
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Při sputění windowsu, seklá lišta
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
mbr log
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
otl
OTL logfile created on: 14.4.2010 20:31:57 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 578,00 Mb Available Physical Memory | 57,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,27 Gb Free Space | 35,25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 20:29:16 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 20:29:16 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 20:13:24 | 000,882,672 | ---- | C] (Duplex Secure Ltd.) -- C:\Documents and Settings\David\Plocha\SPTDinst-v169-x86.exe
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:04:40 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.04.14 12:04:40 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.04.14 12:04:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.04.14 12:04:39 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 12:00:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.14 07:35:03 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 20:16:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:16:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 20:16:04 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 20:14:25 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\David\Plocha\mbr.exe
[2010.04.14 20:13:34 | 000,882,672 | ---- | M] (Duplex Secure Ltd.) -- C:\Documents and Settings\David\Plocha\SPTDinst-v169-x86.exe
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
========== Files Created - No Company Name ==========
[2010.04.14 20:28:41 | 000,000,311 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,311 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 20:14:24 | 000,077,312 | ---- | C] () -- C:\Documents and Settings\David\Plocha\mbr.exe
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 12:04:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.04.14 12:04:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.04.14 12:04:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:14:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Purity Check ==========
< End of report >
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
otl
OTL logfile created on: 14.4.2010 20:31:57 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 578,00 Mb Available Physical Memory | 57,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,27 Gb Free Space | 35,25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 20:29:16 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 20:29:16 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 20:13:24 | 000,882,672 | ---- | C] (Duplex Secure Ltd.) -- C:\Documents and Settings\David\Plocha\SPTDinst-v169-x86.exe
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:04:40 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.04.14 12:04:40 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.04.14 12:04:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.04.14 12:04:39 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 12:00:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.14 07:35:03 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 20:16:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:16:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 20:16:04 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 20:14:25 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\David\Plocha\mbr.exe
[2010.04.14 20:13:34 | 000,882,672 | ---- | M] (Duplex Secure Ltd.) -- C:\Documents and Settings\David\Plocha\SPTDinst-v169-x86.exe
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
========== Files Created - No Company Name ==========
[2010.04.14 20:28:41 | 000,000,311 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,311 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 20:14:24 | 000,077,312 | ---- | C] () -- C:\Documents and Settings\David\Plocha\mbr.exe
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 12:04:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.04.14 12:04:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.04.14 12:04:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:14:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Purity Check ==========
< End of report >
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Při sputění windowsu, seklá lišta
hm,log si nespravila tak ako som napisal
MBR.exe
1;Klik start-klik-spustit a vloz prikaz co som tam napisal ,,log txt vloz sem
2:OTL=-do okna CUSTOMSCAN/FIXES-trebalo vlozit zeleny text a potom kliknut na RunScan.takze este raz to zopakuj,ok
MBR.exe
1;Klik start-klik-spustit a vloz prikaz co som tam napisal ,,log txt vloz sem
2:OTL=-do okna CUSTOMSCAN/FIXES-trebalo vlozit zeleny text a potom kliknut na RunScan.takze este raz to zopakuj,ok
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při sputění windowsu, seklá lišta
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync04.sys atapi.sys viaide.sys
kernel: MBR read successfully
user & kernel MBR OK
OTL logfile created on: 14.4.2010 21:29:19 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 559,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,30 Gb Free Space | 35,30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007.12.27 15:54:18 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 21:25:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 21:25:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 21:25:06 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 21:25:06 | 000,160,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.14 21:17:38 | 000,053,805 | ---- | M] () -- C:\Documents and Settings\David\Plocha\OTL.shtml
[2010.04.14 20:57:19 | 000,028,389 | ---- | M] () -- C:\Documents and Settings\David\Plocha\dv62120ec_mx.jpg
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.04.01 19:39:34 | 000,822,571 | ---- | M] () -- C:\Documents and Settings\David\Plocha\otlv4.h
========== Files Created - No Company Name ==========
[2010.04.14 21:17:37 | 000,053,805 | ---- | C] () -- C:\Documents and Settings\David\Plocha\OTL.shtml
[2010.04.14 21:16:56 | 000,822,571 | ---- | C] () -- C:\Documents and Settings\David\Plocha\otlv4.h
[2010.04.14 20:57:18 | 000,028,389 | ---- | C] () -- C:\Documents and Settings\David\Plocha\dv62120ec_mx.jpg
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
< End of report >
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync04.sys atapi.sys viaide.sys
kernel: MBR read successfully
user & kernel MBR OK
OTL logfile created on: 14.4.2010 21:29:19 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 559,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,30 Gb Free Space | 35,30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007.12.27 15:54:18 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 21:25:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 21:25:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 21:25:06 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 21:25:06 | 000,160,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.14 21:17:38 | 000,053,805 | ---- | M] () -- C:\Documents and Settings\David\Plocha\OTL.shtml
[2010.04.14 20:57:19 | 000,028,389 | ---- | M] () -- C:\Documents and Settings\David\Plocha\dv62120ec_mx.jpg
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.04.01 19:39:34 | 000,822,571 | ---- | M] () -- C:\Documents and Settings\David\Plocha\otlv4.h
========== Files Created - No Company Name ==========
[2010.04.14 21:17:37 | 000,053,805 | ---- | C] () -- C:\Documents and Settings\David\Plocha\OTL.shtml
[2010.04.14 21:16:56 | 000,822,571 | ---- | C] () -- C:\Documents and Settings\David\Plocha\otlv4.h
[2010.04.14 20:57:18 | 000,028,389 | ---- | C] () -- C:\Documents and Settings\David\Plocha\dv62120ec_mx.jpg
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
< End of report >
Re: Při sputění windowsu, seklá lišta
Dobrý večer
Kolega mě poprosil o záskok, vydržte chvilku, než kouknu na logy

Kolega mě poprosil o záskok, vydržte chvilku, než kouknu na logy

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při sputění windowsu, seklá lišta
Dobrý večer
chtěla sem jen říct že sem restartovala pc a už se lišta nesekla, ale snad se to nevrátí.
Mam pro to ještě něco udělat?

chtěla sem jen říct že sem restartovala pc a už se lišta nesekla, ale snad se to nevrátí.
Mam pro to ještě něco udělat?

Re: Při sputění windowsu, seklá lišta
Ještě něco málo dočistíme
Spustte OTL
-do bílého okna dole skopírujte tento skript:
-klikněte na tlačítko Run fix.
-Následně se pc restartuje.
- Log vložte zde


-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.1&q="
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Program Files\SweetIM
:COMMANDS
[Reboot]
-Následně se pc restartuje.
- Log vložte zde

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
OTL logfile created on: 14.4.2010 22:48:30 - Run 2
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 441,00 Mb Available Physical Memory | 43,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,25 Gb Free Space | 35,22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2009.11.16 17:36:19 | 000,172,792 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ6.5\ICQ.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 21:25:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 21:25:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 21:25:06 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 21:25:06 | 000,160,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
========== Files Created - No Company Name ==========
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
========== Purity Check ==========
========== Custom Scans ==========
< :OTL >
< PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) >
< MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll >
< MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll >
< IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found >
< IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) >
< FF - prefs.js..browser.search.defaultenginename: "ICQ Search" >
< FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q=" >
< O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found. >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () >
< O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) >
< O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found >
< >
< :files >
< C:\WINDOWS\system32\*.tmp.dll /s >
< C:\WINDOWS\system32\SET*.tmp /s >
< C:\WINDOWS\*.tmp /s >
[1 C:\WINDOWS\SoftwareDistribution\Download\872cdbc2aa908a12ab47c2f32baffa55\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\872cdbc2aa908a12ab47c2f32baffa55\*.tmp -> ]
[3 C:\WINDOWS\Temp\_avast5_\*.tmp files -> C:\WINDOWS\Temp\_avast5_\*.tmp -> ]
< C:\Program Files\SweetIM >
< >
< :COMMANDS >
< [Reboot] >
< End of report >
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\David\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 441,00 Mb Available Physical Memory | 43,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 26,25 Gb Free Space | 35,22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3,68 Gb Total Space | 2,58 Gb Free Space | 69,98% Space Free | Partition Type: FAT32
Computer Name: DAVID-56D158AFA
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.05 20:17:08 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.25 09:03:36 | 003,059,448 | ---- | M] (www.BitComet.com) -- C:\Program Files\BitComet\BitComet.exe
PRC - [2010.03.13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared Files\brs.exe
PRC - [2010.03.09 13:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.03.05 17:32:28 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.02.03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2009.11.16 17:36:19 | 000,172,792 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ6.5\ICQ.exe
PRC - [2008.12.02 11:02:08 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\UAService7.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.06.07 00:46:24 | 000,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
========== Modules (SafeList) ==========
MOD - [2010.04.14 21:28:37 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David\Dokumenty\Stažené soubory\OTL.exe
MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.03.09 13:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008.09.24 22:30:26 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UAService7.exe -- (UserAccess7) SecuROM User Access Service (V7)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.1
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 09:38:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.05 21:26:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2010.03.11 08:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Extensions
[2010.04.14 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions
[2010.04.12 21:12:13 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.04.05 20:02:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010.03.18 15:30:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010.04.12 23:22:15 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\vnt1alwq.default\searchplugins\icqplugin.xml
[2010.03.11 08:45:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.21 12:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll (BitComet)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.71.150.2 212.71.146.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.27 15:54:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 10:16:06 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.04.14 12:42:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\David\Recent
[2010.04.14 12:23:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.14 12:06:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.14 12:01:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 10:16:06 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2010.04.14 09:56:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 08:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\Malwarebytes
[2010.04.14 08:20:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.14 08:20:09 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.14 08:20:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.04.14 08:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.04.14 07:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.14 07:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.11 20:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\My eBooks
[2010.04.06 22:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010.04.06 22:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Dokumenty\EA Games
[2010.04.06 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2010.04.05 23:46:54 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6.5
[2010.04.05 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\Adobe
[2010.04.05 20:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.04.05 20:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2010.04.05 20:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.04.05 20:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Local Settings\Data aplikací\AOL
[2010.04.05 19:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.05 19:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2010.03.22 18:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\McAfee
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.03.11 07:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.08.05 02:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2007.12.27 16:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
========== Files - Modified Within 14 Days ==========
[2010.04.14 21:25:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 21:25:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 21:25:06 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 21:25:06 | 000,160,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.14 20:16:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 20:15:00 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\David\ntuser.dat
[2010.04.14 20:15:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\David\ntuser.ini
[2010.04.14 12:43:13 | 000,088,938 | ---- | M] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:17:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 12:06:18 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.04.14 10:16:16 | 017,141,571 | ---- | M] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2010.04.14 07:38:01 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.12 01:31:29 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
========== Files Created - No Company Name ==========
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\mbr.log
[2010.04.14 20:28:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\David\log.txt
[2010.04.14 12:43:09 | 000,088,938 | ---- | C] () -- C:\Documents and Settings\David\Dokumenty\cc_20100414_124305.reg
[2010.04.14 12:06:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.04.14 12:06:12 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.04.14 12:04:40 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 12:04:40 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 10:16:11 | 017,141,571 | ---- | C] () -- C:\UsbFix_Upload_Me_DAVID-56D158AFA.zip
[2009.05.06 12:10:01 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\David\ntuser.dat
[2009.02.12 13:38:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.08 18:21:21 | 000,000,151 | ---- | C] () -- C:\Documents and Settings\David\default.pls
[2008.12.08 18:21:16 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.10.16 16:02:52 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.09.30 16:42:07 | 000,000,020 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.03.14 23:45:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.02.15 18:56:26 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.04 16:10:43 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.03 22:18:59 | 000,000,169 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008.01.03 22:18:51 | 000,000,199 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2008.01.02 09:55:35 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\David\Local Settings\Data aplikací\fusioncache.dat
[2008.01.02 00:17:49 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.27 16:18:33 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007.12.27 16:18:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.12.27 16:00:22 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\David\ntuser.ini
[2007.12.27 16:00:21 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\David\NTUSER.DAT.LOG
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2008.01.15 18:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2010.03.11 09:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.03.11 07:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2007.12.27 16:38:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.04.05 23:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.04 23:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.05 20:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.12.24 14:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.04.05 20:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2008.02.26 18:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\AVG7
[2010.03.13 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Command & Conquer 3 Tiberium Wars
[2008.11.12 21:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools
[2010.04.05 19:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
[2008.01.03 22:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Disney Interactive Studios
[2010.04.14 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ
[2008.01.04 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\ICQ Toolbar
[2008.01.01 21:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Leadertech
[2008.09.22 17:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth Files
[2008.09.29 21:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\My Battle for Middle-earth(tm) II Files
[2010.03.30 00:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Software Informer
[2008.01.01 21:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David\Data aplikací\Teleca
========== Purity Check ==========
========== Custom Scans ==========
< :OTL >
< PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) >
< MOD - [2008.12.02 11:01:26 | 000,023,864 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll >
< MOD - [2006.07.11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\SweetIM\Messenger\msvcr71.dll >
< IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found >
< IE - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) >
< FF - prefs.js..browser.search.defaultenginename: "ICQ Search" >
< FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.1&q=" >
< O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found. >
< O3 - HKU\S-1-5-21-1606980848-1647877149-1801674531-1004\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) >
< O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () >
< O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) >
< O4 - Startup: C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění\Registration THE SETTLERS - Dědictví králů.LNK = C:\Program Files\Ubisoft\Blue Byte\THE SETTLERS - Dědictví králů\Support\Register\RegistrationReminder.exe File not found >
< >
< :files >
< C:\WINDOWS\system32\*.tmp.dll /s >
< C:\WINDOWS\system32\SET*.tmp /s >
< C:\WINDOWS\*.tmp /s >
[1 C:\WINDOWS\SoftwareDistribution\Download\872cdbc2aa908a12ab47c2f32baffa55\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\872cdbc2aa908a12ab47c2f32baffa55\*.tmp -> ]
[3 C:\WINDOWS\Temp\_avast5_\*.tmp files -> C:\WINDOWS\Temp\_avast5_\*.tmp -> ]
< C:\Program Files\SweetIM >
< >
< :COMMANDS >
< [Reboot] >
< End of report >
Re: Při sputění windowsu, seklá lišta
Zkopírovala jste tam ten můj skript? Mně se zdá že ne 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
no ano zkopírovala
tak jdu na to ještě jednou.

tak jdu na to ještě jednou.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
Předtím to byl můj omyl
takže se to dodělalo, restartovalo se ale nevím jaký log sem mam šoupnout, když se mi nic neoběvilo. Jen na ploše mam nějaký ,,Thumbs.db" ale nemam ten program v kterém se otevírá

takže se to dodělalo, restartovalo se ale nevím jaký log sem mam šoupnout, když se mi nic neoběvilo. Jen na ploše mam nějaký ,,Thumbs.db" ale nemam ten program v kterém se otevírá

Re: Při sputění windowsu, seklá lišta
Nevadí
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?


- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
Logfile of random's system information tool 1.06 (written by random/random)
Run by David at 2010-04-14 23:52:44
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 27 GB (36%) free of 76 GB
Total RAM: 1023 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:52:52, on 14.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files\Cyberlink\Shared files\brs.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\David\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\David.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKCU\..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
--
End of file - 7197 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll [2010-01-28 671480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-05 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-07 57344]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-04-14 2790472]
"RemoteControl10"=C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [2010-02-03 87336]
"BDRegion"=C:\Program Files\Cyberlink\Shared files\brs.exe [2010-03-13 75048]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BitComet"=C:\Program Files\BitComet\BitComet.exe [2010-03-25 3059448]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění
Registration Heroes of Might & Magic 5.LNK - C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"HonorAutoRunSetting"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-04-14 23:52:44 ----D---- C:\rsit
2010-04-14 23:52:44 ----D---- C:\Program Files\trend micro
2010-04-14 12:23:37 ----SHD---- C:\RECYCLER
2010-04-14 12:06:17 ----A---- C:\Boot.bak
2010-04-14 12:06:05 ----RASHD---- C:\cmdcons
2010-04-14 10:16:06 ----RAD---- C:\autorun.inf
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\wshirda.dll
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\irmon.dll
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\irftp.exe
2010-04-14 08:20:20 ----D---- C:\Documents and Settings\David\Data aplikací\Malwarebytes
2010-04-14 08:20:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-14 08:20:08 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-14 07:53:44 ----D---- C:\Program Files\CCleaner
2010-04-14 07:38:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-14 07:37:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-14 07:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-14 07:33:41 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 07:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 07:33:02 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 09:06:57 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-04-06 22:31:38 ----D---- C:\Program Files\EA GAMES
2010-04-05 23:46:54 ----D---- C:\Program Files\ICQ6.5
2010-04-05 20:19:20 ----D---- C:\Program Files\Common Files\CyberLink
2010-04-05 20:16:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Temp
2010-04-05 20:05:17 ----D---- C:\Program Files\Common Files\Skype
2010-04-05 19:58:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2010-04-05 19:49:29 ----D---- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
2010-03-30 00:09:16 ----D---- C:\Program Files\MagicISO
2010-03-30 00:05:48 ----D---- C:\Documents and Settings\David\Data aplikací\Software Informer
2010-03-22 23:47:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-03-22 11:19:33 ----D---- C:\Documents and Settings\David\Data aplikací\DivX
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\vxblock.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxwave.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxsfs.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxmas.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxdrv.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-03-22 11:18:46 ----N---- C:\WINDOWS\system32\px.dll
2010-03-22 11:17:55 ----D---- C:\Program Files\Common Files\DivX Shared
2010-03-22 11:16:00 ----D---- C:\Program Files\DivX
2010-03-22 11:15:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2010-03-22 08:49:31 ----D---- C:\Program Files\QuickTime
2010-03-22 08:49:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-03-22 08:48:37 ----D---- C:\Program Files\Common Files\Apple
2010-03-22 08:47:58 ----D---- C:\Program Files\Apple Software Update
2010-03-22 08:47:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-03-15 17:48:31 ----D---- C:\WINDOWS\Sun
======List of files/folders modified in the last 1 months======
2010-04-14 23:52:53 ----D---- C:\WINDOWS\Prefetch
2010-04-14 23:52:44 ----RD---- C:\Program Files
2010-04-14 23:51:35 ----D---- C:\Documents and Settings\David\Data aplikací\Skype
2010-04-14 23:50:36 ----D---- C:\WINDOWS\Temp
2010-04-14 23:47:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-14 23:43:50 ----D---- C:\Program Files\BitComet
2010-04-14 23:42:10 ----D---- C:\WINDOWS\Minidump
2010-04-14 23:41:35 ----SHD---- C:\System Volume Information
2010-04-14 23:41:35 ----D---- C:\WINDOWS\system32\Restore
2010-04-14 23:41:26 ----D---- C:\WINDOWS\system32
2010-04-14 23:41:26 ----D---- C:\WINDOWS
2010-04-14 23:38:57 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-14 20:47:23 ----D---- C:\Documents and Settings\David\Data aplikací\ICQ
2010-04-14 20:17:03 ----D---- C:\Documents and Settings\David\Data aplikací\skypePM
2010-04-14 20:14:02 ----D---- C:\WINDOWS\system32\drivers
2010-04-14 18:47:03 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-04-14 12:56:18 ----D---- C:\Documents and Settings\David\Data aplikací\WinRAR
2010-04-14 12:17:59 ----A---- C:\WINDOWS\system.ini
2010-04-14 12:13:59 ----D---- C:\WINDOWS\AppPatch
2010-04-14 12:13:48 ----D---- C:\Program Files\Common Files
2010-04-14 12:06:18 ----RASH---- C:\boot.ini
2010-04-14 08:28:37 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-14 08:28:29 ----D---- C:\WINDOWS\Media
2010-04-14 07:49:29 ----HD---- C:\WINDOWS\inf
2010-04-14 07:38:04 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-14 07:38:01 ----A---- C:\WINDOWS\imsins.BAK
2010-04-14 07:33:19 ----D---- C:\WINDOWS\ie8updates
2010-04-14 00:09:00 ----D---- C:\Program Files\World of Warcraft
2010-04-12 01:31:29 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-06 02:50:50 ----SHD---- C:\WINDOWS\Installer
2010-04-06 02:50:49 ----D---- C:\WINDOWS\WinSxS
2010-04-05 23:19:02 ----D---- C:\Downloads
2010-04-05 21:27:12 ----D---- C:\Documents and Settings\David\Data aplikací\Adobe
2010-04-05 21:27:10 ----D---- C:\Program Files\Common Files\Adobe
2010-04-05 21:26:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-04-05 21:26:06 ----D---- C:\Program Files\Adobe
2010-04-05 20:19:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2010-04-05 20:19:19 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-05 20:17:38 ----D---- C:\Program Files\Mozilla Firefox
2010-04-05 20:16:20 ----D---- C:\Program Files\CyberLink
2010-04-05 20:16:01 ----A---- C:\WINDOWS\system32\msxml3a.dll
2010-04-05 20:15:59 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-04-05 20:15:59 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-04-05 20:06:49 ----D---- C:\Program Files\ICQ6Toolbar
2010-04-05 20:06:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-04-05 20:05:18 ----RD---- C:\Program Files\Skype
2010-04-05 20:05:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-04-05 19:46:43 ----D---- C:\Program Files\WinRAR
2010-03-31 12:06:50 ----D---- C:\Program Files\Internet Explorer
2010-03-31 12:01:53 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-30 18:26:32 ----A---- C:\WINDOWS\setuplog.txt
2010-03-30 06:34:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-30 00:47:34 ----D---- C:\Install
2010-03-22 23:47:08 ----D---- C:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-04-14 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-04-14 162768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-04-14 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/04/05 20:19:36]; \??\C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-04-14 100432]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-05-14 622172]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-04-14 23376]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IpwP;IPWireless 3G Network Adapter; C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2002-10-29 40960]
S3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-05 153376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-02-15 66872]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2008-09-24 126976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
Krásný, asi sme s tím zatočili, lišta se nesekne a vše jde v pořádku
Run by David at 2010-04-14 23:52:44
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 27 GB (36%) free of 76 GB
Total RAM: 1023 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:52:52, on 14.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files\Cyberlink\Shared files\brs.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\David\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\David.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKCU\..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
--
End of file - 7197 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.27.dll [2010-01-28 671480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-05 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-07 57344]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-04-14 2790472]
"RemoteControl10"=C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [2010-02-03 87336]
"BDRegion"=C:\Program Files\Cyberlink\Shared files\brs.exe [2010-03-13 75048]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BitComet"=C:\Program Files\BitComet\BitComet.exe [2010-03-25 3059448]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
C:\Documents and Settings\David\Nabídka Start\Programy\Po spuštění
Registration Heroes of Might & Magic 5.LNK - C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"HonorAutoRunSetting"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-04-14 23:52:44 ----D---- C:\rsit
2010-04-14 23:52:44 ----D---- C:\Program Files\trend micro
2010-04-14 12:23:37 ----SHD---- C:\RECYCLER
2010-04-14 12:06:17 ----A---- C:\Boot.bak
2010-04-14 12:06:05 ----RASHD---- C:\cmdcons
2010-04-14 10:16:06 ----RAD---- C:\autorun.inf
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\wshirda.dll
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\irmon.dll
2010-04-14 08:28:19 ----A---- C:\WINDOWS\system32\irftp.exe
2010-04-14 08:20:20 ----D---- C:\Documents and Settings\David\Data aplikací\Malwarebytes
2010-04-14 08:20:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-14 08:20:08 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-14 07:53:44 ----D---- C:\Program Files\CCleaner
2010-04-14 07:38:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-14 07:37:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-14 07:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-14 07:33:41 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 07:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 07:33:02 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 09:06:57 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-04-06 22:31:38 ----D---- C:\Program Files\EA GAMES
2010-04-05 23:46:54 ----D---- C:\Program Files\ICQ6.5
2010-04-05 20:19:20 ----D---- C:\Program Files\Common Files\CyberLink
2010-04-05 20:16:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Temp
2010-04-05 20:05:17 ----D---- C:\Program Files\Common Files\Skype
2010-04-05 19:58:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2010-04-05 19:49:29 ----D---- C:\Documents and Settings\David\Data aplikací\DAEMON Tools Lite
2010-03-30 00:09:16 ----D---- C:\Program Files\MagicISO
2010-03-30 00:05:48 ----D---- C:\Documents and Settings\David\Data aplikací\Software Informer
2010-03-22 23:47:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-03-22 11:19:33 ----D---- C:\Documents and Settings\David\Data aplikací\DivX
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\vxblock.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxwave.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxsfs.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxmas.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxdrv.dll
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2010-03-22 11:18:47 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-03-22 11:18:46 ----N---- C:\WINDOWS\system32\px.dll
2010-03-22 11:17:55 ----D---- C:\Program Files\Common Files\DivX Shared
2010-03-22 11:16:00 ----D---- C:\Program Files\DivX
2010-03-22 11:15:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2010-03-22 08:49:31 ----D---- C:\Program Files\QuickTime
2010-03-22 08:49:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-03-22 08:48:37 ----D---- C:\Program Files\Common Files\Apple
2010-03-22 08:47:58 ----D---- C:\Program Files\Apple Software Update
2010-03-22 08:47:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-03-15 17:48:31 ----D---- C:\WINDOWS\Sun
======List of files/folders modified in the last 1 months======
2010-04-14 23:52:53 ----D---- C:\WINDOWS\Prefetch
2010-04-14 23:52:44 ----RD---- C:\Program Files
2010-04-14 23:51:35 ----D---- C:\Documents and Settings\David\Data aplikací\Skype
2010-04-14 23:50:36 ----D---- C:\WINDOWS\Temp
2010-04-14 23:47:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-14 23:43:50 ----D---- C:\Program Files\BitComet
2010-04-14 23:42:10 ----D---- C:\WINDOWS\Minidump
2010-04-14 23:41:35 ----SHD---- C:\System Volume Information
2010-04-14 23:41:35 ----D---- C:\WINDOWS\system32\Restore
2010-04-14 23:41:26 ----D---- C:\WINDOWS\system32
2010-04-14 23:41:26 ----D---- C:\WINDOWS
2010-04-14 23:38:57 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-14 20:47:23 ----D---- C:\Documents and Settings\David\Data aplikací\ICQ
2010-04-14 20:17:03 ----D---- C:\Documents and Settings\David\Data aplikací\skypePM
2010-04-14 20:14:02 ----D---- C:\WINDOWS\system32\drivers
2010-04-14 18:47:03 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-04-14 12:56:18 ----D---- C:\Documents and Settings\David\Data aplikací\WinRAR
2010-04-14 12:17:59 ----A---- C:\WINDOWS\system.ini
2010-04-14 12:13:59 ----D---- C:\WINDOWS\AppPatch
2010-04-14 12:13:48 ----D---- C:\Program Files\Common Files
2010-04-14 12:06:18 ----RASH---- C:\boot.ini
2010-04-14 08:28:37 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-14 08:28:29 ----D---- C:\WINDOWS\Media
2010-04-14 07:49:29 ----HD---- C:\WINDOWS\inf
2010-04-14 07:38:04 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-14 07:38:01 ----A---- C:\WINDOWS\imsins.BAK
2010-04-14 07:33:19 ----D---- C:\WINDOWS\ie8updates
2010-04-14 00:09:00 ----D---- C:\Program Files\World of Warcraft
2010-04-12 01:31:29 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-06 02:50:50 ----SHD---- C:\WINDOWS\Installer
2010-04-06 02:50:49 ----D---- C:\WINDOWS\WinSxS
2010-04-05 23:19:02 ----D---- C:\Downloads
2010-04-05 21:27:12 ----D---- C:\Documents and Settings\David\Data aplikací\Adobe
2010-04-05 21:27:10 ----D---- C:\Program Files\Common Files\Adobe
2010-04-05 21:26:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-04-05 21:26:06 ----D---- C:\Program Files\Adobe
2010-04-05 20:19:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2010-04-05 20:19:19 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-05 20:17:38 ----D---- C:\Program Files\Mozilla Firefox
2010-04-05 20:16:20 ----D---- C:\Program Files\CyberLink
2010-04-05 20:16:01 ----A---- C:\WINDOWS\system32\msxml3a.dll
2010-04-05 20:15:59 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-04-05 20:15:59 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-04-05 20:06:49 ----D---- C:\Program Files\ICQ6Toolbar
2010-04-05 20:06:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-04-05 20:05:18 ----RD---- C:\Program Files\Skype
2010-04-05 20:05:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-04-05 19:46:43 ----D---- C:\Program Files\WinRAR
2010-03-31 12:06:50 ----D---- C:\Program Files\Internet Explorer
2010-03-31 12:01:53 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-30 18:26:32 ----A---- C:\WINDOWS\setuplog.txt
2010-03-30 06:34:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-30 00:47:34 ----D---- C:\Install
2010-03-22 23:47:08 ----D---- C:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-04-14 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-04-14 162768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-04-14 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/04/05 20:19:36]; \??\C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-04-14 100432]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-05-14 622172]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-04-14 23376]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IpwP;IPWireless 3G Network Adapter; C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2002-10-29 40960]
S3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-05 153376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-02-15 66872]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2008-09-24 126976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
Krásný, asi sme s tím zatočili, lišta se nesekne a vše jde v pořádku
Re: Při sputění windowsu, seklá lišta

Kód: Vybrat vše
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BitComet"=-
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 66
- Registrován: 14 dub 2010 07:32
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Při spuštění windowsu, seklá lišta
Ano, odinstalovala, ale byli to staré ovládače ke zvuku,
které na tomhle pc byli když jsem ho dostala.
Jinak tam mam už vše v pořádku.
které na tomhle pc byli když jsem ho dostala.
Jinak tam mam už vše v pořádku.
Re: Při sputění windowsu, seklá lišta
Dobře, pokud nejsou problémy, je to vše 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.