojklikem na OTM.exe, pokud to nepůjde, zkuste to s adminskými právy.
  • Do levého okna 'Paste Instructions for Items to be Moved' vkopírujte následující skript:

    Kód: Vybrat vše

    :files
    C:\WINDOWS\system32\*.tmp.dll /s
    C:\WINDOWS\system32\SET*.tmp /s
    C:\WINDOWS\*.tmp /s
    
    :commands
    [emptytemp]
    [reboot]
  • Poté klikněte na červené tlačítko 'MoveIt!'.
  • V zeleném okně vpravo by se měl zobrazit log, ten vkopírujete sem do fóra.
  • Pokud se zobrazí hláška k restartování, klikněte na Yes.
  • Po restartu se log otevře sám, nebo ho najdete v C:\_OTM\MovedFiles
2) OTCleaner
  • Stáhněte OTC a dvojklikem ho spusťte.
  • Vyskočí okénko, kde kliknete na 'CleanUp!'.
  • Potvrdíte kliknutím na 'Yes'.
  • Poté se ještě zeptá, zda chcete restartovat PC - to proveďte opět kliknutím na 'Yes'.
3) Update Internet Exploreru
  • Máte nainstalovanou zastaralou verzi Internet Exploreru (konkrétně verzi 6).
  • Proto doporučuji updatovat (i když IE nepoužíváte) na verzi 7, nebo rovnou na nejnovější 'osmičku'.
4) CCleaner
  • Stáhněte si program jménem CCleaner.
  • Normálně nainstalujte, jen dávejte pozor a odškrtněte položku 'Instalovat Yahoo! Toolbar'.
  • Spusťte ho.
    • Záložka Čistič → nechte zatrženo vše, jak je, a klikněte na 'Spustit CCleaner'.
    • Záložka Registry → klikněte na 'Hledej problémy'. Vyhledá problémy v registru, až dokončí analyzování, klikněte na 'Opravit vybrané problémy'. Nabídne Vám vytvoření zálohy - pro jistotu ji vytvořte a uložte například na Plochu.
  • CCleaner doporučuji používat pravidelně, celkem rapidně dokáže zrychlit PC.
5) Defragmentace
  • Defragmentujte disk.
  • Lze to udělat několika způsoby ↓
    • Přes defragmentaci integrovanou ve Windows [Start → Spustit → dfrg.msc → Enter]. Toto není příliš účinný způsob.
    • Přes jednoduchý a přehledný program jménem Defraggler.
    • Přes geniální program, který se nemusí instalovat a je hodně jednoduchý - JKDefrag.
6) Nový RSIT log
inactive

SIDILKO
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 08 led 2008 18:34
Bydliště: HOME

Re: Zdravim - prosim o preventivku..

#14 Příspěvek od SIDILKO »

tady je log z otm..

All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\002272_.tmp moved successfully.
C:\WINDOWS\002751_.tmp moved successfully.
C:\WINDOWS\005753_.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET30.tmp moved successfully.
C:\WINDOWS\SET31.tmp moved successfully.
C:\WINDOWS\SET32.tmp moved successfully.
C:\WINDOWS\SET33.tmp moved successfully.
C:\WINDOWS\SET3C.tmp moved successfully.
C:\WINDOWS\SET3D.tmp moved successfully.
C:\WINDOWS\SET3E.tmp moved successfully.
C:\WINDOWS\SET42.tmp moved successfully.
C:\WINDOWS\SETA.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1B.tmp folder moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\07c90dcbdedfe16c2b58e68ce910936a\download\BIT8C.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\0bfe47e58d65a90f0263f041ec115a72\download\BIT222.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\0ef983140dac4bebf959fd55dec28b84\BIT6D.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\21d6331d541a8a6e8be11d421ad5373e\download\BIT12.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\31cb49c8ca47771270898ce01c3e98bf\BIT4F.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\36a403eae405ef97aa0ef64c1d6bb90c\BIT81.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\380783bf62debfc3ac1414fa4e21fa30\BIT5A.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\39ebcef938f5a8679059ce0c4c4e030d\BIT46.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\41b2219405346d6421a1b21083eb6dd7\BIT56.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\420b0b62a2c5f5605da3d58c766f7ad0\BIT77.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\48b4f66aba2f3ddfff3e2d0cb40a06d9\download\BITF.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\4af921c6adbab19cab5b5adbcdec9e10\BIT80.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\4dc29e9a3768c22e70939411aaaf7904\BIT50.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\5b1bf3c709a0479f95a0d490dc626aff\BIT69.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\6eb64538d1eb8e0e92baa96fc62ba854\BIT4C.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\7654a5f78a672bd2ba8b0cec462f5907\download\BIT83.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\7bdb1fc2c71999833bcae67284ba2362\BIT7A.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\8058ebceb452c83425841a510aaccdfb\download\BIT10.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\851a69e5c9fef905f7724b836208b4e4\download\BIT11.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\88f026cdf6e47b207e50d34c72431789\BIT63.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\8e8fb6c243dc806cf8d12f60695a91d8\download\BITE.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\8fa34d49e29b308c20dc3c325ba2509b\BIT5C.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\9434f38734605ee74bf380b05e9ff9a2\BIT74.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\98df63c725396df2d3ec6f45abce37f1\download\BIT93.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\aabfb5828fff50277749b3bff3acd78f\BIT5E.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\abd17da5c7c9fd35f1795bb4189a1a1a\download\BIT84.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\ac98a2da0a03b6c54e099895b005800a\BIT7B.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\b063f356f9664bd7343d099ddfdac7fc\BIT67.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\b3ba0f7542150a0ff634f02bb11873ed\BIT71.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\b66048432d7341c70ef08a575b3c4ee7\BIT52.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\be21e799c4114ec3b7e78e2497c5dec7\BIT72.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\cb0f38ed286b9b731b45e45765e59ca2\BIT7F.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\cc6f3a50cf5f6680a71124360c480027\BIT6F.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\db3e2bfd86d0eb6a08a6ca58444df0e3\BIT6B.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\f107d5b05da955cab1bd84bb76f4f00b\BIT59.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\f5e3940b5bd958bd79ba427de6730940\BIT48.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\Temp\NOD1AF.tmp moved successfully.
C:\WINDOWS\Temp\NOD1B0.tmp moved successfully.
C:\WINDOWS\Temp\NODEC.tmp moved successfully.
C:\WINDOWS\Temp\NODED.tmp moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: SIDILKO
->Temp folder emptied: 835943398 bytes
->Temporary Internet Files folder emptied: 858701695 bytes
->FireFox cache emptied: 49654208 bytes
->Flash cache emptied: 5963 bytes

User: Sklad

User: SPUSTIT
->Temp folder emptied: 12598917 bytes
->Temporary Internet Files folder emptied: 43947182 bytes
->FireFox cache emptied: 48854766 bytes
->Flash cache emptied: 1549 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11886 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1380716 bytes

Total Files Cleaned = 1 765,00 mb


OTM by OldTimer - Version 3.1.10.0 log created on 03152010_005719

Files moved on Reboot...
C:\Documents and Settings\SIDILKO\Local Settings\Temp\~DFA8EE.tmp moved successfully.

Registry entries deleted on Reboot...
SIDILKO

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Zdravim - prosim o preventivku..

#15 Příspěvek od Unlimited_Killer »

Po zbylých krocích budu chtít vidět nový RSIT log. :James008:
inactive

Odpovědět