
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu
Dlho sa mi zapína notebook, tak preto dávam log, či tam niečo nie je:
Logfile of random's system information tool 1.07 (written by random/random)
Run by user at 2010-05-14 15:47:11
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 172 GB (75%) free of 229 GB
Total RAM: 2039 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:49, on 14. 5. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\user\Desktop\RSIT.exe
C:\Program Files\trend micro\user.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: rpcnetp - Unknown owner - C:\windows\System32\rpcnetp.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
--
End of file - 7604 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-03-24 2145000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-16 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files\PDF Complete\pdfsty.exe [2007-05-08 331552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-10 145184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-31 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-04-17 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfc65e1f-54f8-11de-acb7-0024813ea289}]
shell\verb\command - explorer http://www.p4c.philips.com/files/s/sa1m ... al_eng.zip
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}]
shell\AutoRun\command - F:\Launcher.exe
======File associations======
.reg - open - "regedit.exe" "%1"
======List of files/folders created in the last 1 months======
2010-05-14 15:47:11 ----D---- C:\rsit
2010-05-12 15:30:07 ----A---- C:\windows\system32\inetcomm.dll
2010-05-09 17:12:56 ----D---- C:\Program Files\VirtualDJ
2010-05-08 10:31:04 ----D---- C:\Users\user\AppData\Roaming\VitySoft
2010-05-06 14:01:51 ----D---- C:\Users\user\AppData\Roaming\OpenCandy
2010-05-05 16:59:44 ----D---- C:\Users\user\AppData\Roaming\Malwarebytes
2010-05-05 16:59:33 ----D---- C:\ProgramData\Malwarebytes
2010-05-05 16:59:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-03 16:44:23 ----A---- C:\windows\BDTSupport.dll
2010-05-03 16:44:22 ----A---- C:\windows\SGDetectionTool.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDRes.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDCore.dll
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-03 16:38:32 ----D---- C:\Users\user\AppData\Roaming\PC Tools
2010-05-03 16:38:32 ----D---- C:\ProgramData\PC Tools
2010-05-03 16:38:32 ----D---- C:\Program Files\Spyware Doctor
2010-05-03 16:38:19 ----AD---- C:\ProgramData\TEMP
2010-05-03 13:30:00 ----A---- C:\windows\SWXCACLS.exe
2010-05-03 13:28:13 ----A---- C:\windows\ntbtlog.txt
2010-05-02 19:59:31 ----D---- C:\Qoobox
2010-05-02 16:46:35 ----D---- C:\Program Files\ASIO4ALL v2
2010-05-01 16:29:39 ----A---- C:\windows\zip.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWSC.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWREG.exe
2010-05-01 16:29:39 ----A---- C:\windows\sed.exe
2010-05-01 16:29:39 ----A---- C:\windows\PEV.exe
2010-05-01 16:29:39 ----A---- C:\windows\NIRCMD.exe
2010-05-01 16:29:39 ----A---- C:\windows\MBR.exe
2010-05-01 16:29:39 ----A---- C:\windows\grep.exe
2010-05-01 16:29:33 ----D---- C:\windows\ERDNT
2010-04-15 10:57:37 ----A---- C:\windows\system32\ntoskrnl.exe
2010-04-15 10:57:37 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-04-15 10:57:32 ----A---- C:\windows\system32\vbscript.dll
2010-04-15 10:57:11 ----A---- C:\windows\system32\iphlpsvc.dll
======List of files/folders modified in the last 1 months======
2010-05-14 15:47:27 ----D---- C:\windows\Prefetch
2010-05-14 15:47:20 ----D---- C:\windows\Temp
2010-05-14 15:47:19 ----D---- C:\Program Files\trend micro
2010-05-14 15:38:38 ----D---- C:\windows\System32
2010-05-14 15:38:37 ----D---- C:\windows\inf
2010-05-14 15:38:37 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-14 02:10:22 ----SHD---- C:\System Volume Information
2010-05-13 03:10:51 ----D---- C:\windows\winsxs
2010-05-13 03:01:56 ----D---- C:\Program Files\Windows Mail
2010-05-13 03:01:38 ----D---- C:\windows\system32\catroot
2010-05-12 19:19:13 ----D---- C:\Users\user\AppData\Roaming\Skype
2010-05-12 18:20:17 ----D---- C:\Users\user\AppData\Roaming\skypePM
2010-05-12 15:26:09 ----D---- C:\windows\system32\catroot2
2010-05-09 17:28:06 ----RSD---- C:\windows\Fonts
2010-05-09 17:12:56 ----RD---- C:\Program Files
2010-05-09 17:05:21 ----D---- C:\Program Files\VstPlugins
2010-05-09 08:07:56 ----D---- C:\Windows
2010-05-09 00:49:02 ----SHD---- C:\windows\Installer
2010-05-09 00:48:50 ----D---- C:\windows\system32\drivers
2010-05-06 17:59:25 ----D---- C:\windows\system32\config
2010-05-06 17:59:21 ----D---- C:\windows\Tasks
2010-05-06 17:59:21 ----D---- C:\windows\system32\wbem
2010-05-06 17:59:21 ----D---- C:\windows\system32\spool
2010-05-06 17:59:21 ----D---- C:\windows\system32\Msdtc
2010-05-06 17:59:20 ----D---- C:\windows\registration
2010-05-06 13:57:06 ----D---- C:\Program Files\Image-Line
2010-05-06 10:36:38 ----N---- C:\windows\system32\MpSigStub.exe
2010-05-05 16:59:33 ----HD---- C:\ProgramData
2010-05-03 16:38:39 ----D---- C:\Program Files\Common Files\microsoft shared
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files
2010-05-03 13:42:10 ----D---- C:\windows\Debug
2010-05-03 13:37:08 ----D---- C:\windows\Minidump
2010-05-02 18:39:40 ----D---- C:\Program Files\CCleaner
2010-05-02 18:39:09 ----D---- C:\windows\system32\Tasks
2010-05-01 15:36:40 ----D---- C:\windows\system32\WDI
2010-04-30 20:51:06 ----A---- C:\windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;Offline Files Driver; C:\windows\system32\drivers\csc.sys [2009-04-11 351744]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2010-03-24 114984]
R1 pctgntdi;pctgntdi; \??\C:\Windows\System32\drivers\pctgntdi.sys [2009-10-30 233136]
R2 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2010-03-24 133512]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2010-03-24 134488]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2010-03-24 41312]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2008-04-22 80424]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2008-04-22 80936]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2008-04-22 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e6032.sys [2007-05-24 223616]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2010-03-24 32584]
R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2008-04-15 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-05-26 101376]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ; C:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2007-06-08 30008]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pctplsg;pctplsg; \??\C:\Windows\System32\drivers\pctplsg.sys [2009-09-03 70408]
S3 TfNetMon;TfNetMon; \??\C:\windows\system32\drivers\TfNetMon.sys [2009-11-12 33552]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2008-01-21 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 540448]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 TeamViewer4;TeamViewer 4; C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe [2009-04-17 185640]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 rpcnetp;rpcnetp; C:\windows\System32\rpcnetp.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-03-24 33560]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2008-01-21 523776]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-06-08 172131]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2008-04-16 165192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-08 1112560]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 ThreatFire;ThreatFire; C:\Program Files\Spyware Doctor\TFEngine\TFService.exe [2009-11-12 70928]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2009-04-11 918528]
-----------------EOF-----------------
Logfile of random's system information tool 1.07 (written by random/random)
Run by user at 2010-05-14 15:47:11
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 172 GB (75%) free of 229 GB
Total RAM: 2039 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:49, on 14. 5. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\user\Desktop\RSIT.exe
C:\Program Files\trend micro\user.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: rpcnetp - Unknown owner - C:\windows\System32\rpcnetp.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
--
End of file - 7604 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-03-24 2145000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-16 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files\PDF Complete\pdfsty.exe [2007-05-08 331552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-10 145184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-31 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-04-17 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfc65e1f-54f8-11de-acb7-0024813ea289}]
shell\verb\command - explorer http://www.p4c.philips.com/files/s/sa1m ... al_eng.zip
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}]
shell\AutoRun\command - F:\Launcher.exe
======File associations======
.reg - open - "regedit.exe" "%1"
======List of files/folders created in the last 1 months======
2010-05-14 15:47:11 ----D---- C:\rsit
2010-05-12 15:30:07 ----A---- C:\windows\system32\inetcomm.dll
2010-05-09 17:12:56 ----D---- C:\Program Files\VirtualDJ
2010-05-08 10:31:04 ----D---- C:\Users\user\AppData\Roaming\VitySoft
2010-05-06 14:01:51 ----D---- C:\Users\user\AppData\Roaming\OpenCandy
2010-05-05 16:59:44 ----D---- C:\Users\user\AppData\Roaming\Malwarebytes
2010-05-05 16:59:33 ----D---- C:\ProgramData\Malwarebytes
2010-05-05 16:59:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-03 16:44:23 ----A---- C:\windows\BDTSupport.dll
2010-05-03 16:44:22 ----A---- C:\windows\SGDetectionTool.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDRes.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDCore.dll
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-03 16:38:32 ----D---- C:\Users\user\AppData\Roaming\PC Tools
2010-05-03 16:38:32 ----D---- C:\ProgramData\PC Tools
2010-05-03 16:38:32 ----D---- C:\Program Files\Spyware Doctor
2010-05-03 16:38:19 ----AD---- C:\ProgramData\TEMP
2010-05-03 13:30:00 ----A---- C:\windows\SWXCACLS.exe
2010-05-03 13:28:13 ----A---- C:\windows\ntbtlog.txt
2010-05-02 19:59:31 ----D---- C:\Qoobox
2010-05-02 16:46:35 ----D---- C:\Program Files\ASIO4ALL v2
2010-05-01 16:29:39 ----A---- C:\windows\zip.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWSC.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWREG.exe
2010-05-01 16:29:39 ----A---- C:\windows\sed.exe
2010-05-01 16:29:39 ----A---- C:\windows\PEV.exe
2010-05-01 16:29:39 ----A---- C:\windows\NIRCMD.exe
2010-05-01 16:29:39 ----A---- C:\windows\MBR.exe
2010-05-01 16:29:39 ----A---- C:\windows\grep.exe
2010-05-01 16:29:33 ----D---- C:\windows\ERDNT
2010-04-15 10:57:37 ----A---- C:\windows\system32\ntoskrnl.exe
2010-04-15 10:57:37 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-04-15 10:57:32 ----A---- C:\windows\system32\vbscript.dll
2010-04-15 10:57:11 ----A---- C:\windows\system32\iphlpsvc.dll
======List of files/folders modified in the last 1 months======
2010-05-14 15:47:27 ----D---- C:\windows\Prefetch
2010-05-14 15:47:20 ----D---- C:\windows\Temp
2010-05-14 15:47:19 ----D---- C:\Program Files\trend micro
2010-05-14 15:38:38 ----D---- C:\windows\System32
2010-05-14 15:38:37 ----D---- C:\windows\inf
2010-05-14 15:38:37 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-14 02:10:22 ----SHD---- C:\System Volume Information
2010-05-13 03:10:51 ----D---- C:\windows\winsxs
2010-05-13 03:01:56 ----D---- C:\Program Files\Windows Mail
2010-05-13 03:01:38 ----D---- C:\windows\system32\catroot
2010-05-12 19:19:13 ----D---- C:\Users\user\AppData\Roaming\Skype
2010-05-12 18:20:17 ----D---- C:\Users\user\AppData\Roaming\skypePM
2010-05-12 15:26:09 ----D---- C:\windows\system32\catroot2
2010-05-09 17:28:06 ----RSD---- C:\windows\Fonts
2010-05-09 17:12:56 ----RD---- C:\Program Files
2010-05-09 17:05:21 ----D---- C:\Program Files\VstPlugins
2010-05-09 08:07:56 ----D---- C:\Windows
2010-05-09 00:49:02 ----SHD---- C:\windows\Installer
2010-05-09 00:48:50 ----D---- C:\windows\system32\drivers
2010-05-06 17:59:25 ----D---- C:\windows\system32\config
2010-05-06 17:59:21 ----D---- C:\windows\Tasks
2010-05-06 17:59:21 ----D---- C:\windows\system32\wbem
2010-05-06 17:59:21 ----D---- C:\windows\system32\spool
2010-05-06 17:59:21 ----D---- C:\windows\system32\Msdtc
2010-05-06 17:59:20 ----D---- C:\windows\registration
2010-05-06 13:57:06 ----D---- C:\Program Files\Image-Line
2010-05-06 10:36:38 ----N---- C:\windows\system32\MpSigStub.exe
2010-05-05 16:59:33 ----HD---- C:\ProgramData
2010-05-03 16:38:39 ----D---- C:\Program Files\Common Files\microsoft shared
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files
2010-05-03 13:42:10 ----D---- C:\windows\Debug
2010-05-03 13:37:08 ----D---- C:\windows\Minidump
2010-05-02 18:39:40 ----D---- C:\Program Files\CCleaner
2010-05-02 18:39:09 ----D---- C:\windows\system32\Tasks
2010-05-01 15:36:40 ----D---- C:\windows\system32\WDI
2010-04-30 20:51:06 ----A---- C:\windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;Offline Files Driver; C:\windows\system32\drivers\csc.sys [2009-04-11 351744]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2010-03-24 114984]
R1 pctgntdi;pctgntdi; \??\C:\Windows\System32\drivers\pctgntdi.sys [2009-10-30 233136]
R2 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2010-03-24 133512]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2010-03-24 134488]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2010-03-24 41312]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2008-04-22 80424]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2008-04-22 80936]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2008-04-22 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e6032.sys [2007-05-24 223616]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2010-03-24 32584]
R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2008-04-15 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-05-26 101376]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ; C:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2007-06-08 30008]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pctplsg;pctplsg; \??\C:\Windows\System32\drivers\pctplsg.sys [2009-09-03 70408]
S3 TfNetMon;TfNetMon; \??\C:\windows\system32\drivers\TfNetMon.sys [2009-11-12 33552]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2008-01-21 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 540448]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 TeamViewer4;TeamViewer 4; C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe [2009-04-17 185640]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 rpcnetp;rpcnetp; C:\windows\System32\rpcnetp.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-03-24 33560]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2008-01-21 523776]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-06-08 172131]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2008-04-16 165192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-08 1112560]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 ThreatFire;ThreatFire; C:\Program Files\Spyware Doctor\TFEngine\TFService.exe [2009-11-12 70928]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2009-04-11 918528]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
Hezký podvečer
Vidím že jste nedávno spouštěl combofix, ale log z něj se asi neudělal? Jinak combofix se nedoporučuje používat bez dozoru rádce, hrozí poškození systému
.

Vidím že jste nedávno spouštěl combofix, ale log z něj se asi neudělal? Jinak combofix se nedoporučuje používat bez dozoru rádce, hrozí poškození systému

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
áno, použil som combofix, ale nešiel mi rozbehnúť
Re: Prosím o kontrolu logu

-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
OTL.Txt:
OTL logfile created on: 15. 5. 2010 13:11:50 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\user\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,88 Gb Total Space | 167,91 Gb Free Space | 75,00% Space Free | Partition Type: NTFS
Drive D: | 9,00 Gb Total Space | 1,63 Gb Free Space | 18,07% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
PRC - [2010/04/02 15:30:46 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/24 20:31:50 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010/03/24 20:31:00 | 002,145,000 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009/11/10 10:28:08 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/04/17 17:11:08 | 000,185,640 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
PRC - [2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/04/18 15:54:02 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/12/11 14:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2007/05/08 18:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2007/02/06 09:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
PRC - [2007/01/04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (SafeList) ==========
MOD - [2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
MOD - [2009/04/11 08:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 04:25:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (PEVSystemStart)
SRV - [2010/03/24 20:39:48 | 000,033,560 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/03/24 20:31:50 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009/11/12 10:03:32 | 000,070,928 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2009/11/10 10:28:08 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/08/09 13:57:24 | 000,017,408 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\rpcnetp.dll -- (rpcnetp)
SRV - [2009/04/17 17:11:08 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2009/02/18 20:38:43 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/04/18 15:54:02 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2008/04/08 14:12:50 | 001,112,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2008/01/21 04:23:59 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/11 14:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2007/06/08 19:06:42 | 000,172,131 | R--- | M] (Hewlett-Packard Ltd) [On_Demand | Stopped] -- C:\Windows\System32\flcdlock.exe -- (FLCDLOCK)
SRV - [2007/05/08 18:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2007/02/06 09:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007/01/04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ==========
DRV - [2010/03/24 20:33:54 | 000,041,312 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2010/03/24 20:33:50 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010/03/24 20:33:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2010/03/24 20:31:06 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/03/24 20:23:54 | 000,133,512 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2009/11/12 10:03:32 | 000,059,664 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - [2009/11/12 10:03:32 | 000,051,984 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2009/11/12 10:03:32 | 000,033,552 | --S- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2009/11/09 11:20:12 | 000,207,792 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/10/30 11:11:00 | 000,233,136 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2009/09/03 09:45:12 | 000,070,408 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pctplsg.sys -- (pctplsg)
DRV - [2008/04/28 08:29:26 | 003,658,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R)
DRV - [2008/04/24 15:26:28 | 000,309,248 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2008/04/22 09:46:28 | 000,080,936 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
DRV - [2008/04/22 09:46:28 | 000,080,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
DRV - [2008/04/22 09:46:28 | 000,016,168 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwrchid.sys -- (btwrchid)
DRV - [2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iastor.sys -- (iaStor)
DRV - [2008/04/15 00:39:06 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2008/03/27 21:06:00 | 000,199,472 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008/03/21 20:35:24 | 001,207,288 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XX)
DRV - [2008/02/29 18:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/02/11 14:36:10 | 002,302,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2008/01/21 04:23:51 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 04:23:51 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 04:23:51 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 04:23:51 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2008/01/21 04:23:51 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 04:23:51 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 04:23:50 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 04:23:50 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 04:23:50 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 04:23:49 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 04:23:49 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008/01/21 04:23:49 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 04:23:48 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] -- C:\windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 04:23:48 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 04:23:48 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 04:23:47 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 04:23:47 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 04:23:46 | 000,342,584 | ---- | M] (Emulex) [Kernel | Boot | Running] -- C:\windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 04:23:45 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 04:23:45 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 04:23:45 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 04:23:44 | 000,179,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2008/01/21 04:23:26 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 04:23:26 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 04:23:26 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/06/19 03:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/06/08 18:49:46 | 000,030,008 | R--- | M] (Hewlett-Packard Development Company L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DAMDrv.sys -- (DAMDrv)
DRV - [2007/05/26 14:37:28 | 000,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2007/05/24 16:07:18 | 000,223,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2006/11/02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... id=afex&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/24 12:55:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/02 15:30:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/05/09 00:47:46 | 000,000,000 | ---D | M]
[2009/05/09 15:24:28 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\mozilla\Extensions
[2010/05/14 23:19:58 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\jcppfgqk.default\extensions
[2010/03/15 22:28:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\jcppfgqk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/08 08:35:36 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-1.xml
[2009/12/17 09:19:31 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-2.xml
[2010/01/08 09:16:14 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-3.xml
[2010/01/31 13:33:39 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-4.xml
[2010/03/02 15:18:41 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-5.xml
[2010/03/23 11:38:39 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-6.xml
[2010/04/02 15:31:02 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-7.xml
[2008/03/31 10:52:00 | 000,000,168 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.gif
[2008/03/31 10:52:00 | 000,000,618 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.src
[2009/07/13 18:12:02 | 000,000,944 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.xml
[2010/05/14 21:57:54 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/20 08:52:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009/02/21 08:24:52 | 000,660,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2010/01/16 03:31:40 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/01/16 03:31:40 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/01/16 03:31:40 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/01/16 03:31:40 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/01/16 03:31:40 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/01/16 03:31:40 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 195.146.128.62
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\DeviceNP: DllName - DeviceNP.dll - C:\windows\System32\DeviceNP.dll (Hewlett-Packard Limited)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O24 - Desktop BackupWallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 04:35:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
File not found -- C:\Users\user\Documents\ haluz
[2010/05/15 13:05:31 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/05/14 15:47:11 | 000,000,000 | ---D | C] -- C:\rsit
[2010/05/13 21:22:42 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\FOTO
[2010/05/09 17:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2010/05/09 00:49:12 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ESET
[2010/05/08 10:31:04 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\VitySoft
[2010/05/08 08:29:37 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Threat Expert
[2010/05/06 14:01:51 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\OpenCandy
[2010/05/05 16:59:44 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Malwarebytes
[2010/05/05 16:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/05/05 16:59:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/03 17:04:05 | 000,059,664 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfSysMon.sys
[2010/05/03 17:04:04 | 000,051,984 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfFsMon.sys
[2010/05/03 17:04:04 | 000,033,552 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfNetMon.sys
[2010/05/03 16:44:22 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\windows\PCTBDCore.dll
[2010/05/03 16:44:22 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\windows\PCTBDRes.dll
[2010/05/03 16:44:22 | 000,149,456 | ---- | C] (PC Tools) -- C:\windows\SGDetectionTool.dll
[2010/05/03 16:39:27 | 000,233,136 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctgntdi.sys
[2010/05/03 16:39:26 | 000,098,600 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctwfpfilter.sys
[2010/05/03 16:39:17 | 000,207,792 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTCore.sys
[2010/05/03 16:39:17 | 000,087,784 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTAppEvent.sys
[2010/05/03 16:38:58 | 000,070,408 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctplsg.sys
[2010/05/03 16:38:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\PC Tools
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/05/03 16:38:19 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/05/03 13:30:00 | 000,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe
[2010/05/02 19:59:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/05/02 16:46:35 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2
[2010/05/02 16:44:37 | 001,554,944 | ---- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) -- C:\windows\System32\vorbis.acm
[2010/05/01 16:29:39 | 000,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2010/05/01 16:29:39 | 000,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2010/05/01 16:29:39 | 000,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2010/05/01 16:29:33 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
========== Files - Modified Within 30 Days ==========
File not found -- C:\Users\user\Documents\ haluz
[2010/05/15 13:06:53 | 002,883,584 | -HS- | M] () -- C:\Users\user\ntuser.dat
[2010/05/15 13:06:50 | 000,751,146 | ---- | M] () -- C:\windows\System32\PerfStringBackup.INI
[2010/05/15 13:06:50 | 000,628,486 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2010/05/15 13:06:50 | 000,117,988 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/05/15 13:04:36 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2010/05/15 13:04:34 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 13:04:33 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 06:17:54 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2010/05/15 06:17:46 | 2138,365,952 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/14 23:42:20 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat
[2010/05/14 23:42:17 | 000,524,288 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
[2010/05/14 23:42:17 | 000,065,536 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
[2010/05/14 23:42:03 | 002,758,311 | -H-- | M] () -- C:\Users\user\AppData\Local\IconCache.db
[2010/05/14 21:47:44 | 000,002,395 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010/05/14 18:04:22 | 000,118,691 | ---- | M] () -- C:\Users\user\Desktop\Snímka1984.jpg
[2010/05/14 15:40:15 | 000,824,681 | ---- | M] () -- C:\Users\user\Desktop\RSIT.exe
[2010/05/10 16:04:33 | 106,733,612 | ---- | M] () -- C:\Users\user\Documents\ mruški mix wav.wav
[2010/05/10 14:04:33 | 000,420,920 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2010/05/09 17:27:31 | 000,000,627 | ---- | M] () -- C:\Users\user\Desktop\Virtual DJ Trial.lnk
[2010/05/06 21:09:37 | 000,020,480 | ---- | M] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/06 10:36:38 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MpSigStub.exe
[2010/05/03 13:37:04 | 167,841,224 | ---- | M] () -- C:\windows\MEMORY.DMP
[2010/05/02 16:46:36 | 000,000,935 | ---- | M] () -- C:\Users\user\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\windows\PEV.exe
[2010/04/18 12:44:18 | 000,002,677 | ---- | M] () -- C:\Users\user\Desktop\Microsoft Office Word 2007.lnk
========== Files Created - No Company Name ==========
[2010/05/14 22:17:30 | 000,118,691 | ---- | C] () -- C:\Users\user\Desktop\Snímka1984.jpg
[2010/05/14 15:40:10 | 000,824,681 | ---- | C] () -- C:\Users\user\Desktop\RSIT.exe
[2010/05/12 16:55:32 | 006,332,544 | ---- | C] () -- C:\Users\user\Desktop\Metallica - The Unforgiven II.mp3
[2010/05/10 15:54:28 | 106,733,612 | ---- | C] () -- C:\Users\user\Documents\ mruški mix wav.wav
[2010/05/09 17:14:55 | 000,000,627 | ---- | C] () -- C:\Users\user\Desktop\Virtual DJ Trial.lnk
[2010/05/03 16:44:23 | 000,767,952 | ---- | C] () -- C:\windows\BDTSupport.dll
[2010/05/03 16:44:22 | 001,152,444 | ---- | C] () -- C:\windows\UDB.zip
[2010/05/03 16:44:22 | 000,000,882 | ---- | C] () -- C:\windows\RegSDImport.xml
[2010/05/03 16:44:22 | 000,000,880 | ---- | C] () -- C:\windows\RegISSImport.xml
[2010/05/03 16:44:22 | 000,000,131 | ---- | C] () -- C:\windows\IDB.zip
[2010/05/03 16:39:27 | 000,007,387 | ---- | C] () -- C:\windows\System32\drivers\pctgntdi.cat
[2010/05/03 16:39:17 | 000,007,412 | ---- | C] () -- C:\windows\System32\drivers\PCTAppEvent.cat
[2010/05/03 16:39:17 | 000,007,383 | ---- | C] () -- C:\windows\System32\drivers\pctcore.cat
[2010/05/03 16:38:59 | 000,007,383 | ---- | C] () -- C:\windows\System32\drivers\pctplsg.cat
[2010/05/03 13:37:05 | 2138,365,952 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/03 13:37:04 | 167,841,224 | ---- | C] () -- C:\windows\MEMORY.DMP
[2010/05/02 16:46:36 | 000,000,935 | ---- | C] () -- C:\Users\user\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2010/05/01 16:29:39 | 000,256,512 | ---- | C] () -- C:\windows\PEV.exe
[2010/05/01 16:29:39 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2010/05/01 16:29:39 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2010/05/01 16:29:39 | 000,077,312 | ---- | C] () -- C:\windows\MBR.exe
[2010/05/01 16:29:39 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2009/07/31 02:12:36 | 000,117,248 | ---- | C] () -- C:\windows\System32\EhStorAuthn.dll
[2009/05/04 13:29:55 | 000,204,800 | ---- | C] () -- C:\windows\System32\IVIresizeW7.dll
[2009/05/04 13:29:55 | 000,188,416 | ---- | C] () -- C:\windows\System32\IVIresizePX.dll
[2009/05/04 13:29:54 | 000,200,704 | ---- | C] () -- C:\windows\System32\IVIresizeA6.dll
[2009/05/04 13:29:54 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeP6.dll
[2009/05/04 13:29:54 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeM6.dll
[2009/05/04 13:29:54 | 000,020,480 | ---- | C] () -- C:\windows\System32\IVIresize.dll
[2009/02/21 08:25:20 | 000,691,592 | ---- | C] () -- C:\windows\System32\OGACheckControl.DLL
[2008/11/22 05:46:56 | 000,000,000 | ---- | C] () -- C:\windows\HPMProp.INI
[2008/10/10 08:36:28 | 000,003,584 | ---- | C] () -- C:\windows\System32\wceprv.dll
[2008/04/18 18:13:12 | 000,017,408 | ---- | C] () -- C:\windows\System32\rpcnetp.dll
[2008/02/11 14:55:18 | 000,147,456 | ---- | C] () -- C:\windows\System32\igfxCoIn_v1437.dll
[2007/06/08 19:05:38 | 000,274,432 | ---- | C] () -- C:\windows\System32\flcdlmsg.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\windows\System32\pacerprf.ini
[2006/03/09 11:58:00 | 001,060,424 | ---- | C] () -- C:\windows\System32\WdfCoInstaller01000.dll
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\windows\System32\lcppn21.dll
========== LOP Check ==========
[2009/05/04 15:02:45 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ESET
[2010/03/07 13:06:25 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ICQ
[2009/06/25 20:37:09 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\InterVideo
[2010/05/06 14:48:58 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
[2009/07/28 15:57:31 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SolSuite
[2009/05/27 14:50:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TeamViewer
[2010/05/08 10:31:04 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\VitySoft
[2010/05/14 23:42:26 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008/01/21 04:25:56 | 000,202,240 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< MD5 for: AGP440.SYS >
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 04:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 04:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2008/10/29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 04:24:50 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: HAL.DLL >
[2009/04/11 08:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Windows\System32\hal.dll
< MD5 for: IASTOR.SYS >
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\SwSetup\Drivers\64\HDD\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\SwSetup\Drivers\Global\INTELMSM\Winall\Driver64\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_6917e7b0\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\SwSetup\Drivers\32\HDD\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\SwSetup\Drivers\Global\INTELMSM\Winall\Driver\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_054cd65f\iaStor.sys
< MD5 for: IASTORV.SYS >
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: LSASS.EXE >
[2009/06/15 14:51:56 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=203D86EBD6D8E4C8501B222421E81506 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_a886901f7335e2fc\lsass.exe
[2009/09/10 16:44:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2D3AC5E7AC01E905F3ABD2D745FE3A9B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
[2009/06/15 14:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\System32\lsass.exe
[2009/06/15 14:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_a7fbf30a5a1929db\lsass.exe
[2009/02/13 09:26:04 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=59DE082968FDD257FFF0D209B9A5B460 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[2009/06/15 15:03:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=6F1F23D3599EAE17734451936B7F17C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_a69e1da376115b2a\lsass.exe
[2009/06/15 14:57:59 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A911ECAC81F94ADEAFBE8E3F7873EDB0 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_a600dfae5d0228c9\lsass.exe
[2009/02/13 06:58:37 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=AFF8A58280863629CA4FFA9E0B259F1E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[2009/06/15 14:59:08 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=BA9A67672E025078C77967731BCFC560 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_a4b3e75378eccda6\lsass.exe
[2009/06/15 15:10:12 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=C731B1FE449D4E9CEA358C9D55B69BE9 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_a418a0745fdd652a\lsass.exe
[2009/09/09 13:09:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=CB7E838C140B4087B2DA323F2D4523C5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
[2009/09/10 16:47:51 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=D09A5DA84B7C9CA9B02EBCD7FAE41C8D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\lsass.exe
[2009/02/13 10:20:29 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=F4C62B07E5BF96F1FDCA9DB393ECED22 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe
< MD5 for: NDIS.SYS >
[2009/04/11 08:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009/04/11 08:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2008/01/21 04:24:15 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
[2008/02/08 06:25:28 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=C8560010A542B5DCA94C62468DC20784 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.22110_none_a845f8a63534c8d3\ndis.sys
[2008/02/08 06:22:00 | 000,503,352 | ---- | M] (Microsoft Corporation) MD5=E50187F20ED749F57C97836FEDE14BD6 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.20768_none_a631acb4382f8e4f\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 04:24:31 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/21 04:25:18 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< MD5 for: SMSS.EXE >
[2008/01/21 04:24:14 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=6701DDAF68BEDE6BBEEA9D514D73A35B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
[2009/04/11 08:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\System32\smss.exe
[2009/04/11 08:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_ae26210916536b06\smss.exe
< MD5 for: SVCHOST.EXE >
[2008/01/21 04:24:10 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/21 04:24:10 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/21 04:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/21 04:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 04:25:17 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008/01/21 04:25:16 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\ws2_32.dll
[2008/01/21 04:25:16 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/04/11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009/04/11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
========== Alternate Data Streams ==========
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
OTL logfile created on: 15. 5. 2010 13:11:50 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\user\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,88 Gb Total Space | 167,91 Gb Free Space | 75,00% Space Free | Partition Type: NTFS
Drive D: | 9,00 Gb Total Space | 1,63 Gb Free Space | 18,07% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
PRC - [2010/04/02 15:30:46 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/24 20:31:50 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010/03/24 20:31:00 | 002,145,000 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009/11/10 10:28:08 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/04/17 17:11:08 | 000,185,640 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
PRC - [2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/04/18 15:54:02 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/12/11 14:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2007/05/08 18:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2007/02/06 09:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
PRC - [2007/01/04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (SafeList) ==========
MOD - [2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
MOD - [2009/04/11 08:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 04:25:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (PEVSystemStart)
SRV - [2010/03/24 20:39:48 | 000,033,560 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/03/24 20:31:50 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009/11/12 10:03:32 | 000,070,928 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2009/11/10 10:28:08 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/08/09 13:57:24 | 000,017,408 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\rpcnetp.dll -- (rpcnetp)
SRV - [2009/04/17 17:11:08 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2009/02/18 20:38:43 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/04/18 15:54:02 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2008/04/08 14:12:50 | 001,112,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2008/01/21 04:23:59 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/11 14:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2007/06/08 19:06:42 | 000,172,131 | R--- | M] (Hewlett-Packard Ltd) [On_Demand | Stopped] -- C:\Windows\System32\flcdlock.exe -- (FLCDLOCK)
SRV - [2007/05/08 18:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2007/02/06 09:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007/01/04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ==========
DRV - [2010/03/24 20:33:54 | 000,041,312 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2010/03/24 20:33:50 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010/03/24 20:33:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2010/03/24 20:31:06 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/03/24 20:23:54 | 000,133,512 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2009/11/12 10:03:32 | 000,059,664 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - [2009/11/12 10:03:32 | 000,051,984 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2009/11/12 10:03:32 | 000,033,552 | --S- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2009/11/09 11:20:12 | 000,207,792 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/10/30 11:11:00 | 000,233,136 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2009/09/03 09:45:12 | 000,070,408 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pctplsg.sys -- (pctplsg)
DRV - [2008/04/28 08:29:26 | 003,658,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R)
DRV - [2008/04/24 15:26:28 | 000,309,248 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2008/04/22 09:46:28 | 000,080,936 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
DRV - [2008/04/22 09:46:28 | 000,080,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
DRV - [2008/04/22 09:46:28 | 000,016,168 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btwrchid.sys -- (btwrchid)
DRV - [2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iastor.sys -- (iaStor)
DRV - [2008/04/15 00:39:06 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2008/03/27 21:06:00 | 000,199,472 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008/03/21 20:35:24 | 001,207,288 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XX)
DRV - [2008/02/29 18:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/02/11 14:36:10 | 002,302,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2008/01/21 04:23:51 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 04:23:51 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 04:23:51 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 04:23:51 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2008/01/21 04:23:51 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 04:23:51 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 04:23:50 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 04:23:50 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 04:23:50 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 04:23:49 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 04:23:49 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008/01/21 04:23:49 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 04:23:48 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] -- C:\windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 04:23:48 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 04:23:48 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 04:23:47 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 04:23:47 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 04:23:46 | 000,342,584 | ---- | M] (Emulex) [Kernel | Boot | Running] -- C:\windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 04:23:45 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 04:23:45 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 04:23:45 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 04:23:44 | 000,179,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2008/01/21 04:23:26 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 04:23:26 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 04:23:26 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/06/19 03:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/06/08 18:49:46 | 000,030,008 | R--- | M] (Hewlett-Packard Development Company L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DAMDrv.sys -- (DAMDrv)
DRV - [2007/05/26 14:37:28 | 000,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2007/05/24 16:07:18 | 000,223,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2006/11/02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Boot | Running] -- C:\windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... id=afex&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/24 12:55:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/02 15:30:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/05/09 00:47:46 | 000,000,000 | ---D | M]
[2009/05/09 15:24:28 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\mozilla\Extensions
[2010/05/14 23:19:58 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\jcppfgqk.default\extensions
[2010/03/15 22:28:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\jcppfgqk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/08 08:35:36 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-1.xml
[2009/12/17 09:19:31 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-2.xml
[2010/01/08 09:16:14 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-3.xml
[2010/01/31 13:33:39 | 000,000,961 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-4.xml
[2010/03/02 15:18:41 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-5.xml
[2010/03/23 11:38:39 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-6.xml
[2010/04/02 15:31:02 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin-7.xml
[2008/03/31 10:52:00 | 000,000,168 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.gif
[2008/03/31 10:52:00 | 000,000,618 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.src
[2009/07/13 18:12:02 | 000,000,944 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\jcppfgqk.default\searchplugins\icqplugin.xml
[2010/05/14 21:57:54 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/20 08:52:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009/02/21 08:24:52 | 000,660,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2010/01/16 03:31:40 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/01/16 03:31:40 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/01/16 03:31:40 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/01/16 03:31:40 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/01/16 03:31:40 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/01/16 03:31:40 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 195.146.128.62
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\DeviceNP: DllName - DeviceNP.dll - C:\windows\System32\DeviceNP.dll (Hewlett-Packard Limited)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O24 - Desktop BackupWallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}\Shell - "" = AutoRun
O33 - MountPoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 04:35:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
File not found -- C:\Users\user\Documents\ haluz
[2010/05/15 13:05:31 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/05/14 15:47:11 | 000,000,000 | ---D | C] -- C:\rsit
[2010/05/13 21:22:42 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\FOTO
[2010/05/09 17:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2010/05/09 00:49:12 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ESET
[2010/05/08 10:31:04 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\VitySoft
[2010/05/08 08:29:37 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Threat Expert
[2010/05/06 14:01:51 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\OpenCandy
[2010/05/05 16:59:44 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Malwarebytes
[2010/05/05 16:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/05/05 16:59:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/03 17:04:05 | 000,059,664 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfSysMon.sys
[2010/05/03 17:04:04 | 000,051,984 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfFsMon.sys
[2010/05/03 17:04:04 | 000,033,552 | --S- | C] (PC Tools) -- C:\windows\System32\drivers\TfNetMon.sys
[2010/05/03 16:44:22 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\windows\PCTBDCore.dll
[2010/05/03 16:44:22 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\windows\PCTBDRes.dll
[2010/05/03 16:44:22 | 000,149,456 | ---- | C] (PC Tools) -- C:\windows\SGDetectionTool.dll
[2010/05/03 16:39:27 | 000,233,136 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctgntdi.sys
[2010/05/03 16:39:26 | 000,098,600 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctwfpfilter.sys
[2010/05/03 16:39:17 | 000,207,792 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTCore.sys
[2010/05/03 16:39:17 | 000,087,784 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTAppEvent.sys
[2010/05/03 16:38:58 | 000,070,408 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\pctplsg.sys
[2010/05/03 16:38:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\PC Tools
[2010/05/03 16:38:32 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/05/03 16:38:19 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/05/03 13:30:00 | 000,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe
[2010/05/02 19:59:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/05/02 16:46:35 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2
[2010/05/02 16:44:37 | 001,554,944 | ---- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) -- C:\windows\System32\vorbis.acm
[2010/05/01 16:29:39 | 000,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2010/05/01 16:29:39 | 000,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2010/05/01 16:29:39 | 000,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2010/05/01 16:29:33 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
========== Files - Modified Within 30 Days ==========
File not found -- C:\Users\user\Documents\ haluz
[2010/05/15 13:06:53 | 002,883,584 | -HS- | M] () -- C:\Users\user\ntuser.dat
[2010/05/15 13:06:50 | 000,751,146 | ---- | M] () -- C:\windows\System32\PerfStringBackup.INI
[2010/05/15 13:06:50 | 000,628,486 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2010/05/15 13:06:50 | 000,117,988 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2010/05/15 13:05:58 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/05/15 13:04:36 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2010/05/15 13:04:34 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 13:04:33 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 06:17:54 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2010/05/15 06:17:46 | 2138,365,952 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/14 23:42:20 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat
[2010/05/14 23:42:17 | 000,524,288 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
[2010/05/14 23:42:17 | 000,065,536 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
[2010/05/14 23:42:03 | 002,758,311 | -H-- | M] () -- C:\Users\user\AppData\Local\IconCache.db
[2010/05/14 21:47:44 | 000,002,395 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010/05/14 18:04:22 | 000,118,691 | ---- | M] () -- C:\Users\user\Desktop\Snímka1984.jpg
[2010/05/14 15:40:15 | 000,824,681 | ---- | M] () -- C:\Users\user\Desktop\RSIT.exe
[2010/05/10 16:04:33 | 106,733,612 | ---- | M] () -- C:\Users\user\Documents\ mruški mix wav.wav
[2010/05/10 14:04:33 | 000,420,920 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2010/05/09 17:27:31 | 000,000,627 | ---- | M] () -- C:\Users\user\Desktop\Virtual DJ Trial.lnk
[2010/05/06 21:09:37 | 000,020,480 | ---- | M] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/06 10:36:38 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MpSigStub.exe
[2010/05/03 13:37:04 | 167,841,224 | ---- | M] () -- C:\windows\MEMORY.DMP
[2010/05/02 16:46:36 | 000,000,935 | ---- | M] () -- C:\Users\user\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\windows\PEV.exe
[2010/04/18 12:44:18 | 000,002,677 | ---- | M] () -- C:\Users\user\Desktop\Microsoft Office Word 2007.lnk
========== Files Created - No Company Name ==========
[2010/05/14 22:17:30 | 000,118,691 | ---- | C] () -- C:\Users\user\Desktop\Snímka1984.jpg
[2010/05/14 15:40:10 | 000,824,681 | ---- | C] () -- C:\Users\user\Desktop\RSIT.exe
[2010/05/12 16:55:32 | 006,332,544 | ---- | C] () -- C:\Users\user\Desktop\Metallica - The Unforgiven II.mp3
[2010/05/10 15:54:28 | 106,733,612 | ---- | C] () -- C:\Users\user\Documents\ mruški mix wav.wav
[2010/05/09 17:14:55 | 000,000,627 | ---- | C] () -- C:\Users\user\Desktop\Virtual DJ Trial.lnk
[2010/05/03 16:44:23 | 000,767,952 | ---- | C] () -- C:\windows\BDTSupport.dll
[2010/05/03 16:44:22 | 001,152,444 | ---- | C] () -- C:\windows\UDB.zip
[2010/05/03 16:44:22 | 000,000,882 | ---- | C] () -- C:\windows\RegSDImport.xml
[2010/05/03 16:44:22 | 000,000,880 | ---- | C] () -- C:\windows\RegISSImport.xml
[2010/05/03 16:44:22 | 000,000,131 | ---- | C] () -- C:\windows\IDB.zip
[2010/05/03 16:39:27 | 000,007,387 | ---- | C] () -- C:\windows\System32\drivers\pctgntdi.cat
[2010/05/03 16:39:17 | 000,007,412 | ---- | C] () -- C:\windows\System32\drivers\PCTAppEvent.cat
[2010/05/03 16:39:17 | 000,007,383 | ---- | C] () -- C:\windows\System32\drivers\pctcore.cat
[2010/05/03 16:38:59 | 000,007,383 | ---- | C] () -- C:\windows\System32\drivers\pctplsg.cat
[2010/05/03 13:37:05 | 2138,365,952 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/03 13:37:04 | 167,841,224 | ---- | C] () -- C:\windows\MEMORY.DMP
[2010/05/02 16:46:36 | 000,000,935 | ---- | C] () -- C:\Users\user\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2010/05/01 16:29:39 | 000,256,512 | ---- | C] () -- C:\windows\PEV.exe
[2010/05/01 16:29:39 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2010/05/01 16:29:39 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2010/05/01 16:29:39 | 000,077,312 | ---- | C] () -- C:\windows\MBR.exe
[2010/05/01 16:29:39 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2009/07/31 02:12:36 | 000,117,248 | ---- | C] () -- C:\windows\System32\EhStorAuthn.dll
[2009/05/04 13:29:55 | 000,204,800 | ---- | C] () -- C:\windows\System32\IVIresizeW7.dll
[2009/05/04 13:29:55 | 000,188,416 | ---- | C] () -- C:\windows\System32\IVIresizePX.dll
[2009/05/04 13:29:54 | 000,200,704 | ---- | C] () -- C:\windows\System32\IVIresizeA6.dll
[2009/05/04 13:29:54 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeP6.dll
[2009/05/04 13:29:54 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeM6.dll
[2009/05/04 13:29:54 | 000,020,480 | ---- | C] () -- C:\windows\System32\IVIresize.dll
[2009/02/21 08:25:20 | 000,691,592 | ---- | C] () -- C:\windows\System32\OGACheckControl.DLL
[2008/11/22 05:46:56 | 000,000,000 | ---- | C] () -- C:\windows\HPMProp.INI
[2008/10/10 08:36:28 | 000,003,584 | ---- | C] () -- C:\windows\System32\wceprv.dll
[2008/04/18 18:13:12 | 000,017,408 | ---- | C] () -- C:\windows\System32\rpcnetp.dll
[2008/02/11 14:55:18 | 000,147,456 | ---- | C] () -- C:\windows\System32\igfxCoIn_v1437.dll
[2007/06/08 19:05:38 | 000,274,432 | ---- | C] () -- C:\windows\System32\flcdlmsg.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\windows\System32\pacerprf.ini
[2006/03/09 11:58:00 | 001,060,424 | ---- | C] () -- C:\windows\System32\WdfCoInstaller01000.dll
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\windows\System32\lcppn21.dll
========== LOP Check ==========
[2009/05/04 15:02:45 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ESET
[2010/03/07 13:06:25 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ICQ
[2009/06/25 20:37:09 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\InterVideo
[2010/05/06 14:48:58 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
[2009/07/28 15:57:31 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SolSuite
[2009/05/27 14:50:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TeamViewer
[2010/05/08 10:31:04 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\VitySoft
[2010/05/14 23:42:26 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008/01/21 04:25:56 | 000,202,240 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< MD5 for: AGP440.SYS >
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 04:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 04:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 04:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2008/10/29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 04:24:50 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: HAL.DLL >
[2009/04/11 08:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Windows\System32\hal.dll
< MD5 for: IASTOR.SYS >
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\SwSetup\Drivers\64\HDD\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\SwSetup\Drivers\Global\INTELMSM\Winall\Driver64\IaStor.sys
[2008/04/15 19:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_6917e7b0\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\SwSetup\Drivers\32\HDD\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\SwSetup\Drivers\Global\INTELMSM\Winall\Driver\IaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
[2008/04/15 19:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_054cd65f\iaStor.sys
< MD5 for: IASTORV.SYS >
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 04:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: LSASS.EXE >
[2009/06/15 14:51:56 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=203D86EBD6D8E4C8501B222421E81506 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_a886901f7335e2fc\lsass.exe
[2009/09/10 16:44:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2D3AC5E7AC01E905F3ABD2D745FE3A9B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
[2009/06/15 14:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\System32\lsass.exe
[2009/06/15 14:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_a7fbf30a5a1929db\lsass.exe
[2009/02/13 09:26:04 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=59DE082968FDD257FFF0D209B9A5B460 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[2009/06/15 15:03:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=6F1F23D3599EAE17734451936B7F17C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_a69e1da376115b2a\lsass.exe
[2009/06/15 14:57:59 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A911ECAC81F94ADEAFBE8E3F7873EDB0 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_a600dfae5d0228c9\lsass.exe
[2009/02/13 06:58:37 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=AFF8A58280863629CA4FFA9E0B259F1E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[2009/06/15 14:59:08 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=BA9A67672E025078C77967731BCFC560 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_a4b3e75378eccda6\lsass.exe
[2009/06/15 15:10:12 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=C731B1FE449D4E9CEA358C9D55B69BE9 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_a418a0745fdd652a\lsass.exe
[2009/09/09 13:09:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=CB7E838C140B4087B2DA323F2D4523C5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
[2009/09/10 16:47:51 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=D09A5DA84B7C9CA9B02EBCD7FAE41C8D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[2008/01/21 04:24:43 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\lsass.exe
[2009/02/13 10:20:29 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=F4C62B07E5BF96F1FDCA9DB393ECED22 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe
< MD5 for: NDIS.SYS >
[2009/04/11 08:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009/04/11 08:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2008/01/21 04:24:15 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
[2008/02/08 06:25:28 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=C8560010A542B5DCA94C62468DC20784 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.22110_none_a845f8a63534c8d3\ndis.sys
[2008/02/08 06:22:00 | 000,503,352 | ---- | M] (Microsoft Corporation) MD5=E50187F20ED749F57C97836FEDE14BD6 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.20768_none_a631acb4382f8e4f\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 04:24:31 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 04:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/21 04:25:18 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< MD5 for: SMSS.EXE >
[2008/01/21 04:24:14 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=6701DDAF68BEDE6BBEEA9D514D73A35B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
[2009/04/11 08:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\System32\smss.exe
[2009/04/11 08:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_ae26210916536b06\smss.exe
< MD5 for: SVCHOST.EXE >
[2008/01/21 04:24:10 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/21 04:24:10 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/21 04:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/21 04:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 04:25:17 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008/01/21 04:25:16 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\ws2_32.dll
[2008/01/21 04:25:16 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/04/11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009/04/11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
========== Alternate Data Streams ==========
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
Re: Prosím o kontrolu logu
Extras.Txt:
OTL Extras logfile created on: 15. 5. 2010 13:11:50 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\user\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,88 Gb Total Space | 167,91 Gb Free Space | 75,00% Space Free | Partition Type: NTFS
Drive D: | 9,00 Gb Total Space | 1,63 Gb Free Space | 18,07% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2320732015-1930792971-3522236662-1004]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{D341ADEC-A053-48F1-B064-3DE755A8EDC0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00ECD620-EA84-4377-94F5-2FC43D1803FF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{03B60219-A11A-4A6C-A5A4-E8B8B0E14034}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{065AB7D7-7C56-4D15-867B-D1A9FAA386D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0991E3AB-3AEF-44D0-BA6D-18BACF4E42F1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{146C4A76-D9F7-44CC-AEB3-0EBC85AF16C1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1AF27FC5-6436-41E6-86FB-38CE55A83DAC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1B137436-F81D-45AD-839C-E9504530E2CB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1CBF565C-2FE6-4016-8D1A-B54C5AA8FCF2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1E933B6D-EB19-4334-A317-C5ABABA3C612}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1FEA1B60-2D50-4CB8-B7BA-34C8A184D2CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{238C7AF6-D848-4E11-9B01-65F32774378B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2513A2D5-96DF-4BE0-956A-EFEF5146F62F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{25BBA26B-0759-49CD-A021-FFFE7537B774}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{26597C92-4038-484C-AAEC-4007554A9CC1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{29402865-99F7-45A9-BF22-52F654622345}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2AFA9D61-D83A-4C91-8F45-BE7665DC0833}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{34FECFC3-09AE-430E-B300-E673931C9094}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3719CC5E-4061-4FC3-8F03-5B54E7C6B680}" = protocol=6 | dir=in | app=c:\program files\teamviewer3\teamviewer.exe |
"{377F8030-6F1F-4750-B020-88F2AE5636EA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3803BBDD-DFFD-49B6-99CB-B939E9161214}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{384414AF-7FF8-450C-9780-5B7A33BC00ED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3FBB1F49-A04F-4F1A-8020-37069FD5E3A6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41178EC4-5DD6-4CBD-A408-8BEACF6D19C5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41A1D96A-C070-4221-B4A7-CDE6CA13D2AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41DE32BD-8520-4614-AAE4-D0403282B224}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{444D2EE3-9C0E-47AF-AA21-2DC66174EF3C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4534DFE1-CD2E-4617-BD95-472AE913C8BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{485C8DF3-4F14-40E5-B34E-E20A5EC675D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4D529893-151C-4CCF-A165-815F6D502A83}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4F1AE243-EF64-4842-BCE3-7969EE5EBC1C}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{53FB8348-0F8A-406F-A5B0-745FE203F50B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{54A53AD1-0DED-4797-8533-7660103FA5A3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{599AFF3A-FFE1-4D67-A19A-967CB83F6987}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5B64C6B1-B27E-44BC-947F-0172D179A14F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5C27BAF9-D78B-463D-9AA1-AC2AF4223B5B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{612ADF01-897C-48DE-B972-E214CB10661B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{63509D30-0092-45CA-8F69-B2BFE41CA644}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{637FCBB1-DF17-40FA-A9CD-B360186E2C83}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{655C9CE0-0DC1-4476-9A20-8C420682A4CD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{68E0D815-7C80-43EC-9CB2-5DFE551D2BB8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6BEA6ECA-409C-4F0D-B928-03C80CA0A80E}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{6C0041B0-64F3-4E4D-A9AF-B8BB462B40A3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{70F0F8A2-D2C7-49E5-B704-B82187F415AB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{715EE9D7-5D2A-42CE-9FE0-FFAC9F0E5F22}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{7EBE5462-1941-447E-877F-B3F43C915162}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{8AFB0BD2-8209-48FE-9131-AE2A159F5941}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{91966E54-23E3-404D-8193-CE936307FE19}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93210069-F423-4DD3-A4CF-5E929EE2B2B4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93E6FF39-4DCB-4A1B-94E1-D6ED60A761D6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9888C13B-4FAB-497F-843F-E19A1F0FD8E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E79187F-DE77-450C-B4FE-DEA5B855A2A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A070157D-8992-4989-A90E-EFCC883508CA}" = protocol=17 | dir=in | app=c:\program files\teamviewer3\teamviewer.exe |
"{A0F126EF-41FB-4060-A7EE-87A37FE0D9D1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A9BECB46-3D5D-4025-A3A5-1649026AD028}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AC955468-E618-4A59-B101-2A2FD4F10291}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AC962AD5-3917-4128-8BAA-F1EAAE7A5F2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B1B7CD57-5200-46CE-90E7-B7B853A363E9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B43ACF19-79EC-4B14-B5F4-02B214368906}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B44E7EBC-BEED-4347-88C0-9FBAAFD51BC1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B5C2AFC6-9766-49C2-8E91-5EAB8DE63142}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B930340F-C938-4F4B-B822-87B23C2DCE87}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BACDE189-0116-4AA2-AFD2-A275A98CA286}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BD08FFE8-11DC-4C29-A8B6-5D4BC9BC8776}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C04C9356-643C-4D73-ACE1-66389ECF8F81}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C1CD882F-BCD9-4091-9754-C9C67748E0BB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C71A59EC-7CF6-46EA-9AC7-DECC21FC5488}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C9214761-0F03-459B-AF21-2E02921E5324}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CA469A1F-A533-42E4-8377-7796756153EA}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{D14FBFDB-0AD0-4339-8C3D-62028D9DF93A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D74C44E3-2E72-4A31-A8E5-27C273DBFC90}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DA39AE66-91D0-4162-9F81-F40F05913DF3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DAFAAE7B-F680-4BA2-9A32-53F9471A1010}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DBF38ED2-4FA0-4B06-A7A1-5872A480AB4D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DEA72442-6DE4-47B6-8DAD-1F773DA64F51}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E021B52C-4369-47A7-9F38-953F09D8CE2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E14FEF63-9343-4C28-B60B-B11046A45CEC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E18A9116-08F9-4AFE-BEE3-ACC70F3028EF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E374D68B-FD31-42D2-9A87-525A7DFC7636}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E38216AD-4905-4098-A943-9FE12FC049DA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E5351B21-2C47-4A1E-B142-38AA283A0B62}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E788A67D-427D-413E-BB64-F38D126DEA69}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EC1E4C32-DA06-40A8-96EE-B78419C6F69F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ECBB8DF5-26E9-47A3-91A8-7A445CF59666}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ECE69B8D-DBFC-4628-8C47-5B5281F40E86}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F14F3BC9-C56D-4DDF-BF22-2A1593B3D6C4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F1AA4C31-EAFA-4D8E-B29E-B87D01AAD806}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F1B9E909-6A1A-4963-A5DC-E38CDA5ED0E2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F1EE73D5-D196-439B-B27E-0F17366AD39A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FBD0E0BA-B918-4F96-ABC3-8606BF9EA4BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FF19696C-0358-4DD0-9025-728DFC84668B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{1CBB2257-D242-47D5-A841-887D56F65E57}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{426D70C2-4D06-45B4-97F7-0AD812855CE0}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{0FA9CB33-2ECD-4F8E-BA0C-CA3D65610675}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{49D4B032-6662-493D-AF36-F83895C5B4AB}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6201
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 16
"{2DB165DC-DDB4-403F-B985-19F3EC7D0357}" = HP ProtectTools Security Manager
"{30A2A953-DEB1-466A-B660-F4399C7C6B9D}" = Roxio MyDVD
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 E1
"{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = Mobile Connect
"{420BBA1D-B275-4891-838C-EA88FE87A632}" = HP Customer Experience Enhancements
"{4217C49A-545A-499E-9428-6D61B004A671}" = HP User Guides 0113
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55B52830-024A-443E-AF61-61E1E71AFA1B}" = Device Access Manager for HP ProtectTools
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = HP Software Setup 5.00.A.7
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{8BB128BE-2670-485D-A221-B00715BCEBCF}" = HP Easy Setup - Frontend
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{90120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{938B7504-41A5-42EE-8ECC-5E4B976E8876}" = ESET Smart Security
"{93D44E47-EBE0-43FC-A427-8AC3CD026536}" = Vista Default Settings
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BC1DC565-8B34-4B29-9DB2-BF281C2FB56E}" = ESU for Microsoft Vista SP1
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Business v10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ASIO4ALL" = ASIO4ALL
"Browser Defender_is1" = Browser Defender 2.0.6.11
"CCleaner" = CCleaner
"Collab" = Collab
"Drumaxx" = Drumaxx
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"ICQToolbar" = ICQ Toolbar
"IL Download Manager" = IL Download Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"PDF Complete" = PDF Complete
"PoiZone" = PoiZone
"PROSet" = Intel(R) PRO Network Connections Drivers
"Sakura" = Sakura
"Sawer" = Sawer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SMALLBUSINESS" = Microsoft Office Small Business 2007
"SolSuite_is1" = SolSuite 2009 v9.4
"Spyware Doctor" = Spyware Doctor 7.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 4" = TeamViewer 4
"The KMPlayer" = The KMPlayer (remove only)
"Toxic Biohazard" = Toxic Biohazard
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"Winamp" = Winamp
"WinRAR archiver" = WinRAR
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 9. 5. 2010 11:32:48 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 9. 5. 2010 15:13:38 | Computer Name = user-PC | Source = Windows Search Service | ID = 3024
Description =
Error - 10. 5. 2010 8:05:36 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 13. 5. 2010 15:52:27 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 14. 5. 2010 9:35:26 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
[ OSession Events ]
Error - 30. 4. 2010 2:52:54 | Computer Name = user-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 19
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 14. 5. 2010 10:41:29 | Computer Name = user-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 14. 5. 2010 15:46:04 | Computer Name = user-PC | Source = DCOM | ID = 10010
Description =
Error - 15. 5. 2010 0:18:27 | Computer Name = user-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 15. 5. 2010 0:32:52 | Computer Name = user-PC | Source = disk | ID = 262155
Description = The driver detected a controller error on \...\DR2.
Error - 15. 5. 2010 7:04:28 | Computer Name = user-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 15. 5. 2010 7:04:36 | Computer Name = user-PC | Source = BTHUSB | ID = 327697
Description = Miestny adaptér Bluetooth zlyhal bližšie neurčeným spôsobom a nebude
sa používať. Ovládač bol odstránený z pamäte.
< End of report >
OTL Extras logfile created on: 15. 5. 2010 13:11:50 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\user\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,88 Gb Total Space | 167,91 Gb Free Space | 75,00% Space Free | Partition Type: NTFS
Drive D: | 9,00 Gb Total Space | 1,63 Gb Free Space | 18,07% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2320732015-1930792971-3522236662-1004]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{D341ADEC-A053-48F1-B064-3DE755A8EDC0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00ECD620-EA84-4377-94F5-2FC43D1803FF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{03B60219-A11A-4A6C-A5A4-E8B8B0E14034}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{065AB7D7-7C56-4D15-867B-D1A9FAA386D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0991E3AB-3AEF-44D0-BA6D-18BACF4E42F1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{146C4A76-D9F7-44CC-AEB3-0EBC85AF16C1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1AF27FC5-6436-41E6-86FB-38CE55A83DAC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1B137436-F81D-45AD-839C-E9504530E2CB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1CBF565C-2FE6-4016-8D1A-B54C5AA8FCF2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1E933B6D-EB19-4334-A317-C5ABABA3C612}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1FEA1B60-2D50-4CB8-B7BA-34C8A184D2CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{238C7AF6-D848-4E11-9B01-65F32774378B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2513A2D5-96DF-4BE0-956A-EFEF5146F62F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{25BBA26B-0759-49CD-A021-FFFE7537B774}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{26597C92-4038-484C-AAEC-4007554A9CC1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{29402865-99F7-45A9-BF22-52F654622345}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2AFA9D61-D83A-4C91-8F45-BE7665DC0833}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{34FECFC3-09AE-430E-B300-E673931C9094}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3719CC5E-4061-4FC3-8F03-5B54E7C6B680}" = protocol=6 | dir=in | app=c:\program files\teamviewer3\teamviewer.exe |
"{377F8030-6F1F-4750-B020-88F2AE5636EA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3803BBDD-DFFD-49B6-99CB-B939E9161214}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{384414AF-7FF8-450C-9780-5B7A33BC00ED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3FBB1F49-A04F-4F1A-8020-37069FD5E3A6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41178EC4-5DD6-4CBD-A408-8BEACF6D19C5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41A1D96A-C070-4221-B4A7-CDE6CA13D2AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41DE32BD-8520-4614-AAE4-D0403282B224}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{444D2EE3-9C0E-47AF-AA21-2DC66174EF3C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4534DFE1-CD2E-4617-BD95-472AE913C8BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{485C8DF3-4F14-40E5-B34E-E20A5EC675D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4D529893-151C-4CCF-A165-815F6D502A83}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4F1AE243-EF64-4842-BCE3-7969EE5EBC1C}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{53FB8348-0F8A-406F-A5B0-745FE203F50B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{54A53AD1-0DED-4797-8533-7660103FA5A3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{599AFF3A-FFE1-4D67-A19A-967CB83F6987}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5B64C6B1-B27E-44BC-947F-0172D179A14F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5C27BAF9-D78B-463D-9AA1-AC2AF4223B5B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{612ADF01-897C-48DE-B972-E214CB10661B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{63509D30-0092-45CA-8F69-B2BFE41CA644}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{637FCBB1-DF17-40FA-A9CD-B360186E2C83}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{655C9CE0-0DC1-4476-9A20-8C420682A4CD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{68E0D815-7C80-43EC-9CB2-5DFE551D2BB8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6BEA6ECA-409C-4F0D-B928-03C80CA0A80E}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{6C0041B0-64F3-4E4D-A9AF-B8BB462B40A3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{70F0F8A2-D2C7-49E5-B704-B82187F415AB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{715EE9D7-5D2A-42CE-9FE0-FFAC9F0E5F22}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{7EBE5462-1941-447E-877F-B3F43C915162}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{8AFB0BD2-8209-48FE-9131-AE2A159F5941}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{91966E54-23E3-404D-8193-CE936307FE19}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93210069-F423-4DD3-A4CF-5E929EE2B2B4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93E6FF39-4DCB-4A1B-94E1-D6ED60A761D6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9888C13B-4FAB-497F-843F-E19A1F0FD8E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E79187F-DE77-450C-B4FE-DEA5B855A2A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A070157D-8992-4989-A90E-EFCC883508CA}" = protocol=17 | dir=in | app=c:\program files\teamviewer3\teamviewer.exe |
"{A0F126EF-41FB-4060-A7EE-87A37FE0D9D1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A9BECB46-3D5D-4025-A3A5-1649026AD028}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AC955468-E618-4A59-B101-2A2FD4F10291}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AC962AD5-3917-4128-8BAA-F1EAAE7A5F2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B1B7CD57-5200-46CE-90E7-B7B853A363E9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B43ACF19-79EC-4B14-B5F4-02B214368906}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B44E7EBC-BEED-4347-88C0-9FBAAFD51BC1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B5C2AFC6-9766-49C2-8E91-5EAB8DE63142}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B930340F-C938-4F4B-B822-87B23C2DCE87}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BACDE189-0116-4AA2-AFD2-A275A98CA286}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BD08FFE8-11DC-4C29-A8B6-5D4BC9BC8776}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C04C9356-643C-4D73-ACE1-66389ECF8F81}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C1CD882F-BCD9-4091-9754-C9C67748E0BB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C71A59EC-7CF6-46EA-9AC7-DECC21FC5488}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C9214761-0F03-459B-AF21-2E02921E5324}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CA469A1F-A533-42E4-8377-7796756153EA}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{D14FBFDB-0AD0-4339-8C3D-62028D9DF93A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D74C44E3-2E72-4A31-A8E5-27C273DBFC90}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DA39AE66-91D0-4162-9F81-F40F05913DF3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DAFAAE7B-F680-4BA2-9A32-53F9471A1010}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DBF38ED2-4FA0-4B06-A7A1-5872A480AB4D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DEA72442-6DE4-47B6-8DAD-1F773DA64F51}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E021B52C-4369-47A7-9F38-953F09D8CE2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E14FEF63-9343-4C28-B60B-B11046A45CEC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E18A9116-08F9-4AFE-BEE3-ACC70F3028EF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E374D68B-FD31-42D2-9A87-525A7DFC7636}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E38216AD-4905-4098-A943-9FE12FC049DA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E5351B21-2C47-4A1E-B142-38AA283A0B62}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E788A67D-427D-413E-BB64-F38D126DEA69}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EC1E4C32-DA06-40A8-96EE-B78419C6F69F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ECBB8DF5-26E9-47A3-91A8-7A445CF59666}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ECE69B8D-DBFC-4628-8C47-5B5281F40E86}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F14F3BC9-C56D-4DDF-BF22-2A1593B3D6C4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F1AA4C31-EAFA-4D8E-B29E-B87D01AAD806}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F1B9E909-6A1A-4963-A5DC-E38CDA5ED0E2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F1EE73D5-D196-439B-B27E-0F17366AD39A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FBD0E0BA-B918-4F96-ABC3-8606BF9EA4BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FF19696C-0358-4DD0-9025-728DFC84668B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{1CBB2257-D242-47D5-A841-887D56F65E57}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{426D70C2-4D06-45B4-97F7-0AD812855CE0}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{0FA9CB33-2ECD-4F8E-BA0C-CA3D65610675}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{49D4B032-6662-493D-AF36-F83895C5B4AB}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6201
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 16
"{2DB165DC-DDB4-403F-B985-19F3EC7D0357}" = HP ProtectTools Security Manager
"{30A2A953-DEB1-466A-B660-F4399C7C6B9D}" = Roxio MyDVD
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 E1
"{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = Mobile Connect
"{420BBA1D-B275-4891-838C-EA88FE87A632}" = HP Customer Experience Enhancements
"{4217C49A-545A-499E-9428-6D61B004A671}" = HP User Guides 0113
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55B52830-024A-443E-AF61-61E1E71AFA1B}" = Device Access Manager for HP ProtectTools
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = HP Software Setup 5.00.A.7
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{8BB128BE-2670-485D-A221-B00715BCEBCF}" = HP Easy Setup - Frontend
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{90120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{938B7504-41A5-42EE-8ECC-5E4B976E8876}" = ESET Smart Security
"{93D44E47-EBE0-43FC-A427-8AC3CD026536}" = Vista Default Settings
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BC1DC565-8B34-4B29-9DB2-BF281C2FB56E}" = ESU for Microsoft Vista SP1
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Business v10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ASIO4ALL" = ASIO4ALL
"Browser Defender_is1" = Browser Defender 2.0.6.11
"CCleaner" = CCleaner
"Collab" = Collab
"Drumaxx" = Drumaxx
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"ICQToolbar" = ICQ Toolbar
"IL Download Manager" = IL Download Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"PDF Complete" = PDF Complete
"PoiZone" = PoiZone
"PROSet" = Intel(R) PRO Network Connections Drivers
"Sakura" = Sakura
"Sawer" = Sawer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SMALLBUSINESS" = Microsoft Office Small Business 2007
"SolSuite_is1" = SolSuite 2009 v9.4
"Spyware Doctor" = Spyware Doctor 7.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 4" = TeamViewer 4
"The KMPlayer" = The KMPlayer (remove only)
"Toxic Biohazard" = Toxic Biohazard
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"Winamp" = Winamp
"WinRAR archiver" = WinRAR
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 9. 5. 2010 11:31:31 | Computer Name = user-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 9. 5. 2010 11:32:48 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 9. 5. 2010 15:13:38 | Computer Name = user-PC | Source = Windows Search Service | ID = 3024
Description =
Error - 10. 5. 2010 8:05:36 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 13. 5. 2010 15:52:27 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 14. 5. 2010 9:35:26 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = WinMgmt | ID = 10
Description =
[ OSession Events ]
Error - 30. 4. 2010 2:52:54 | Computer Name = user-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 19
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 14. 5. 2010 10:41:29 | Computer Name = user-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 14. 5. 2010 10:42:14 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 14. 5. 2010 15:46:04 | Computer Name = user-PC | Source = DCOM | ID = 10010
Description =
Error - 15. 5. 2010 0:18:27 | Computer Name = user-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 15. 5. 2010 0:19:22 | Computer Name = user-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 15. 5. 2010 0:32:52 | Computer Name = user-PC | Source = disk | ID = 262155
Description = The driver detected a controller error on \...\DR2.
Error - 15. 5. 2010 7:04:28 | Computer Name = user-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 15. 5. 2010 7:04:36 | Computer Name = user-PC | Source = BTHUSB | ID = 327697
Description = Miestny adaptér Bluetooth zlyhal bližšie neurčeným spôsobom a nebude
sa používať. Ovládač bol odstránený z pamäte.
< End of report >
Re: Prosím o kontrolu logu

-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2320732015-1930792971-3522236662-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
:commands
[emptytemp]
[EMPTYFLASH]
[Reboot]
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde


-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Program Files\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: "http://search.icq.com/search/afe_result ... id=afex&q=" removed from keyword.URL
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3255.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3A41.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP862F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD6AF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE4F1.tmp folder moved successfully.
C:\WINDOWS\Temp\HTT100B.tmp moved successfully.
C:\WINDOWS\Temp\HTT103A.tmp moved successfully.
C:\WINDOWS\Temp\HTT104B.tmp moved successfully.
C:\WINDOWS\Temp\HTT105C.tmp moved successfully.
C:\WINDOWS\Temp\HTT106C.tmp moved successfully.
C:\WINDOWS\Temp\HTT108C.tmp moved successfully.
C:\WINDOWS\Temp\HTT109F.tmp moved successfully.
C:\WINDOWS\Temp\HTT10A6.tmp moved successfully.
C:\WINDOWS\Temp\HTT10BF.tmp moved successfully.
C:\WINDOWS\Temp\HTT10D0.tmp moved successfully.
C:\WINDOWS\Temp\HTT10F0.tmp moved successfully.
C:\WINDOWS\Temp\HTT1110.tmp moved successfully.
C:\WINDOWS\Temp\HTT1121.tmp moved successfully.
C:\WINDOWS\Temp\HTT1131.tmp moved successfully.
C:\WINDOWS\Temp\HTT1152.tmp moved successfully.
C:\WINDOWS\Temp\HTT1162.tmp moved successfully.
C:\WINDOWS\Temp\HTT1173.tmp moved successfully.
C:\WINDOWS\Temp\HTT1183.tmp moved successfully.
C:\WINDOWS\Temp\HTT1185.tmp moved successfully.
C:\WINDOWS\Temp\HTT1194.tmp moved successfully.
C:\WINDOWS\Temp\HTT11A5.tmp moved successfully.
C:\WINDOWS\Temp\HTT124C.tmp moved successfully.
C:\WINDOWS\Temp\HTT13CF.tmp moved successfully.
C:\WINDOWS\Temp\HTT1611.tmp moved successfully.
C:\WINDOWS\Temp\HTT163B.tmp moved successfully.
C:\WINDOWS\Temp\HTT17CA.tmp moved successfully.
C:\WINDOWS\Temp\HTT1941.tmp moved successfully.
C:\WINDOWS\Temp\HTT1957.tmp moved successfully.
C:\WINDOWS\Temp\HTT19D8.tmp moved successfully.
C:\WINDOWS\Temp\HTT1B17.tmp moved successfully.
C:\WINDOWS\Temp\HTT1B2A.tmp moved successfully.
C:\WINDOWS\Temp\HTT1CF5.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D5F.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D75.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D7A.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D9B.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E38.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E3E.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E81.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E92.tmp moved successfully.
C:\WINDOWS\Temp\HTT1F7D.tmp moved successfully.
C:\WINDOWS\Temp\HTT1FBC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2186.tmp moved successfully.
C:\WINDOWS\Temp\HTT2196.tmp moved successfully.
C:\WINDOWS\Temp\HTT22EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT231F.tmp moved successfully.
C:\WINDOWS\Temp\HTT243E.tmp moved successfully.
C:\WINDOWS\Temp\HTT24EB.tmp moved successfully.
C:\WINDOWS\Temp\HTT2506.tmp moved successfully.
C:\WINDOWS\Temp\HTT250E.tmp moved successfully.
C:\WINDOWS\Temp\HTT25A4.tmp moved successfully.
C:\WINDOWS\Temp\HTT25B4.tmp moved successfully.
C:\WINDOWS\Temp\HTT25D5.tmp moved successfully.
C:\WINDOWS\Temp\HTT25EC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2618.tmp moved successfully.
C:\WINDOWS\Temp\HTT262A.tmp moved successfully.
C:\WINDOWS\Temp\HTT265A.tmp moved successfully.
C:\WINDOWS\Temp\HTT2671.tmp moved successfully.
C:\WINDOWS\Temp\HTT26CE.tmp moved successfully.
C:\WINDOWS\Temp\HTT2711.tmp moved successfully.
C:\WINDOWS\Temp\HTT2760.tmp moved successfully.
C:\WINDOWS\Temp\HTT27A0.tmp moved successfully.
C:\WINDOWS\Temp\HTT288D.tmp moved successfully.
C:\WINDOWS\Temp\HTT289A.tmp moved successfully.
C:\WINDOWS\Temp\HTT28A4.tmp moved successfully.
C:\WINDOWS\Temp\HTT2907.tmp moved successfully.
C:\WINDOWS\Temp\HTT299F.tmp moved successfully.
C:\WINDOWS\Temp\HTT2ADD.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B0B.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B95.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B96.tmp moved successfully.
C:\WINDOWS\Temp\HTT2C28.tmp moved successfully.
C:\WINDOWS\Temp\HTT2C57.tmp moved successfully.
C:\WINDOWS\Temp\HTT2CA9.tmp moved successfully.
C:\WINDOWS\Temp\HTT2D6E.tmp moved successfully.
C:\WINDOWS\Temp\HTT2D8C.tmp moved successfully.
C:\WINDOWS\Temp\HTT2DDD.tmp moved successfully.
C:\WINDOWS\Temp\HTT2DFC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2FD6.tmp moved successfully.
C:\WINDOWS\Temp\HTT300D.tmp moved successfully.
C:\WINDOWS\Temp\HTT311B.tmp moved successfully.
C:\WINDOWS\Temp\HTT3270.tmp moved successfully.
C:\WINDOWS\Temp\HTT3365.tmp moved successfully.
C:\WINDOWS\Temp\HTT3378.tmp moved successfully.
C:\WINDOWS\Temp\HTT3483.tmp moved successfully.
C:\WINDOWS\Temp\HTT352F.tmp moved successfully.
C:\WINDOWS\Temp\HTT358C.tmp moved successfully.
C:\WINDOWS\Temp\HTT35AD.tmp moved successfully.
C:\WINDOWS\Temp\HTT370.tmp moved successfully.
C:\WINDOWS\Temp\HTT3720.tmp moved successfully.
C:\WINDOWS\Temp\HTT3733.tmp moved successfully.
C:\WINDOWS\Temp\HTT3969.tmp moved successfully.
C:\WINDOWS\Temp\HTT39B2.tmp moved successfully.
C:\WINDOWS\Temp\HTT3A8B.tmp moved successfully.
C:\WINDOWS\Temp\HTT3B11.tmp moved successfully.
C:\WINDOWS\Temp\HTT3BAF.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C30.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C31.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C6E.tmp moved successfully.
C:\WINDOWS\Temp\HTT3CD2.tmp moved successfully.
C:\WINDOWS\Temp\HTT3D3A.tmp moved successfully.
C:\WINDOWS\Temp\HTT3D7D.tmp moved successfully.
C:\WINDOWS\Temp\HTT40BC.tmp moved successfully.
C:\WINDOWS\Temp\HTT40C6.tmp moved successfully.
C:\WINDOWS\Temp\HTT40ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT40EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT4110.tmp moved successfully.
C:\WINDOWS\Temp\HTT4111.tmp moved successfully.
C:\WINDOWS\Temp\HTT4122.tmp moved successfully.
C:\WINDOWS\Temp\HTT4133.tmp moved successfully.
C:\WINDOWS\Temp\HTT4143.tmp moved successfully.
C:\WINDOWS\Temp\HTT4163.tmp moved successfully.
C:\WINDOWS\Temp\HTT4174.tmp moved successfully.
C:\WINDOWS\Temp\HTT4185.tmp moved successfully.
C:\WINDOWS\Temp\HTT4186.tmp moved successfully.
C:\WINDOWS\Temp\HTT41A6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41C4.tmp moved successfully.
C:\WINDOWS\Temp\HTT41C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT41D8.tmp moved successfully.
C:\WINDOWS\Temp\HTT41E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41E8.tmp moved successfully.
C:\WINDOWS\Temp\HTT41F9.tmp moved successfully.
C:\WINDOWS\Temp\HTT4219.tmp moved successfully.
C:\WINDOWS\Temp\HTT422A.tmp moved successfully.
C:\WINDOWS\Temp\HTT423A.tmp moved successfully.
C:\WINDOWS\Temp\HTT424B.tmp moved successfully.
C:\WINDOWS\Temp\HTT426B.tmp moved successfully.
C:\WINDOWS\Temp\HTT4270.tmp moved successfully.
C:\WINDOWS\Temp\HTT42EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT4460.tmp moved successfully.
C:\WINDOWS\Temp\HTT45AD.tmp moved successfully.
C:\WINDOWS\Temp\HTT45B8.tmp moved successfully.
C:\WINDOWS\Temp\HTT46F3.tmp moved successfully.
C:\WINDOWS\Temp\HTT46F4.tmp moved successfully.
C:\WINDOWS\Temp\HTT481.tmp moved successfully.
C:\WINDOWS\Temp\HTT4921.tmp moved successfully.
C:\WINDOWS\Temp\HTT496.tmp moved successfully.
C:\WINDOWS\Temp\HTT4A34.tmp moved successfully.
C:\WINDOWS\Temp\HTT4AA1.tmp moved successfully.
C:\WINDOWS\Temp\HTT4C24.tmp moved successfully.
C:\WINDOWS\Temp\HTT4CE1.tmp moved successfully.
C:\WINDOWS\Temp\HTT4DCA.tmp moved successfully.
C:\WINDOWS\Temp\HTT4DDD.tmp moved successfully.
C:\WINDOWS\Temp\HTT4EB4.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F06.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F17.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F27.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F28.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F39.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F49.tmp moved successfully.
C:\WINDOWS\Temp\HTT4FBC.tmp moved successfully.
C:\WINDOWS\Temp\HTT52D.tmp moved successfully.
C:\WINDOWS\Temp\HTT53B.tmp moved successfully.
C:\WINDOWS\Temp\HTT5460.tmp moved successfully.
C:\WINDOWS\Temp\HTT5581.tmp moved successfully.
C:\WINDOWS\Temp\HTT55D2.tmp moved successfully.
C:\WINDOWS\Temp\HTT56CE.tmp moved successfully.
C:\WINDOWS\Temp\HTT57ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT57FE.tmp moved successfully.
C:\WINDOWS\Temp\HTT582D.tmp moved successfully.
C:\WINDOWS\Temp\HTT58FA.tmp moved successfully.
C:\WINDOWS\Temp\HTT590B.tmp moved successfully.
C:\WINDOWS\Temp\HTT5B52.tmp moved successfully.
C:\WINDOWS\Temp\HTT5CA2.tmp moved successfully.
C:\WINDOWS\Temp\HTT5DB8.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E47.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E65.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E7.tmp moved successfully.
C:\WINDOWS\Temp\HTT5F32.tmp moved successfully.
C:\WINDOWS\Temp\HTT5F61.tmp moved successfully.
C:\WINDOWS\Temp\HTT6069.tmp moved successfully.
C:\WINDOWS\Temp\HTT607C.tmp moved successfully.
C:\WINDOWS\Temp\HTT60F2.tmp moved successfully.
C:\WINDOWS\Temp\HTT61DF.tmp moved successfully.
C:\WINDOWS\Temp\HTT625C.tmp moved successfully.
C:\WINDOWS\Temp\HTT6261.tmp moved successfully.
C:\WINDOWS\Temp\HTT626D.tmp moved successfully.
C:\WINDOWS\Temp\HTT627.tmp moved successfully.
C:\WINDOWS\Temp\HTT633.tmp moved successfully.
C:\WINDOWS\Temp\HTT63D.tmp moved successfully.
C:\WINDOWS\Temp\HTT63E3.tmp moved successfully.
C:\WINDOWS\Temp\HTT64.tmp moved successfully.
C:\WINDOWS\Temp\HTT6455.tmp moved successfully.
C:\WINDOWS\Temp\HTT64F.tmp moved successfully.
C:\WINDOWS\Temp\HTT6537.tmp moved successfully.
C:\WINDOWS\Temp\HTT6638.tmp moved successfully.
C:\WINDOWS\Temp\HTT66B4.tmp moved successfully.
C:\WINDOWS\Temp\HTT6808.tmp moved successfully.
C:\WINDOWS\Temp\HTT69E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT6A21.tmp moved successfully.
C:\WINDOWS\Temp\HTT6B05.tmp moved successfully.
C:\WINDOWS\Temp\HTT6C58.tmp moved successfully.
C:\WINDOWS\Temp\HTT6D4.tmp moved successfully.
C:\WINDOWS\Temp\HTT6DE2.tmp moved successfully.
C:\WINDOWS\Temp\HTT6FB0.tmp moved successfully.
C:\WINDOWS\Temp\HTT70AA.tmp moved successfully.
C:\WINDOWS\Temp\HTT71EA.tmp moved successfully.
C:\WINDOWS\Temp\HTT71FA.tmp moved successfully.
C:\WINDOWS\Temp\HTT72C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT7335.tmp moved successfully.
C:\WINDOWS\Temp\HTT73F1.tmp moved successfully.
C:\WINDOWS\Temp\HTT7535.tmp moved successfully.
C:\WINDOWS\Temp\HTT754.tmp moved successfully.
C:\WINDOWS\Temp\HTT75EB.tmp moved successfully.
C:\WINDOWS\Temp\HTT76C3.tmp moved successfully.
C:\WINDOWS\Temp\HTT7732.tmp moved successfully.
C:\WINDOWS\Temp\HTT7733.tmp moved successfully.
C:\WINDOWS\Temp\HTT7744.tmp moved successfully.
C:\WINDOWS\Temp\HTT778A.tmp moved successfully.
C:\WINDOWS\Temp\HTT77AB.tmp moved successfully.
C:\WINDOWS\Temp\HTT78ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT79B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A11.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A12.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A93.tmp moved successfully.
C:\WINDOWS\Temp\HTT7BA8.tmp moved successfully.
C:\WINDOWS\Temp\HTT7BCD.tmp moved successfully.
C:\WINDOWS\Temp\HTT7C06.tmp moved successfully.
C:\WINDOWS\Temp\HTT7CE4.tmp moved successfully.
C:\WINDOWS\Temp\HTT7D4.tmp moved successfully.
C:\WINDOWS\Temp\HTT7D59.tmp moved successfully.
C:\WINDOWS\Temp\HTT7E1F.tmp moved successfully.
C:\WINDOWS\Temp\HTT7EAB.tmp moved successfully.
C:\WINDOWS\Temp\HTT7ED1.tmp moved successfully.
C:\WINDOWS\Temp\HTT7F25.tmp moved successfully.
C:\WINDOWS\Temp\HTT7F49.tmp moved successfully.
C:\WINDOWS\Temp\HTT7FB1.tmp moved successfully.
C:\WINDOWS\Temp\HTT8001.tmp moved successfully.
C:\WINDOWS\Temp\HTT8085.tmp moved successfully.
C:\WINDOWS\Temp\HTT8089.tmp moved successfully.
C:\WINDOWS\Temp\HTT8160.tmp moved successfully.
C:\WINDOWS\Temp\HTT8180.tmp moved successfully.
C:\WINDOWS\Temp\HTT8181.tmp moved successfully.
C:\WINDOWS\Temp\HTT81C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT8534.tmp moved successfully.
C:\WINDOWS\Temp\HTT8565.tmp moved successfully.
C:\WINDOWS\Temp\HTT86FE.tmp moved successfully.
C:\WINDOWS\Temp\HTT86FF.tmp moved successfully.
C:\WINDOWS\Temp\HTT872A.tmp moved successfully.
C:\WINDOWS\Temp\HTT87CD.tmp moved successfully.
C:\WINDOWS\Temp\HTT8816.tmp moved successfully.
C:\WINDOWS\Temp\HTT8894.tmp moved successfully.
C:\WINDOWS\Temp\HTT8896.tmp moved successfully.
C:\WINDOWS\Temp\HTT88B2.tmp moved successfully.
C:\WINDOWS\Temp\HTT891E.tmp moved successfully.
C:\WINDOWS\Temp\HTT8923.tmp moved successfully.
C:\WINDOWS\Temp\HTT8925.tmp moved successfully.
C:\WINDOWS\Temp\HTT8974.tmp moved successfully.
C:\WINDOWS\Temp\HTT89E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT8CA6.tmp moved successfully.
C:\WINDOWS\Temp\HTT8DE5.tmp moved successfully.
C:\WINDOWS\Temp\HTT8DFD.tmp moved successfully.
C:\WINDOWS\Temp\HTT908D.tmp moved successfully.
C:\WINDOWS\Temp\HTT9095.tmp moved successfully.
C:\WINDOWS\Temp\HTT90AE.tmp moved successfully.
C:\WINDOWS\Temp\HTT90E7.tmp moved successfully.
C:\WINDOWS\Temp\HTT912E.tmp moved successfully.
C:\WINDOWS\Temp\HTT9179.tmp moved successfully.
C:\WINDOWS\Temp\HTT9419.tmp moved successfully.
C:\WINDOWS\Temp\HTT94B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT9641.tmp moved successfully.
C:\WINDOWS\Temp\HTT971A.tmp moved successfully.
C:\WINDOWS\Temp\HTT9799.tmp moved successfully.
C:\WINDOWS\Temp\HTT97C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT9822.tmp moved successfully.
C:\WINDOWS\Temp\HTT99D3.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A54.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A7E.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A8B.tmp moved successfully.
C:\WINDOWS\Temp\HTT9D49.tmp moved successfully.
C:\WINDOWS\Temp\HTTA0AD.tmp moved successfully.
C:\WINDOWS\Temp\HTTA14A.tmp moved successfully.
C:\WINDOWS\Temp\HTTA26D.tmp moved successfully.
C:\WINDOWS\Temp\HTTA43B.tmp moved successfully.
C:\WINDOWS\Temp\HTTA59.tmp moved successfully.
C:\WINDOWS\Temp\HTTA594.tmp moved successfully.
C:\WINDOWS\Temp\HTTA75A.tmp moved successfully.
C:\WINDOWS\Temp\HTTA78E.tmp moved successfully.
C:\WINDOWS\Temp\HTTA7DD.tmp moved successfully.
C:\WINDOWS\Temp\HTTA7F2.tmp moved successfully.
C:\WINDOWS\Temp\HTTA810.tmp moved successfully.
C:\WINDOWS\Temp\HTTA851.tmp moved successfully.
C:\WINDOWS\Temp\HTTAA92.tmp moved successfully.
C:\WINDOWS\Temp\HTTAB16.tmp moved successfully.
C:\WINDOWS\Temp\HTTAB50.tmp moved successfully.
C:\WINDOWS\Temp\HTTABFD.tmp moved successfully.
C:\WINDOWS\Temp\HTTAC7F.tmp moved successfully.
C:\WINDOWS\Temp\HTTACD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTACE5.tmp moved successfully.
C:\WINDOWS\Temp\HTTAD47.tmp moved successfully.
C:\WINDOWS\Temp\HTTADFB.tmp moved successfully.
C:\WINDOWS\Temp\HTTAE30.tmp moved successfully.
C:\WINDOWS\Temp\HTTAEF2.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF16.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF26.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF2D.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF46.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF4D.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF4F.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF62.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF67.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF77.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF97.tmp moved successfully.
C:\WINDOWS\Temp\HTTAFA8.tmp moved successfully.
C:\WINDOWS\Temp\HTTAFD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTB058.tmp moved successfully.
C:\WINDOWS\Temp\HTTB07A.tmp moved successfully.
C:\WINDOWS\Temp\HTTB107.tmp moved successfully.
C:\WINDOWS\Temp\HTTB182.tmp moved successfully.
C:\WINDOWS\Temp\HTTB31F.tmp moved successfully.
C:\WINDOWS\Temp\HTTB4C6.tmp moved successfully.
C:\WINDOWS\Temp\HTTB573.tmp moved successfully.
C:\WINDOWS\Temp\HTTB574.tmp moved successfully.
C:\WINDOWS\Temp\HTTB596.tmp moved successfully.
C:\WINDOWS\Temp\HTTB597.tmp moved successfully.
C:\WINDOWS\Temp\HTTB71B.tmp moved successfully.
C:\WINDOWS\Temp\HTTB72C.tmp moved successfully.
C:\WINDOWS\Temp\HTTB777.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7A0.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7B0.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7C1.tmp moved successfully.
C:\WINDOWS\Temp\HTTB945.tmp moved successfully.
C:\WINDOWS\Temp\HTTBA04.tmp moved successfully.
C:\WINDOWS\Temp\HTTBA95.tmp moved successfully.
C:\WINDOWS\Temp\HTTBC75.tmp moved successfully.
C:\WINDOWS\Temp\HTTBCC.tmp moved successfully.
C:\WINDOWS\Temp\HTTBE51.tmp moved successfully.
C:\WINDOWS\Temp\HTTBE6E.tmp moved successfully.
C:\WINDOWS\Temp\HTTC26D.tmp moved successfully.
C:\WINDOWS\Temp\HTTC2F0.tmp moved successfully.
C:\WINDOWS\Temp\HTTC352.tmp moved successfully.
C:\WINDOWS\Temp\HTTC6B8.tmp moved successfully.
C:\WINDOWS\Temp\HTTC716.tmp moved successfully.
C:\WINDOWS\Temp\HTTCBA4.tmp moved successfully.
C:\WINDOWS\Temp\HTTCD71.tmp moved successfully.
C:\WINDOWS\Temp\HTTCDB2.tmp moved successfully.
C:\WINDOWS\Temp\HTTCE90.tmp moved successfully.
C:\WINDOWS\Temp\HTTCFC0.tmp moved successfully.
C:\WINDOWS\Temp\HTTCFF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTD0C3.tmp moved successfully.
C:\WINDOWS\Temp\HTTD16E.tmp moved successfully.
C:\WINDOWS\Temp\HTTD1AB.tmp moved successfully.
C:\WINDOWS\Temp\HTTD1DF.tmp moved successfully.
C:\WINDOWS\Temp\HTTD357.tmp moved successfully.
C:\WINDOWS\Temp\HTTD3B1.tmp moved successfully.
C:\WINDOWS\Temp\HTTD49A.tmp moved successfully.
C:\WINDOWS\Temp\HTTD67.tmp moved successfully.
C:\WINDOWS\Temp\HTTD682.tmp moved successfully.
C:\WINDOWS\Temp\HTTD837.tmp moved successfully.
C:\WINDOWS\Temp\HTTD8EC.tmp moved successfully.
C:\WINDOWS\Temp\HTTD9AC.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAC9.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAFD.tmp moved successfully.
C:\WINDOWS\Temp\HTTDB88.tmp moved successfully.
C:\WINDOWS\Temp\HTTDE12.tmp moved successfully.
C:\WINDOWS\Temp\HTTDE98.tmp moved successfully.
C:\WINDOWS\Temp\HTTDF6C.tmp moved successfully.
C:\WINDOWS\Temp\HTTE186.tmp moved successfully.
C:\WINDOWS\Temp\HTTE21A.tmp moved successfully.
C:\WINDOWS\Temp\HTTE308.tmp moved successfully.
C:\WINDOWS\Temp\HTTE384.tmp moved successfully.
C:\WINDOWS\Temp\HTTE3E.tmp moved successfully.
C:\WINDOWS\Temp\HTTE7B5.tmp moved successfully.
C:\WINDOWS\Temp\HTTE7F5.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB03.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB83.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB9.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB9C.tmp moved successfully.
C:\WINDOWS\Temp\HTTED23.tmp moved successfully.
C:\WINDOWS\Temp\HTTED42.tmp moved successfully.
C:\WINDOWS\Temp\HTTED4D.tmp moved successfully.
C:\WINDOWS\Temp\HTTED52.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDEC.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDF3.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDFF.tmp moved successfully.
C:\WINDOWS\Temp\HTTEE7D.tmp moved successfully.
C:\WINDOWS\Temp\HTTEEFB.tmp moved successfully.
C:\WINDOWS\Temp\HTTF255.tmp moved successfully.
C:\WINDOWS\Temp\HTTF273.tmp moved successfully.
C:\WINDOWS\Temp\HTTF306.tmp moved successfully.
C:\WINDOWS\Temp\HTTF374.tmp moved successfully.
C:\WINDOWS\Temp\HTTF4F4.tmp moved successfully.
C:\WINDOWS\Temp\HTTF5D7.tmp moved successfully.
C:\WINDOWS\Temp\HTTF664.tmp moved successfully.
C:\WINDOWS\Temp\HTTF66B.tmp moved successfully.
C:\WINDOWS\Temp\HTTF6C1.tmp moved successfully.
C:\WINDOWS\Temp\HTTF896.tmp moved successfully.
C:\WINDOWS\Temp\HTTF8DE.tmp moved successfully.
C:\WINDOWS\Temp\HTTFA90.tmp moved successfully.
C:\WINDOWS\Temp\HTTFADC.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC02.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC8.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCC7.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFD17.tmp moved successfully.
C:\WINDOWS\Temp\HTTFD6C.tmp moved successfully.
C:\WINDOWS\Temp\HTTFE9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFECE.tmp moved successfully.
C:\WINDOWS\Temp\HTTFEF2.tmp moved successfully.
C:\WINDOWS\Temp\HTTFF90.tmp moved successfully.
C:\WINDOWS\Temp\HTTFFA.tmp moved successfully.
C:\WINDOWS\Temp\NOD1073.tmp moved successfully.
C:\WINDOWS\Temp\NOD118D.tmp moved successfully.
C:\WINDOWS\Temp\NOD127F.tmp moved successfully.
C:\WINDOWS\Temp\NOD16CB.tmp moved successfully.
C:\WINDOWS\Temp\NOD1A0C.tmp moved successfully.
C:\WINDOWS\Temp\NOD1BD7.tmp moved successfully.
C:\WINDOWS\Temp\NOD1DB2.tmp moved successfully.
C:\WINDOWS\Temp\NOD208E.tmp moved successfully.
C:\WINDOWS\Temp\NOD2131.tmp moved successfully.
C:\WINDOWS\Temp\NOD244C.tmp moved successfully.
C:\WINDOWS\Temp\NOD255B.tmp moved successfully.
C:\WINDOWS\Temp\NOD2730.tmp moved successfully.
C:\WINDOWS\Temp\NOD2BD0.tmp moved successfully.
C:\WINDOWS\Temp\NOD3004.tmp moved successfully.
C:\WINDOWS\Temp\NOD3086.tmp moved successfully.
C:\WINDOWS\Temp\NOD311.tmp moved successfully.
C:\WINDOWS\Temp\NOD3549.tmp moved successfully.
C:\WINDOWS\Temp\NOD39DA.tmp moved successfully.
C:\WINDOWS\Temp\NOD3B8A.tmp moved successfully.
C:\WINDOWS\Temp\NOD3DD6.tmp moved successfully.
C:\WINDOWS\Temp\NOD3F57.tmp moved successfully.
C:\WINDOWS\Temp\NOD3FA9.tmp moved successfully.
C:\WINDOWS\Temp\NOD3FD9.tmp moved successfully.
C:\WINDOWS\Temp\NOD4251.tmp moved successfully.
C:\WINDOWS\Temp\NOD45B2.tmp moved successfully.
C:\WINDOWS\Temp\NOD473D.tmp moved successfully.
C:\WINDOWS\Temp\NOD484B.tmp moved successfully.
C:\WINDOWS\Temp\NOD4B4A.tmp moved successfully.
C:\WINDOWS\Temp\NOD4E73.tmp moved successfully.
C:\WINDOWS\Temp\NOD4F5A.tmp moved successfully.
C:\WINDOWS\Temp\NOD5154.tmp moved successfully.
C:\WINDOWS\Temp\NOD5933.tmp moved successfully.
C:\WINDOWS\Temp\NOD5B07.tmp moved successfully.
C:\WINDOWS\Temp\NOD5C98.tmp moved successfully.
C:\WINDOWS\Temp\NOD5D3.tmp moved successfully.
C:\WINDOWS\Temp\NOD5F29.tmp moved successfully.
C:\WINDOWS\Temp\NOD6049.tmp moved successfully.
C:\WINDOWS\Temp\NOD66D6.tmp moved successfully.
C:\WINDOWS\Temp\NOD6737.tmp moved successfully.
C:\WINDOWS\Temp\NOD68A1.tmp moved successfully.
C:\WINDOWS\Temp\NOD6AD7.tmp moved successfully.
C:\WINDOWS\Temp\NOD6C04.tmp moved successfully.
C:\WINDOWS\Temp\NOD6CC1.tmp moved successfully.
C:\WINDOWS\Temp\NOD6E47.tmp moved successfully.
C:\WINDOWS\Temp\NOD740A.tmp moved successfully.
C:\WINDOWS\Temp\NOD74B0.tmp moved successfully.
C:\WINDOWS\Temp\NOD755F.tmp moved successfully.
C:\WINDOWS\Temp\NOD7674.tmp moved successfully.
C:\WINDOWS\Temp\NOD7778.tmp moved successfully.
C:\WINDOWS\Temp\NOD7C4.tmp moved successfully.
C:\WINDOWS\Temp\NOD7E08.tmp moved successfully.
C:\WINDOWS\Temp\NOD83FF.tmp moved successfully.
C:\WINDOWS\Temp\NOD85F1.tmp moved successfully.
C:\WINDOWS\Temp\NOD8672.tmp moved successfully.
C:\WINDOWS\Temp\NOD8761.tmp moved successfully.
C:\WINDOWS\Temp\NOD8A0E.tmp moved successfully.
C:\WINDOWS\Temp\NOD8AAD.tmp moved successfully.
C:\WINDOWS\Temp\NOD8B50.tmp moved successfully.
C:\WINDOWS\Temp\NOD8C7D.tmp moved successfully.
C:\WINDOWS\Temp\NOD8DF.tmp moved successfully.
C:\WINDOWS\Temp\NOD8F86.tmp moved successfully.
C:\WINDOWS\Temp\NOD90DC.tmp moved successfully.
C:\WINDOWS\Temp\NOD9109.tmp moved successfully.
C:\WINDOWS\Temp\NOD912F.tmp moved successfully.
C:\WINDOWS\Temp\NOD9526.tmp moved successfully.
C:\WINDOWS\Temp\NOD983C.tmp moved successfully.
C:\WINDOWS\Temp\NOD9B2B.tmp moved successfully.
C:\WINDOWS\Temp\NODA24D.tmp moved successfully.
C:\WINDOWS\Temp\NODA2CE.tmp moved successfully.
C:\WINDOWS\Temp\NODA3BA.tmp moved successfully.
C:\WINDOWS\Temp\NODA40C.tmp moved successfully.
C:\WINDOWS\Temp\NODAF82.tmp moved successfully.
C:\WINDOWS\Temp\NODB003.tmp moved successfully.
C:\WINDOWS\Temp\NODB0EC.tmp moved successfully.
C:\WINDOWS\Temp\NODB113.tmp moved successfully.
C:\WINDOWS\Temp\NODB219.tmp moved successfully.
C:\WINDOWS\Temp\NODB698.tmp moved successfully.
C:\WINDOWS\Temp\NODB792.tmp moved successfully.
C:\WINDOWS\Temp\NODBD3.tmp moved successfully.
C:\WINDOWS\Temp\NODBE2D.tmp moved successfully.
C:\WINDOWS\Temp\NODBE3B.tmp moved successfully.
C:\WINDOWS\Temp\NODBF27.tmp moved successfully.
C:\WINDOWS\Temp\NODC260.tmp moved successfully.
C:\WINDOWS\Temp\NODC7B6.tmp moved successfully.
C:\WINDOWS\Temp\NODC959.tmp moved successfully.
C:\WINDOWS\Temp\NODCB67.tmp moved successfully.
C:\WINDOWS\Temp\NODCCF6.tmp moved successfully.
C:\WINDOWS\Temp\NODCD77.tmp moved successfully.
C:\WINDOWS\Temp\NODCF15.tmp moved successfully.
C:\WINDOWS\Temp\NODD055.tmp moved successfully.
C:\WINDOWS\Temp\NODD205.tmp moved successfully.
C:\WINDOWS\Temp\NODD3F1.tmp moved successfully.
C:\WINDOWS\Temp\NODD5F2.tmp moved successfully.
C:\WINDOWS\Temp\NODD8E3.tmp moved successfully.
C:\WINDOWS\Temp\NODD936.tmp moved successfully.
C:\WINDOWS\Temp\NODD999.tmp moved successfully.
C:\WINDOWS\Temp\NODD99A.tmp moved successfully.
C:\WINDOWS\Temp\NODDC8B.tmp moved successfully.
C:\WINDOWS\Temp\NODE02F.tmp moved successfully.
C:\WINDOWS\Temp\NODE332.tmp moved successfully.
C:\WINDOWS\Temp\NODE5A7.tmp moved successfully.
C:\WINDOWS\Temp\NODE60E.tmp moved successfully.
C:\WINDOWS\Temp\NODE8E4.tmp moved successfully.
C:\WINDOWS\Temp\NODE97C.tmp moved successfully.
C:\WINDOWS\Temp\NODED62.tmp moved successfully.
C:\WINDOWS\Temp\NODEDDB.tmp moved successfully.
C:\WINDOWS\Temp\NODF12A.tmp moved successfully.
C:\WINDOWS\Temp\NODF506.tmp moved successfully.
C:\WINDOWS\Temp\NODF611.tmp moved successfully.
C:\WINDOWS\Temp\NODF620.tmp moved successfully.
C:\WINDOWS\Temp\NODF78B.tmp moved successfully.
C:\WINDOWS\Temp\NODFC14.tmp moved successfully.
C:\WINDOWS\Temp\NODFE7.tmp moved successfully.
C:\WINDOWS\Temp\NODFE7F.tmp moved successfully.
C:\WINDOWS\Temp\NODFE9F.tmp moved successfully.
C:\WINDOWS\Temp\TarCD92.tmp moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: user
->Temp folder emptied: 45432386 bytes
->Temporary Internet Files folder emptied: 3387713 bytes
->Java cache emptied: 38544278 bytes
->FireFox cache emptied: 36860170 bytes
->Flash cache emptied: 6360 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2514542 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 17102047 bytes
Total Files Cleaned = 137,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Public
User: user
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.4.1 log created on 05182010_174934
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2320732015-1930792971-3522236662-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Program Files\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: "http://search.icq.com/search/afe_result ... id=afex&q=" removed from keyword.URL
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3255.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3A41.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP862F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD6AF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE4F1.tmp folder moved successfully.
C:\WINDOWS\Temp\HTT100B.tmp moved successfully.
C:\WINDOWS\Temp\HTT103A.tmp moved successfully.
C:\WINDOWS\Temp\HTT104B.tmp moved successfully.
C:\WINDOWS\Temp\HTT105C.tmp moved successfully.
C:\WINDOWS\Temp\HTT106C.tmp moved successfully.
C:\WINDOWS\Temp\HTT108C.tmp moved successfully.
C:\WINDOWS\Temp\HTT109F.tmp moved successfully.
C:\WINDOWS\Temp\HTT10A6.tmp moved successfully.
C:\WINDOWS\Temp\HTT10BF.tmp moved successfully.
C:\WINDOWS\Temp\HTT10D0.tmp moved successfully.
C:\WINDOWS\Temp\HTT10F0.tmp moved successfully.
C:\WINDOWS\Temp\HTT1110.tmp moved successfully.
C:\WINDOWS\Temp\HTT1121.tmp moved successfully.
C:\WINDOWS\Temp\HTT1131.tmp moved successfully.
C:\WINDOWS\Temp\HTT1152.tmp moved successfully.
C:\WINDOWS\Temp\HTT1162.tmp moved successfully.
C:\WINDOWS\Temp\HTT1173.tmp moved successfully.
C:\WINDOWS\Temp\HTT1183.tmp moved successfully.
C:\WINDOWS\Temp\HTT1185.tmp moved successfully.
C:\WINDOWS\Temp\HTT1194.tmp moved successfully.
C:\WINDOWS\Temp\HTT11A5.tmp moved successfully.
C:\WINDOWS\Temp\HTT124C.tmp moved successfully.
C:\WINDOWS\Temp\HTT13CF.tmp moved successfully.
C:\WINDOWS\Temp\HTT1611.tmp moved successfully.
C:\WINDOWS\Temp\HTT163B.tmp moved successfully.
C:\WINDOWS\Temp\HTT17CA.tmp moved successfully.
C:\WINDOWS\Temp\HTT1941.tmp moved successfully.
C:\WINDOWS\Temp\HTT1957.tmp moved successfully.
C:\WINDOWS\Temp\HTT19D8.tmp moved successfully.
C:\WINDOWS\Temp\HTT1B17.tmp moved successfully.
C:\WINDOWS\Temp\HTT1B2A.tmp moved successfully.
C:\WINDOWS\Temp\HTT1CF5.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D5F.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D75.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D7A.tmp moved successfully.
C:\WINDOWS\Temp\HTT1D9B.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E38.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E3E.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E81.tmp moved successfully.
C:\WINDOWS\Temp\HTT1E92.tmp moved successfully.
C:\WINDOWS\Temp\HTT1F7D.tmp moved successfully.
C:\WINDOWS\Temp\HTT1FBC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2186.tmp moved successfully.
C:\WINDOWS\Temp\HTT2196.tmp moved successfully.
C:\WINDOWS\Temp\HTT22EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT231F.tmp moved successfully.
C:\WINDOWS\Temp\HTT243E.tmp moved successfully.
C:\WINDOWS\Temp\HTT24EB.tmp moved successfully.
C:\WINDOWS\Temp\HTT2506.tmp moved successfully.
C:\WINDOWS\Temp\HTT250E.tmp moved successfully.
C:\WINDOWS\Temp\HTT25A4.tmp moved successfully.
C:\WINDOWS\Temp\HTT25B4.tmp moved successfully.
C:\WINDOWS\Temp\HTT25D5.tmp moved successfully.
C:\WINDOWS\Temp\HTT25EC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2618.tmp moved successfully.
C:\WINDOWS\Temp\HTT262A.tmp moved successfully.
C:\WINDOWS\Temp\HTT265A.tmp moved successfully.
C:\WINDOWS\Temp\HTT2671.tmp moved successfully.
C:\WINDOWS\Temp\HTT26CE.tmp moved successfully.
C:\WINDOWS\Temp\HTT2711.tmp moved successfully.
C:\WINDOWS\Temp\HTT2760.tmp moved successfully.
C:\WINDOWS\Temp\HTT27A0.tmp moved successfully.
C:\WINDOWS\Temp\HTT288D.tmp moved successfully.
C:\WINDOWS\Temp\HTT289A.tmp moved successfully.
C:\WINDOWS\Temp\HTT28A4.tmp moved successfully.
C:\WINDOWS\Temp\HTT2907.tmp moved successfully.
C:\WINDOWS\Temp\HTT299F.tmp moved successfully.
C:\WINDOWS\Temp\HTT2ADD.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B0B.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B95.tmp moved successfully.
C:\WINDOWS\Temp\HTT2B96.tmp moved successfully.
C:\WINDOWS\Temp\HTT2C28.tmp moved successfully.
C:\WINDOWS\Temp\HTT2C57.tmp moved successfully.
C:\WINDOWS\Temp\HTT2CA9.tmp moved successfully.
C:\WINDOWS\Temp\HTT2D6E.tmp moved successfully.
C:\WINDOWS\Temp\HTT2D8C.tmp moved successfully.
C:\WINDOWS\Temp\HTT2DDD.tmp moved successfully.
C:\WINDOWS\Temp\HTT2DFC.tmp moved successfully.
C:\WINDOWS\Temp\HTT2FD6.tmp moved successfully.
C:\WINDOWS\Temp\HTT300D.tmp moved successfully.
C:\WINDOWS\Temp\HTT311B.tmp moved successfully.
C:\WINDOWS\Temp\HTT3270.tmp moved successfully.
C:\WINDOWS\Temp\HTT3365.tmp moved successfully.
C:\WINDOWS\Temp\HTT3378.tmp moved successfully.
C:\WINDOWS\Temp\HTT3483.tmp moved successfully.
C:\WINDOWS\Temp\HTT352F.tmp moved successfully.
C:\WINDOWS\Temp\HTT358C.tmp moved successfully.
C:\WINDOWS\Temp\HTT35AD.tmp moved successfully.
C:\WINDOWS\Temp\HTT370.tmp moved successfully.
C:\WINDOWS\Temp\HTT3720.tmp moved successfully.
C:\WINDOWS\Temp\HTT3733.tmp moved successfully.
C:\WINDOWS\Temp\HTT3969.tmp moved successfully.
C:\WINDOWS\Temp\HTT39B2.tmp moved successfully.
C:\WINDOWS\Temp\HTT3A8B.tmp moved successfully.
C:\WINDOWS\Temp\HTT3B11.tmp moved successfully.
C:\WINDOWS\Temp\HTT3BAF.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C30.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C31.tmp moved successfully.
C:\WINDOWS\Temp\HTT3C6E.tmp moved successfully.
C:\WINDOWS\Temp\HTT3CD2.tmp moved successfully.
C:\WINDOWS\Temp\HTT3D3A.tmp moved successfully.
C:\WINDOWS\Temp\HTT3D7D.tmp moved successfully.
C:\WINDOWS\Temp\HTT40BC.tmp moved successfully.
C:\WINDOWS\Temp\HTT40C6.tmp moved successfully.
C:\WINDOWS\Temp\HTT40ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT40EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT4110.tmp moved successfully.
C:\WINDOWS\Temp\HTT4111.tmp moved successfully.
C:\WINDOWS\Temp\HTT4122.tmp moved successfully.
C:\WINDOWS\Temp\HTT4133.tmp moved successfully.
C:\WINDOWS\Temp\HTT4143.tmp moved successfully.
C:\WINDOWS\Temp\HTT4163.tmp moved successfully.
C:\WINDOWS\Temp\HTT4174.tmp moved successfully.
C:\WINDOWS\Temp\HTT4185.tmp moved successfully.
C:\WINDOWS\Temp\HTT4186.tmp moved successfully.
C:\WINDOWS\Temp\HTT41A6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41C4.tmp moved successfully.
C:\WINDOWS\Temp\HTT41C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT41D8.tmp moved successfully.
C:\WINDOWS\Temp\HTT41E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT41E8.tmp moved successfully.
C:\WINDOWS\Temp\HTT41F9.tmp moved successfully.
C:\WINDOWS\Temp\HTT4219.tmp moved successfully.
C:\WINDOWS\Temp\HTT422A.tmp moved successfully.
C:\WINDOWS\Temp\HTT423A.tmp moved successfully.
C:\WINDOWS\Temp\HTT424B.tmp moved successfully.
C:\WINDOWS\Temp\HTT426B.tmp moved successfully.
C:\WINDOWS\Temp\HTT4270.tmp moved successfully.
C:\WINDOWS\Temp\HTT42EE.tmp moved successfully.
C:\WINDOWS\Temp\HTT4460.tmp moved successfully.
C:\WINDOWS\Temp\HTT45AD.tmp moved successfully.
C:\WINDOWS\Temp\HTT45B8.tmp moved successfully.
C:\WINDOWS\Temp\HTT46F3.tmp moved successfully.
C:\WINDOWS\Temp\HTT46F4.tmp moved successfully.
C:\WINDOWS\Temp\HTT481.tmp moved successfully.
C:\WINDOWS\Temp\HTT4921.tmp moved successfully.
C:\WINDOWS\Temp\HTT496.tmp moved successfully.
C:\WINDOWS\Temp\HTT4A34.tmp moved successfully.
C:\WINDOWS\Temp\HTT4AA1.tmp moved successfully.
C:\WINDOWS\Temp\HTT4C24.tmp moved successfully.
C:\WINDOWS\Temp\HTT4CE1.tmp moved successfully.
C:\WINDOWS\Temp\HTT4DCA.tmp moved successfully.
C:\WINDOWS\Temp\HTT4DDD.tmp moved successfully.
C:\WINDOWS\Temp\HTT4EB4.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F06.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F17.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F27.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F28.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F39.tmp moved successfully.
C:\WINDOWS\Temp\HTT4F49.tmp moved successfully.
C:\WINDOWS\Temp\HTT4FBC.tmp moved successfully.
C:\WINDOWS\Temp\HTT52D.tmp moved successfully.
C:\WINDOWS\Temp\HTT53B.tmp moved successfully.
C:\WINDOWS\Temp\HTT5460.tmp moved successfully.
C:\WINDOWS\Temp\HTT5581.tmp moved successfully.
C:\WINDOWS\Temp\HTT55D2.tmp moved successfully.
C:\WINDOWS\Temp\HTT56CE.tmp moved successfully.
C:\WINDOWS\Temp\HTT57ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT57FE.tmp moved successfully.
C:\WINDOWS\Temp\HTT582D.tmp moved successfully.
C:\WINDOWS\Temp\HTT58FA.tmp moved successfully.
C:\WINDOWS\Temp\HTT590B.tmp moved successfully.
C:\WINDOWS\Temp\HTT5B52.tmp moved successfully.
C:\WINDOWS\Temp\HTT5CA2.tmp moved successfully.
C:\WINDOWS\Temp\HTT5DB8.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E47.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E65.tmp moved successfully.
C:\WINDOWS\Temp\HTT5E7.tmp moved successfully.
C:\WINDOWS\Temp\HTT5F32.tmp moved successfully.
C:\WINDOWS\Temp\HTT5F61.tmp moved successfully.
C:\WINDOWS\Temp\HTT6069.tmp moved successfully.
C:\WINDOWS\Temp\HTT607C.tmp moved successfully.
C:\WINDOWS\Temp\HTT60F2.tmp moved successfully.
C:\WINDOWS\Temp\HTT61DF.tmp moved successfully.
C:\WINDOWS\Temp\HTT625C.tmp moved successfully.
C:\WINDOWS\Temp\HTT6261.tmp moved successfully.
C:\WINDOWS\Temp\HTT626D.tmp moved successfully.
C:\WINDOWS\Temp\HTT627.tmp moved successfully.
C:\WINDOWS\Temp\HTT633.tmp moved successfully.
C:\WINDOWS\Temp\HTT63D.tmp moved successfully.
C:\WINDOWS\Temp\HTT63E3.tmp moved successfully.
C:\WINDOWS\Temp\HTT64.tmp moved successfully.
C:\WINDOWS\Temp\HTT6455.tmp moved successfully.
C:\WINDOWS\Temp\HTT64F.tmp moved successfully.
C:\WINDOWS\Temp\HTT6537.tmp moved successfully.
C:\WINDOWS\Temp\HTT6638.tmp moved successfully.
C:\WINDOWS\Temp\HTT66B4.tmp moved successfully.
C:\WINDOWS\Temp\HTT6808.tmp moved successfully.
C:\WINDOWS\Temp\HTT69E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT6A21.tmp moved successfully.
C:\WINDOWS\Temp\HTT6B05.tmp moved successfully.
C:\WINDOWS\Temp\HTT6C58.tmp moved successfully.
C:\WINDOWS\Temp\HTT6D4.tmp moved successfully.
C:\WINDOWS\Temp\HTT6DE2.tmp moved successfully.
C:\WINDOWS\Temp\HTT6FB0.tmp moved successfully.
C:\WINDOWS\Temp\HTT70AA.tmp moved successfully.
C:\WINDOWS\Temp\HTT71EA.tmp moved successfully.
C:\WINDOWS\Temp\HTT71FA.tmp moved successfully.
C:\WINDOWS\Temp\HTT72C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT7335.tmp moved successfully.
C:\WINDOWS\Temp\HTT73F1.tmp moved successfully.
C:\WINDOWS\Temp\HTT7535.tmp moved successfully.
C:\WINDOWS\Temp\HTT754.tmp moved successfully.
C:\WINDOWS\Temp\HTT75EB.tmp moved successfully.
C:\WINDOWS\Temp\HTT76C3.tmp moved successfully.
C:\WINDOWS\Temp\HTT7732.tmp moved successfully.
C:\WINDOWS\Temp\HTT7733.tmp moved successfully.
C:\WINDOWS\Temp\HTT7744.tmp moved successfully.
C:\WINDOWS\Temp\HTT778A.tmp moved successfully.
C:\WINDOWS\Temp\HTT77AB.tmp moved successfully.
C:\WINDOWS\Temp\HTT78ED.tmp moved successfully.
C:\WINDOWS\Temp\HTT79B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A11.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A12.tmp moved successfully.
C:\WINDOWS\Temp\HTT7A93.tmp moved successfully.
C:\WINDOWS\Temp\HTT7BA8.tmp moved successfully.
C:\WINDOWS\Temp\HTT7BCD.tmp moved successfully.
C:\WINDOWS\Temp\HTT7C06.tmp moved successfully.
C:\WINDOWS\Temp\HTT7CE4.tmp moved successfully.
C:\WINDOWS\Temp\HTT7D4.tmp moved successfully.
C:\WINDOWS\Temp\HTT7D59.tmp moved successfully.
C:\WINDOWS\Temp\HTT7E1F.tmp moved successfully.
C:\WINDOWS\Temp\HTT7EAB.tmp moved successfully.
C:\WINDOWS\Temp\HTT7ED1.tmp moved successfully.
C:\WINDOWS\Temp\HTT7F25.tmp moved successfully.
C:\WINDOWS\Temp\HTT7F49.tmp moved successfully.
C:\WINDOWS\Temp\HTT7FB1.tmp moved successfully.
C:\WINDOWS\Temp\HTT8001.tmp moved successfully.
C:\WINDOWS\Temp\HTT8085.tmp moved successfully.
C:\WINDOWS\Temp\HTT8089.tmp moved successfully.
C:\WINDOWS\Temp\HTT8160.tmp moved successfully.
C:\WINDOWS\Temp\HTT8180.tmp moved successfully.
C:\WINDOWS\Temp\HTT8181.tmp moved successfully.
C:\WINDOWS\Temp\HTT81C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT8534.tmp moved successfully.
C:\WINDOWS\Temp\HTT8565.tmp moved successfully.
C:\WINDOWS\Temp\HTT86FE.tmp moved successfully.
C:\WINDOWS\Temp\HTT86FF.tmp moved successfully.
C:\WINDOWS\Temp\HTT872A.tmp moved successfully.
C:\WINDOWS\Temp\HTT87CD.tmp moved successfully.
C:\WINDOWS\Temp\HTT8816.tmp moved successfully.
C:\WINDOWS\Temp\HTT8894.tmp moved successfully.
C:\WINDOWS\Temp\HTT8896.tmp moved successfully.
C:\WINDOWS\Temp\HTT88B2.tmp moved successfully.
C:\WINDOWS\Temp\HTT891E.tmp moved successfully.
C:\WINDOWS\Temp\HTT8923.tmp moved successfully.
C:\WINDOWS\Temp\HTT8925.tmp moved successfully.
C:\WINDOWS\Temp\HTT8974.tmp moved successfully.
C:\WINDOWS\Temp\HTT89E6.tmp moved successfully.
C:\WINDOWS\Temp\HTT8CA6.tmp moved successfully.
C:\WINDOWS\Temp\HTT8DE5.tmp moved successfully.
C:\WINDOWS\Temp\HTT8DFD.tmp moved successfully.
C:\WINDOWS\Temp\HTT908D.tmp moved successfully.
C:\WINDOWS\Temp\HTT9095.tmp moved successfully.
C:\WINDOWS\Temp\HTT90AE.tmp moved successfully.
C:\WINDOWS\Temp\HTT90E7.tmp moved successfully.
C:\WINDOWS\Temp\HTT912E.tmp moved successfully.
C:\WINDOWS\Temp\HTT9179.tmp moved successfully.
C:\WINDOWS\Temp\HTT9419.tmp moved successfully.
C:\WINDOWS\Temp\HTT94B6.tmp moved successfully.
C:\WINDOWS\Temp\HTT9641.tmp moved successfully.
C:\WINDOWS\Temp\HTT971A.tmp moved successfully.
C:\WINDOWS\Temp\HTT9799.tmp moved successfully.
C:\WINDOWS\Temp\HTT97C7.tmp moved successfully.
C:\WINDOWS\Temp\HTT9822.tmp moved successfully.
C:\WINDOWS\Temp\HTT99D3.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A54.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A7E.tmp moved successfully.
C:\WINDOWS\Temp\HTT9A8B.tmp moved successfully.
C:\WINDOWS\Temp\HTT9D49.tmp moved successfully.
C:\WINDOWS\Temp\HTTA0AD.tmp moved successfully.
C:\WINDOWS\Temp\HTTA14A.tmp moved successfully.
C:\WINDOWS\Temp\HTTA26D.tmp moved successfully.
C:\WINDOWS\Temp\HTTA43B.tmp moved successfully.
C:\WINDOWS\Temp\HTTA59.tmp moved successfully.
C:\WINDOWS\Temp\HTTA594.tmp moved successfully.
C:\WINDOWS\Temp\HTTA75A.tmp moved successfully.
C:\WINDOWS\Temp\HTTA78E.tmp moved successfully.
C:\WINDOWS\Temp\HTTA7DD.tmp moved successfully.
C:\WINDOWS\Temp\HTTA7F2.tmp moved successfully.
C:\WINDOWS\Temp\HTTA810.tmp moved successfully.
C:\WINDOWS\Temp\HTTA851.tmp moved successfully.
C:\WINDOWS\Temp\HTTAA92.tmp moved successfully.
C:\WINDOWS\Temp\HTTAB16.tmp moved successfully.
C:\WINDOWS\Temp\HTTAB50.tmp moved successfully.
C:\WINDOWS\Temp\HTTABFD.tmp moved successfully.
C:\WINDOWS\Temp\HTTAC7F.tmp moved successfully.
C:\WINDOWS\Temp\HTTACD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTACE5.tmp moved successfully.
C:\WINDOWS\Temp\HTTAD47.tmp moved successfully.
C:\WINDOWS\Temp\HTTADFB.tmp moved successfully.
C:\WINDOWS\Temp\HTTAE30.tmp moved successfully.
C:\WINDOWS\Temp\HTTAEF2.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF16.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF26.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF2D.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF46.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF4D.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF4F.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF62.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF67.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF77.tmp moved successfully.
C:\WINDOWS\Temp\HTTAF97.tmp moved successfully.
C:\WINDOWS\Temp\HTTAFA8.tmp moved successfully.
C:\WINDOWS\Temp\HTTAFD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTB058.tmp moved successfully.
C:\WINDOWS\Temp\HTTB07A.tmp moved successfully.
C:\WINDOWS\Temp\HTTB107.tmp moved successfully.
C:\WINDOWS\Temp\HTTB182.tmp moved successfully.
C:\WINDOWS\Temp\HTTB31F.tmp moved successfully.
C:\WINDOWS\Temp\HTTB4C6.tmp moved successfully.
C:\WINDOWS\Temp\HTTB573.tmp moved successfully.
C:\WINDOWS\Temp\HTTB574.tmp moved successfully.
C:\WINDOWS\Temp\HTTB596.tmp moved successfully.
C:\WINDOWS\Temp\HTTB597.tmp moved successfully.
C:\WINDOWS\Temp\HTTB71B.tmp moved successfully.
C:\WINDOWS\Temp\HTTB72C.tmp moved successfully.
C:\WINDOWS\Temp\HTTB777.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7A0.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7B0.tmp moved successfully.
C:\WINDOWS\Temp\HTTB7C1.tmp moved successfully.
C:\WINDOWS\Temp\HTTB945.tmp moved successfully.
C:\WINDOWS\Temp\HTTBA04.tmp moved successfully.
C:\WINDOWS\Temp\HTTBA95.tmp moved successfully.
C:\WINDOWS\Temp\HTTBC75.tmp moved successfully.
C:\WINDOWS\Temp\HTTBCC.tmp moved successfully.
C:\WINDOWS\Temp\HTTBE51.tmp moved successfully.
C:\WINDOWS\Temp\HTTBE6E.tmp moved successfully.
C:\WINDOWS\Temp\HTTC26D.tmp moved successfully.
C:\WINDOWS\Temp\HTTC2F0.tmp moved successfully.
C:\WINDOWS\Temp\HTTC352.tmp moved successfully.
C:\WINDOWS\Temp\HTTC6B8.tmp moved successfully.
C:\WINDOWS\Temp\HTTC716.tmp moved successfully.
C:\WINDOWS\Temp\HTTCBA4.tmp moved successfully.
C:\WINDOWS\Temp\HTTCD71.tmp moved successfully.
C:\WINDOWS\Temp\HTTCDB2.tmp moved successfully.
C:\WINDOWS\Temp\HTTCE90.tmp moved successfully.
C:\WINDOWS\Temp\HTTCFC0.tmp moved successfully.
C:\WINDOWS\Temp\HTTCFF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTD0C3.tmp moved successfully.
C:\WINDOWS\Temp\HTTD16E.tmp moved successfully.
C:\WINDOWS\Temp\HTTD1AB.tmp moved successfully.
C:\WINDOWS\Temp\HTTD1DF.tmp moved successfully.
C:\WINDOWS\Temp\HTTD357.tmp moved successfully.
C:\WINDOWS\Temp\HTTD3B1.tmp moved successfully.
C:\WINDOWS\Temp\HTTD49A.tmp moved successfully.
C:\WINDOWS\Temp\HTTD67.tmp moved successfully.
C:\WINDOWS\Temp\HTTD682.tmp moved successfully.
C:\WINDOWS\Temp\HTTD837.tmp moved successfully.
C:\WINDOWS\Temp\HTTD8EC.tmp moved successfully.
C:\WINDOWS\Temp\HTTD9AC.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAC9.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTDAFD.tmp moved successfully.
C:\WINDOWS\Temp\HTTDB88.tmp moved successfully.
C:\WINDOWS\Temp\HTTDE12.tmp moved successfully.
C:\WINDOWS\Temp\HTTDE98.tmp moved successfully.
C:\WINDOWS\Temp\HTTDF6C.tmp moved successfully.
C:\WINDOWS\Temp\HTTE186.tmp moved successfully.
C:\WINDOWS\Temp\HTTE21A.tmp moved successfully.
C:\WINDOWS\Temp\HTTE308.tmp moved successfully.
C:\WINDOWS\Temp\HTTE384.tmp moved successfully.
C:\WINDOWS\Temp\HTTE3E.tmp moved successfully.
C:\WINDOWS\Temp\HTTE7B5.tmp moved successfully.
C:\WINDOWS\Temp\HTTE7F5.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB03.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB83.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB9.tmp moved successfully.
C:\WINDOWS\Temp\HTTEB9C.tmp moved successfully.
C:\WINDOWS\Temp\HTTED23.tmp moved successfully.
C:\WINDOWS\Temp\HTTED42.tmp moved successfully.
C:\WINDOWS\Temp\HTTED4D.tmp moved successfully.
C:\WINDOWS\Temp\HTTED52.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDEC.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDF3.tmp moved successfully.
C:\WINDOWS\Temp\HTTEDFF.tmp moved successfully.
C:\WINDOWS\Temp\HTTEE7D.tmp moved successfully.
C:\WINDOWS\Temp\HTTEEFB.tmp moved successfully.
C:\WINDOWS\Temp\HTTF255.tmp moved successfully.
C:\WINDOWS\Temp\HTTF273.tmp moved successfully.
C:\WINDOWS\Temp\HTTF306.tmp moved successfully.
C:\WINDOWS\Temp\HTTF374.tmp moved successfully.
C:\WINDOWS\Temp\HTTF4F4.tmp moved successfully.
C:\WINDOWS\Temp\HTTF5D7.tmp moved successfully.
C:\WINDOWS\Temp\HTTF664.tmp moved successfully.
C:\WINDOWS\Temp\HTTF66B.tmp moved successfully.
C:\WINDOWS\Temp\HTTF6C1.tmp moved successfully.
C:\WINDOWS\Temp\HTTF896.tmp moved successfully.
C:\WINDOWS\Temp\HTTF8DE.tmp moved successfully.
C:\WINDOWS\Temp\HTTFA90.tmp moved successfully.
C:\WINDOWS\Temp\HTTFADC.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC02.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC8.tmp moved successfully.
C:\WINDOWS\Temp\HTTFC9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCC7.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCD7.tmp moved successfully.
C:\WINDOWS\Temp\HTTFCF9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFD17.tmp moved successfully.
C:\WINDOWS\Temp\HTTFD6C.tmp moved successfully.
C:\WINDOWS\Temp\HTTFE9.tmp moved successfully.
C:\WINDOWS\Temp\HTTFECE.tmp moved successfully.
C:\WINDOWS\Temp\HTTFEF2.tmp moved successfully.
C:\WINDOWS\Temp\HTTFF90.tmp moved successfully.
C:\WINDOWS\Temp\HTTFFA.tmp moved successfully.
C:\WINDOWS\Temp\NOD1073.tmp moved successfully.
C:\WINDOWS\Temp\NOD118D.tmp moved successfully.
C:\WINDOWS\Temp\NOD127F.tmp moved successfully.
C:\WINDOWS\Temp\NOD16CB.tmp moved successfully.
C:\WINDOWS\Temp\NOD1A0C.tmp moved successfully.
C:\WINDOWS\Temp\NOD1BD7.tmp moved successfully.
C:\WINDOWS\Temp\NOD1DB2.tmp moved successfully.
C:\WINDOWS\Temp\NOD208E.tmp moved successfully.
C:\WINDOWS\Temp\NOD2131.tmp moved successfully.
C:\WINDOWS\Temp\NOD244C.tmp moved successfully.
C:\WINDOWS\Temp\NOD255B.tmp moved successfully.
C:\WINDOWS\Temp\NOD2730.tmp moved successfully.
C:\WINDOWS\Temp\NOD2BD0.tmp moved successfully.
C:\WINDOWS\Temp\NOD3004.tmp moved successfully.
C:\WINDOWS\Temp\NOD3086.tmp moved successfully.
C:\WINDOWS\Temp\NOD311.tmp moved successfully.
C:\WINDOWS\Temp\NOD3549.tmp moved successfully.
C:\WINDOWS\Temp\NOD39DA.tmp moved successfully.
C:\WINDOWS\Temp\NOD3B8A.tmp moved successfully.
C:\WINDOWS\Temp\NOD3DD6.tmp moved successfully.
C:\WINDOWS\Temp\NOD3F57.tmp moved successfully.
C:\WINDOWS\Temp\NOD3FA9.tmp moved successfully.
C:\WINDOWS\Temp\NOD3FD9.tmp moved successfully.
C:\WINDOWS\Temp\NOD4251.tmp moved successfully.
C:\WINDOWS\Temp\NOD45B2.tmp moved successfully.
C:\WINDOWS\Temp\NOD473D.tmp moved successfully.
C:\WINDOWS\Temp\NOD484B.tmp moved successfully.
C:\WINDOWS\Temp\NOD4B4A.tmp moved successfully.
C:\WINDOWS\Temp\NOD4E73.tmp moved successfully.
C:\WINDOWS\Temp\NOD4F5A.tmp moved successfully.
C:\WINDOWS\Temp\NOD5154.tmp moved successfully.
C:\WINDOWS\Temp\NOD5933.tmp moved successfully.
C:\WINDOWS\Temp\NOD5B07.tmp moved successfully.
C:\WINDOWS\Temp\NOD5C98.tmp moved successfully.
C:\WINDOWS\Temp\NOD5D3.tmp moved successfully.
C:\WINDOWS\Temp\NOD5F29.tmp moved successfully.
C:\WINDOWS\Temp\NOD6049.tmp moved successfully.
C:\WINDOWS\Temp\NOD66D6.tmp moved successfully.
C:\WINDOWS\Temp\NOD6737.tmp moved successfully.
C:\WINDOWS\Temp\NOD68A1.tmp moved successfully.
C:\WINDOWS\Temp\NOD6AD7.tmp moved successfully.
C:\WINDOWS\Temp\NOD6C04.tmp moved successfully.
C:\WINDOWS\Temp\NOD6CC1.tmp moved successfully.
C:\WINDOWS\Temp\NOD6E47.tmp moved successfully.
C:\WINDOWS\Temp\NOD740A.tmp moved successfully.
C:\WINDOWS\Temp\NOD74B0.tmp moved successfully.
C:\WINDOWS\Temp\NOD755F.tmp moved successfully.
C:\WINDOWS\Temp\NOD7674.tmp moved successfully.
C:\WINDOWS\Temp\NOD7778.tmp moved successfully.
C:\WINDOWS\Temp\NOD7C4.tmp moved successfully.
C:\WINDOWS\Temp\NOD7E08.tmp moved successfully.
C:\WINDOWS\Temp\NOD83FF.tmp moved successfully.
C:\WINDOWS\Temp\NOD85F1.tmp moved successfully.
C:\WINDOWS\Temp\NOD8672.tmp moved successfully.
C:\WINDOWS\Temp\NOD8761.tmp moved successfully.
C:\WINDOWS\Temp\NOD8A0E.tmp moved successfully.
C:\WINDOWS\Temp\NOD8AAD.tmp moved successfully.
C:\WINDOWS\Temp\NOD8B50.tmp moved successfully.
C:\WINDOWS\Temp\NOD8C7D.tmp moved successfully.
C:\WINDOWS\Temp\NOD8DF.tmp moved successfully.
C:\WINDOWS\Temp\NOD8F86.tmp moved successfully.
C:\WINDOWS\Temp\NOD90DC.tmp moved successfully.
C:\WINDOWS\Temp\NOD9109.tmp moved successfully.
C:\WINDOWS\Temp\NOD912F.tmp moved successfully.
C:\WINDOWS\Temp\NOD9526.tmp moved successfully.
C:\WINDOWS\Temp\NOD983C.tmp moved successfully.
C:\WINDOWS\Temp\NOD9B2B.tmp moved successfully.
C:\WINDOWS\Temp\NODA24D.tmp moved successfully.
C:\WINDOWS\Temp\NODA2CE.tmp moved successfully.
C:\WINDOWS\Temp\NODA3BA.tmp moved successfully.
C:\WINDOWS\Temp\NODA40C.tmp moved successfully.
C:\WINDOWS\Temp\NODAF82.tmp moved successfully.
C:\WINDOWS\Temp\NODB003.tmp moved successfully.
C:\WINDOWS\Temp\NODB0EC.tmp moved successfully.
C:\WINDOWS\Temp\NODB113.tmp moved successfully.
C:\WINDOWS\Temp\NODB219.tmp moved successfully.
C:\WINDOWS\Temp\NODB698.tmp moved successfully.
C:\WINDOWS\Temp\NODB792.tmp moved successfully.
C:\WINDOWS\Temp\NODBD3.tmp moved successfully.
C:\WINDOWS\Temp\NODBE2D.tmp moved successfully.
C:\WINDOWS\Temp\NODBE3B.tmp moved successfully.
C:\WINDOWS\Temp\NODBF27.tmp moved successfully.
C:\WINDOWS\Temp\NODC260.tmp moved successfully.
C:\WINDOWS\Temp\NODC7B6.tmp moved successfully.
C:\WINDOWS\Temp\NODC959.tmp moved successfully.
C:\WINDOWS\Temp\NODCB67.tmp moved successfully.
C:\WINDOWS\Temp\NODCCF6.tmp moved successfully.
C:\WINDOWS\Temp\NODCD77.tmp moved successfully.
C:\WINDOWS\Temp\NODCF15.tmp moved successfully.
C:\WINDOWS\Temp\NODD055.tmp moved successfully.
C:\WINDOWS\Temp\NODD205.tmp moved successfully.
C:\WINDOWS\Temp\NODD3F1.tmp moved successfully.
C:\WINDOWS\Temp\NODD5F2.tmp moved successfully.
C:\WINDOWS\Temp\NODD8E3.tmp moved successfully.
C:\WINDOWS\Temp\NODD936.tmp moved successfully.
C:\WINDOWS\Temp\NODD999.tmp moved successfully.
C:\WINDOWS\Temp\NODD99A.tmp moved successfully.
C:\WINDOWS\Temp\NODDC8B.tmp moved successfully.
C:\WINDOWS\Temp\NODE02F.tmp moved successfully.
C:\WINDOWS\Temp\NODE332.tmp moved successfully.
C:\WINDOWS\Temp\NODE5A7.tmp moved successfully.
C:\WINDOWS\Temp\NODE60E.tmp moved successfully.
C:\WINDOWS\Temp\NODE8E4.tmp moved successfully.
C:\WINDOWS\Temp\NODE97C.tmp moved successfully.
C:\WINDOWS\Temp\NODED62.tmp moved successfully.
C:\WINDOWS\Temp\NODEDDB.tmp moved successfully.
C:\WINDOWS\Temp\NODF12A.tmp moved successfully.
C:\WINDOWS\Temp\NODF506.tmp moved successfully.
C:\WINDOWS\Temp\NODF611.tmp moved successfully.
C:\WINDOWS\Temp\NODF620.tmp moved successfully.
C:\WINDOWS\Temp\NODF78B.tmp moved successfully.
C:\WINDOWS\Temp\NODFC14.tmp moved successfully.
C:\WINDOWS\Temp\NODFE7.tmp moved successfully.
C:\WINDOWS\Temp\NODFE7F.tmp moved successfully.
C:\WINDOWS\Temp\NODFE9F.tmp moved successfully.
C:\WINDOWS\Temp\TarCD92.tmp moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: user
->Temp folder emptied: 45432386 bytes
->Temporary Internet Files folder emptied: 3387713 bytes
->Java cache emptied: 38544278 bytes
->FireFox cache emptied: 36860170 bytes
->Flash cache emptied: 6360 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2514542 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 17102047 bytes
Total Files Cleaned = 137,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Public
User: user
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.4.1 log created on 05182010_174934
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Re: Prosím o kontrolu logu
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verzia databázy: 4112
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
18. 5. 2010 19:15:57
mbam-log-2010-05-18 (19-15-57).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 256572
Uplynulý čas: 1 hod, 17 min, 40 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 1
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
www.malwarebytes.org
Verzia databázy: 4112
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
18. 5. 2010 19:15:57
mbam-log-2010-05-18 (19-15-57).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 256572
Uplynulý čas: 1 hod, 17 min, 40 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 1
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
Re: Prosím o kontrolu logu
Co našel mabm smažte. Jak to vypadá s počítačem ted?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
no ten program čo našiel tú chybu, tak ja som zavrel ten program a potom som zistil, že som to nemal robiť, lebo keď som ten program potom zapol, tak už to v tej karanténe nebolo, takže budem musieť ešte raz dať kontrolu....ale inak to z notebookom vyzerá dobre...nebude potrebný už žiadny log pre istotu?
Re: Prosím o kontrolu logu
Můžete dát ještě log ze Rsitu 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
Jedna otázka: combofix sa ešte nachádza v PC? Lebo som ho spúšťal asi 2 týždne dozadu...na ploche ale nie je
Tu je log:
Logfile of random's system information tool 1.07 (written by random/random)
Run by user at 2010-05-19 16:17:40
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 179 GB (78%) free of 229 GB
Total RAM: 2039 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:19:46, on 19. 5. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\windows\system32\taskeng.exe
C:\Users\user\Desktop\RSIT.exe
C:\Program Files\trend micro\user.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\SearchProtocolHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - (no file)
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: rpcnetp - Unknown owner - C:\windows\System32\rpcnetp.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
--
End of file - 7483 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{855F3B16-6D32-4FE6-8A56-BBB695989046}
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-03-24 2145000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-16 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files\PDF Complete\pdfsty.exe [2007-05-08 331552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-10 145184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-31 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-04-17 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}]
shell\AutoRun\command - F:\Launcher.exe
======List of files/folders created in the last 1 months======
2010-05-18 17:49:34 ----D---- C:\_OTL
2010-05-14 15:47:11 ----D---- C:\rsit
2010-05-12 15:30:07 ----A---- C:\windows\system32\inetcomm.dll
2010-05-09 17:12:56 ----D---- C:\Program Files\VirtualDJ
2010-05-08 10:31:04 ----D---- C:\Users\user\AppData\Roaming\VitySoft
2010-05-06 14:01:51 ----D---- C:\Users\user\AppData\Roaming\OpenCandy
2010-05-05 16:59:44 ----D---- C:\Users\user\AppData\Roaming\Malwarebytes
2010-05-05 16:59:33 ----D---- C:\ProgramData\Malwarebytes
2010-05-05 16:59:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-03 16:44:23 ----A---- C:\windows\BDTSupport.dll
2010-05-03 16:44:22 ----A---- C:\windows\SGDetectionTool.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDRes.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDCore.dll
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-03 16:38:32 ----D---- C:\Users\user\AppData\Roaming\PC Tools
2010-05-03 16:38:32 ----D---- C:\ProgramData\PC Tools
2010-05-03 16:38:32 ----D---- C:\Program Files\Spyware Doctor
2010-05-03 16:38:19 ----AD---- C:\ProgramData\TEMP
2010-05-03 13:30:00 ----A---- C:\windows\SWXCACLS.exe
2010-05-03 13:28:13 ----A---- C:\windows\ntbtlog.txt
2010-05-02 19:59:31 ----D---- C:\Qoobox
2010-05-02 16:46:35 ----D---- C:\Program Files\ASIO4ALL v2
2010-05-01 16:29:39 ----A---- C:\windows\zip.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWSC.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWREG.exe
2010-05-01 16:29:39 ----A---- C:\windows\sed.exe
2010-05-01 16:29:39 ----A---- C:\windows\PEV.exe
2010-05-01 16:29:39 ----A---- C:\windows\NIRCMD.exe
2010-05-01 16:29:39 ----A---- C:\windows\MBR.exe
2010-05-01 16:29:39 ----A---- C:\windows\grep.exe
2010-05-01 16:29:33 ----D---- C:\windows\ERDNT
======List of files/folders modified in the last 1 months======
2010-05-19 16:19:46 ----D---- C:\windows\Temp
2010-05-19 16:19:29 ----D---- C:\Program Files\trend micro
2010-05-19 16:12:44 ----D---- C:\windows\Prefetch
2010-05-19 14:14:24 ----D---- C:\Users\user\AppData\Roaming\Skype
2010-05-19 14:10:21 ----D---- C:\Users\user\AppData\Roaming\skypePM
2010-05-19 14:00:05 ----D---- C:\windows\System32
2010-05-19 14:00:04 ----D---- C:\windows\inf
2010-05-19 14:00:04 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-18 18:57:33 ----SHD---- C:\windows\Installer
2010-05-18 18:57:28 ----SHD---- C:\System Volume Information
2010-05-18 18:35:36 ----D---- C:\windows\system32\config
2010-05-18 18:35:32 ----D---- C:\windows\Tasks
2010-05-18 18:35:32 ----D---- C:\windows\system32\spool
2010-05-18 18:35:32 ----D---- C:\windows\system32\Msdtc
2010-05-18 18:35:32 ----D---- C:\windows\system32\CodeIntegrity
2010-05-18 18:35:32 ----D---- C:\windows\system32\catroot2
2010-05-18 18:35:32 ----D---- C:\Windows
2010-05-18 18:35:31 ----D---- C:\windows\system32\wbem
2010-05-18 18:35:31 ----D---- C:\windows\registration
2010-05-18 17:56:38 ----D---- C:\windows\system32\drivers
2010-05-18 17:49:37 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-13 03:10:51 ----D---- C:\windows\winsxs
2010-05-13 03:01:56 ----D---- C:\Program Files\Windows Mail
2010-05-13 03:01:38 ----D---- C:\windows\system32\catroot
2010-05-09 17:28:06 ----RSD---- C:\windows\Fonts
2010-05-09 17:12:56 ----RD---- C:\Program Files
2010-05-09 17:05:21 ----D---- C:\Program Files\VstPlugins
2010-05-06 13:57:06 ----D---- C:\Program Files\Image-Line
2010-05-06 10:36:38 ----N---- C:\windows\system32\MpSigStub.exe
2010-05-05 16:59:33 ----HD---- C:\ProgramData
2010-05-03 16:38:39 ----D---- C:\Program Files\Common Files\microsoft shared
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files
2010-05-03 13:42:10 ----D---- C:\windows\Debug
2010-05-03 13:37:08 ----D---- C:\windows\Minidump
2010-05-02 18:39:40 ----D---- C:\Program Files\CCleaner
2010-05-02 18:39:09 ----D---- C:\windows\system32\Tasks
2010-05-01 15:36:40 ----D---- C:\windows\system32\WDI
2010-04-30 20:51:06 ----A---- C:\windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;Offline Files Driver; C:\windows\system32\drivers\csc.sys [2009-04-11 351744]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2010-03-24 114984]
R1 pctgntdi;pctgntdi; \??\C:\Windows\System32\drivers\pctgntdi.sys [2009-10-30 233136]
R2 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2010-03-24 133512]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2010-03-24 134488]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2010-03-24 41312]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2008-04-22 80424]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2008-04-22 80936]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2008-04-22 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e6032.sys [2007-05-24 223616]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2010-03-24 32584]
R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2008-04-15 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ; C:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2007-06-08 30008]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-05-26 101376]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pctplsg;pctplsg; \??\C:\Windows\System32\drivers\pctplsg.sys [2009-09-03 70408]
S3 TfNetMon;TfNetMon; \??\C:\windows\system32\drivers\TfNetMon.sys [2009-11-12 33552]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2008-01-21 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 540448]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 TeamViewer4;TeamViewer 4; C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe [2009-04-17 185640]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 rpcnetp;rpcnetp; C:\windows\System32\rpcnetp.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-03-24 33560]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2008-01-21 523776]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-06-08 172131]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2008-04-16 165192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-08 1112560]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 ThreatFire;ThreatFire; C:\Program Files\Spyware Doctor\TFEngine\TFService.exe [2009-11-12 70928]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2009-04-11 918528]
-----------------EOF-----------------
Tu je log:
Logfile of random's system information tool 1.07 (written by random/random)
Run by user at 2010-05-19 16:17:40
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 179 GB (78%) free of 229 GB
Total RAM: 2039 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:19:46, on 19. 5. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\windows\system32\taskeng.exe
C:\Users\user\Desktop\RSIT.exe
C:\Program Files\trend micro\user.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\SearchProtocolHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - (no file)
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: rpcnetp - Unknown owner - C:\windows\System32\rpcnetp.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
--
End of file - 7483 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{855F3B16-6D32-4FE6-8A56-BBB695989046}
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-03-24 2145000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-16 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files\PDF Complete\pdfsty.exe [2007-05-08 331552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-10 145184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-31 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-04-17 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406c9-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406cd-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a87406e5-38d3-11de-9309-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aaf9177b-3d42-11de-b7b3-806e6f6e6963}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bac0e54b-3a3e-11de-b7d1-00247e2dc0f4}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e25cd152-0f52-11df-aa12-00247e2dc0f4}]
shell\AutoRun\command - F:\Launcher.exe
======List of files/folders created in the last 1 months======
2010-05-18 17:49:34 ----D---- C:\_OTL
2010-05-14 15:47:11 ----D---- C:\rsit
2010-05-12 15:30:07 ----A---- C:\windows\system32\inetcomm.dll
2010-05-09 17:12:56 ----D---- C:\Program Files\VirtualDJ
2010-05-08 10:31:04 ----D---- C:\Users\user\AppData\Roaming\VitySoft
2010-05-06 14:01:51 ----D---- C:\Users\user\AppData\Roaming\OpenCandy
2010-05-05 16:59:44 ----D---- C:\Users\user\AppData\Roaming\Malwarebytes
2010-05-05 16:59:33 ----D---- C:\ProgramData\Malwarebytes
2010-05-05 16:59:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-03 16:44:23 ----A---- C:\windows\BDTSupport.dll
2010-05-03 16:44:22 ----A---- C:\windows\SGDetectionTool.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDRes.dll
2010-05-03 16:44:22 ----A---- C:\windows\PCTBDCore.dll
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-03 16:38:32 ----D---- C:\Users\user\AppData\Roaming\PC Tools
2010-05-03 16:38:32 ----D---- C:\ProgramData\PC Tools
2010-05-03 16:38:32 ----D---- C:\Program Files\Spyware Doctor
2010-05-03 16:38:19 ----AD---- C:\ProgramData\TEMP
2010-05-03 13:30:00 ----A---- C:\windows\SWXCACLS.exe
2010-05-03 13:28:13 ----A---- C:\windows\ntbtlog.txt
2010-05-02 19:59:31 ----D---- C:\Qoobox
2010-05-02 16:46:35 ----D---- C:\Program Files\ASIO4ALL v2
2010-05-01 16:29:39 ----A---- C:\windows\zip.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWSC.exe
2010-05-01 16:29:39 ----A---- C:\windows\SWREG.exe
2010-05-01 16:29:39 ----A---- C:\windows\sed.exe
2010-05-01 16:29:39 ----A---- C:\windows\PEV.exe
2010-05-01 16:29:39 ----A---- C:\windows\NIRCMD.exe
2010-05-01 16:29:39 ----A---- C:\windows\MBR.exe
2010-05-01 16:29:39 ----A---- C:\windows\grep.exe
2010-05-01 16:29:33 ----D---- C:\windows\ERDNT
======List of files/folders modified in the last 1 months======
2010-05-19 16:19:46 ----D---- C:\windows\Temp
2010-05-19 16:19:29 ----D---- C:\Program Files\trend micro
2010-05-19 16:12:44 ----D---- C:\windows\Prefetch
2010-05-19 14:14:24 ----D---- C:\Users\user\AppData\Roaming\Skype
2010-05-19 14:10:21 ----D---- C:\Users\user\AppData\Roaming\skypePM
2010-05-19 14:00:05 ----D---- C:\windows\System32
2010-05-19 14:00:04 ----D---- C:\windows\inf
2010-05-19 14:00:04 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-18 18:57:33 ----SHD---- C:\windows\Installer
2010-05-18 18:57:28 ----SHD---- C:\System Volume Information
2010-05-18 18:35:36 ----D---- C:\windows\system32\config
2010-05-18 18:35:32 ----D---- C:\windows\Tasks
2010-05-18 18:35:32 ----D---- C:\windows\system32\spool
2010-05-18 18:35:32 ----D---- C:\windows\system32\Msdtc
2010-05-18 18:35:32 ----D---- C:\windows\system32\CodeIntegrity
2010-05-18 18:35:32 ----D---- C:\windows\system32\catroot2
2010-05-18 18:35:32 ----D---- C:\Windows
2010-05-18 18:35:31 ----D---- C:\windows\system32\wbem
2010-05-18 18:35:31 ----D---- C:\windows\registration
2010-05-18 17:56:38 ----D---- C:\windows\system32\drivers
2010-05-18 17:49:37 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-13 03:10:51 ----D---- C:\windows\winsxs
2010-05-13 03:01:56 ----D---- C:\Program Files\Windows Mail
2010-05-13 03:01:38 ----D---- C:\windows\system32\catroot
2010-05-09 17:28:06 ----RSD---- C:\windows\Fonts
2010-05-09 17:12:56 ----RD---- C:\Program Files
2010-05-09 17:05:21 ----D---- C:\Program Files\VstPlugins
2010-05-06 13:57:06 ----D---- C:\Program Files\Image-Line
2010-05-06 10:36:38 ----N---- C:\windows\system32\MpSigStub.exe
2010-05-05 16:59:33 ----HD---- C:\ProgramData
2010-05-03 16:38:39 ----D---- C:\Program Files\Common Files\microsoft shared
2010-05-03 16:38:34 ----D---- C:\Program Files\Common Files
2010-05-03 13:42:10 ----D---- C:\windows\Debug
2010-05-03 13:37:08 ----D---- C:\windows\Minidump
2010-05-02 18:39:40 ----D---- C:\Program Files\CCleaner
2010-05-02 18:39:09 ----D---- C:\windows\system32\Tasks
2010-05-01 15:36:40 ----D---- C:\windows\system32\WDI
2010-04-30 20:51:06 ----A---- C:\windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;Offline Files Driver; C:\windows\system32\drivers\csc.sys [2009-04-11 351744]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2010-03-24 114984]
R1 pctgntdi;pctgntdi; \??\C:\Windows\System32\drivers\pctgntdi.sys [2009-10-30 233136]
R2 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2010-03-24 133512]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2010-03-24 134488]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2010-03-24 41312]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2008-04-22 80424]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2008-04-22 80936]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2008-04-22 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e6032.sys [2007-05-24 223616]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2010-03-24 32584]
R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2008-04-15 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ; C:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2007-06-08 30008]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-05-26 101376]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pctplsg;pctplsg; \??\C:\Windows\System32\drivers\pctplsg.sys [2009-09-03 70408]
S3 TfNetMon;TfNetMon; \??\C:\windows\system32\drivers\TfNetMon.sys [2009-11-12 33552]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2008-01-21 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 540448]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 TeamViewer4;TeamViewer 4; C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe [2009-04-17 185640]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 rpcnetp;rpcnetp; C:\windows\System32\rpcnetp.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-03-24 33560]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2008-01-21 523776]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-06-08 172131]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2008-04-16 165192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-08 1112560]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 ThreatFire;ThreatFire; C:\Program Files\Spyware Doctor\TFEngine\TFService.exe [2009-11-12 70928]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2009-04-11 918528]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
Nějaké zbytky po combofixu tam jsou
Ještě znovu spustte OTL, klikněte na tlačítko vyčisti, uklidí po sobě
Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
Otevřete si Poznámkový blok a zkopírujte do něj text
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.




http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir

Kód: Vybrat vše
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0BF43445-2F28-4351-9252-17FE6E806AA0}"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu
Je to všetko hotové