Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

100% využití CPU, často neodpovídající programy atd.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

100% využití CPU, často neodpovídající programy atd.

#1 Příspěvek od jackdoppelherz »

Prosím o kontrolu logu, nejde systém ani tento počítač, programy se sekaj, načítání trvá minimálně 10 minut, 100%využití CPU.. tak jestli se to dá nějak zachránit, nebo je reinstall nevyhnutelnej :) Díky

Logfile of random's system information tool 1.07 (written by random/random)
Run by User at 2010-05-24 18:25:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (7%) free of 76 GB
Total RAM: 1280 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:25:38, on 24.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Documents and Settings\User\Local Settings\Data aplikací\Seznam.cz\postak.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\utilman.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Plocha\RSIT.exe
C:\Program Files\trend micro\User.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Seznam Postak] "C:\Documents and Settings\User\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: UltiDev Cassini Web Server for ASP.NET 2.0 - UltiDev LLC - C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe

--
End of file - 7869 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-24 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-05-03 344064]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Documents and Settings\User\Local Settings\Data aplikací\Seznam.cz\postak.exe [2009-11-02 448664]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-24 29696]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

C:\Documents and Settings\User\Nabídka Start\Programy\Po spuštění
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-05-04 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
WgaLogon.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe"="C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe:LocalSubNet:Enabled:UltiDev Cassini Web Server for ASP.NET 2.0"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-05-24 18:25:06 ----D---- C:\Program Files\trend micro
2010-05-24 17:33:06 ----A---- C:\WINDOWS\OEWABLog.txt
2010-05-24 17:32:46 ----D---- C:\WINDOWS\Prefetch
2010-05-24 17:30:01 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-24 17:29:32 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-24 17:29:13 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-24 17:28:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-05-24 17:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-24 17:28:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-24 17:27:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-24 17:27:28 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-05-24 17:27:02 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-24 17:26:43 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-24 17:26:14 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-05-24 17:25:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-24 17:25:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-24 17:25:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-24 17:24:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-05-24 17:24:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-05-24 17:24:07 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-05-24 17:23:41 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-24 17:23:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-24 17:23:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-05-24 17:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-05-24 17:22:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-05-24 17:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-24 17:21:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-05-24 17:21:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-05-24 17:20:57 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-24 17:20:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-24 17:20:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-05-24 17:19:45 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-05-24 17:19:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-05-24 17:19:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-05-24 17:18:38 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-24 17:18:19 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-24 17:18:00 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-05-24 17:17:38 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-05-24 17:17:13 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-05-24 17:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-05-24 17:16:29 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-05-24 17:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-05-24 17:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-05-24 17:15:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2010-05-24 17:15:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2010-05-24 17:14:20 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-05-24 17:14:01 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-05-24 17:13:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-05-24 17:13:18 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-05-24 17:12:59 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-05-24 17:12:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2010-05-24 17:12:18 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-05-24 17:11:59 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-05-24 17:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-05-24 17:11:19 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2010-05-24 17:11:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-05-24 17:10:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2010-05-24 17:09:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-05-24 17:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-05-24 17:08:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-05-24 17:08:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-24 17:07:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-05-24 17:07:21 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-05-24 17:07:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2010-05-24 17:06:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2010-05-24 17:06:22 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2010-05-24 17:05:59 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-05-24 17:05:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-05-24 17:05:17 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-05-24 17:04:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-05-24 17:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2010-05-24 17:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-05-24 17:03:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2010-05-24 17:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-05-24 17:03:13 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-05-24 17:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-05-24 17:02:32 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-05-24 17:02:14 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2010-05-24 17:01:54 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-05-24 17:01:39 ----D---- C:\WINDOWS\LastGood.Tmp
2010-05-24 16:55:28 ----D---- C:\WINDOWS\l2schemas
2010-05-24 16:55:27 ----D---- C:\WINDOWS\system32\cs
2010-05-24 16:55:27 ----D---- C:\WINDOWS\system32\bits
2010-05-24 07:24:31 ----D---- C:\Program Files\QuickTime
2010-05-24 07:19:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-05-24 07:19:22 ----A---- C:\WINDOWS\system32\javaws.exe
2010-05-24 07:19:22 ----A---- C:\WINDOWS\system32\javaw.exe
2010-05-24 07:19:22 ----A---- C:\WINDOWS\system32\java.exe
2010-05-24 07:19:22 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-05-23 23:11:25 ----D---- C:\Program Files\Secunia
2010-05-16 00:03:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Office Genuine Advantage
2010-05-16 00:03:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-05-15 23:27:16 ----A---- C:\WINDOWS\setuplog.txt
2010-05-13 23:29:12 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-05-13 23:29:12 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-05-13 22:13:41 ----A---- C:\WINDOWS\wininit.ini
2010-05-13 22:06:46 ----SHD---- C:\RECYCLER
2010-05-13 18:59:56 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-05-13 18:59:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-13 18:39:33 ----A---- C:\ComboFix.txt
2010-05-13 18:27:31 ----A---- C:\WINDOWS\PEV.exe
2010-05-13 18:27:31 ----A---- C:\WINDOWS\MBR.exe
2010-05-12 21:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2010-05-12 20:47:59 ----A---- C:\WINDOWS\ViewNX.INI
2010-05-12 18:01:30 ----D---- C:\Documents and Settings\User\Data aplikací\Nikon
2010-05-12 16:23:40 ----D---- C:\123
2010-05-12 16:07:54 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-05-11 20:38:45 ----D---- C:\Program Files\Common Files\muvee Technologies
2010-05-11 20:37:57 ----D---- C:\Program Files\Common Files\Nikon
2010-05-11 20:37:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nikon
2010-05-11 20:37:35 ----D---- C:\Program Files\Nikon
2010-05-11 20:35:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ultima_T15
2010-05-11 20:35:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\EnterNHelp
2010-05-06 22:23:15 ----D---- C:\Documents and Settings\User\Data aplikací\Opera

======List of files/folders modified in the last 1 months======

2010-05-24 18:25:06 ----RD---- C:\Program Files
2010-05-24 17:43:11 ----D---- C:\WINDOWS\temp
2010-05-24 17:35:11 ----D---- C:\WINDOWS\system32
2010-05-24 17:34:35 ----D---- C:\WINDOWS\Debug
2010-05-24 17:34:30 ----D---- C:\WINDOWS
2010-05-24 17:33:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-24 17:31:42 ----D---- C:\WINDOWS\system32\Setup
2010-05-24 17:31:42 ----D---- C:\WINDOWS\AppPatch
2010-05-24 17:31:41 ----D---- C:\WINDOWS\system32\wbem
2010-05-24 17:31:40 ----RSD---- C:\WINDOWS\Fonts
2010-05-24 17:31:36 ----D---- C:\WINDOWS\system32\drivers
2010-05-24 17:30:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-24 17:30:39 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-24 17:30:16 ----HD---- C:\WINDOWS\inf
2010-05-24 17:30:04 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-24 17:28:15 ----D---- C:\Program Files\Outlook Express
2010-05-24 17:25:28 ----D---- C:\Program Files\Movie Maker
2010-05-24 17:07:26 ----D---- C:\WINDOWS\security
2010-05-24 17:02:34 ----D---- C:\Program Files\Messenger
2010-05-24 16:56:17 ----D---- C:\WINDOWS\WinSxS
2010-05-24 16:56:00 ----D---- C:\WINDOWS\EHome
2010-05-24 16:55:58 ----D---- C:\WINDOWS\system32\inetsrv
2010-05-24 16:55:57 ----D---- C:\WINDOWS\network diagnostic
2010-05-24 16:55:57 ----D---- C:\WINDOWS\ime
2010-05-24 16:55:56 ----D---- C:\WINDOWS\Help
2010-05-24 16:55:30 ----D---- C:\WINDOWS\system32\usmt
2010-05-24 16:55:30 ----D---- C:\WINDOWS\system32\cs-cz
2010-05-24 16:55:27 ----SHD---- C:\WINDOWS\Installer
2010-05-24 16:55:27 ----D---- C:\WINDOWS\peernet
2010-05-24 16:50:32 ----D---- C:\WINDOWS\system32\Restore
2010-05-24 16:50:32 ----D---- C:\WINDOWS\system32\npp
2010-05-24 16:50:31 ----D---- C:\WINDOWS\msagent
2010-05-24 16:50:29 ----D---- C:\WINDOWS\srchasst
2010-05-24 16:50:27 ----D---- C:\Program Files\NetMeeting
2010-05-24 16:50:26 ----D---- C:\WINDOWS\system32\Com
2010-05-24 16:50:23 ----D---- C:\Program Files\Windows NT
2010-05-24 16:50:23 ----D---- C:\Program Files\Windows Media Player
2010-05-24 16:50:20 ----D---- C:\Program Files\Common Files\System
2010-05-24 16:50:00 ----D---- C:\WINDOWS\system32\oobe
2010-05-24 16:49:58 ----D---- C:\WINDOWS\system
2010-05-24 16:45:46 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-24 16:45:21 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-05-24 07:26:31 ----D---- C:\Config.Msi
2010-05-24 07:17:39 ----D---- C:\Program Files\Java
2010-05-24 06:44:02 ----D---- C:\Program Files\uTorrent
2010-05-23 22:35:06 ----D---- C:\Documents and Settings\User\Data aplikací\uTorrent
2010-05-17 15:11:52 ----D---- C:\Documents and Settings\User\Data aplikací\ICQ
2010-05-16 21:06:05 ----A---- C:\WINDOWS\wincmd.ini
2010-05-16 13:36:50 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-16 00:51:11 ----D---- C:\WINDOWS\SoftwareDistribution
2010-05-16 00:32:31 ----D---- C:\Program Files\Common Files\Adobe
2010-05-16 00:32:31 ----D---- C:\Program Files\Adobe
2010-05-16 00:30:09 ----RD---- C:\Program Files\Common Files
2010-05-16 00:30:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-05-13 18:39:37 ----D---- C:\Qoobox
2010-05-13 18:37:47 ----D---- C:\WINDOWS\ERDNT
2010-05-13 18:36:39 ----A---- C:\WINDOWS\system.ini
2010-05-13 18:35:59 ----D---- C:\Program Files\Internet Explorer
2010-05-13 18:16:04 ----SD---- C:\WINDOWS\Tasks
2010-05-12 14:44:29 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-11 20:33:52 ----A---- C:\WINDOWS\system32\ATL71.DLL
2010-05-06 22:23:18 ----A---- C:\WINDOWS\win.ini
2010-04-30 20:51:06 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2002-12-05 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2007-03-08 20747]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-02-07 271360]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-02-07 18048]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-05-04 1133056]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\sisnic.sys [2004-08-03 32768]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-08-29 578304]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
S3 catchme;catchme; \??\C:\DOCUME~1\JAKUBS~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WUDFRd;WUDFRd; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-05-04 364544]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-05-24 153376]
R2 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2005-01-14 53248]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0; C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [2007-02-07 49152]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-05-03 516096]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-02-10 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#2 Příspěvek od Caroprd111 »

Zdravím :)


Obrázek Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#3 Příspěvek od jackdoppelherz »

Extras.txt:
OTL Extras logfile created on: 24.5.2010 18:47:25 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Jakub Sirovátko\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 56,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 5,48 Gb Free Space | 7,36% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAKUB-GN8G3KS7K
Current User Name: Jakub Sirovátko
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ -- (ICQ, LLC.)
"C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe" = C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe:LocalSubNet:Enabled:UltiDev Cassini Web Server for ASP.NET 2.0 -- (UltiDev LLC)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{19D2B63E-C1F1-4803-BA8B-4AB8FE216952}" = EPSON PRINT Image Framer Tool
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{40247AAC-AB0D-449C-882F-90401C3351E8}" = UltiDev Cassini Web Server Explorer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F62B1AE-E778-49E2-9C57-C1C65A122098}" = Zoner Callisto 5
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{659B48CD-0608-4ED5-94C0-0B6C87114F10}" = Apple Mobile Device Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7CBD8A89-45F4-4203-9923-673F72603747}" = Adobe Photoshop Lightroom 2.3
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8F722FA9-B994-4C9B-B292-FD32D6206EDF}" = ASUS WLAN Card Utilities/Driver
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1029-7B44-A70500000002}" = Adobe Reader 7.0.5 - Czech
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC5702D7-86E2-45A8-99D7-E8B976ADCC56}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DA507A38-4B2A-40C0-90AC-E30AAA0B757C}" = Vegas Movie Studio Platinum 9.0
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F11A3FEB-CB75-499C-A50C-4D75B98600E3}" = SteelSeries Ikari Optical
"{F6C8DAED-8CC7-43FD-9DA4-1F629B873A17}" = UltiDev Cassini Web Server for ASP.NET 2.0
"µTorrent CZ_is1" = µTorrent CZ 1.8.2 (build 15196)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"B/Works for Digital Cameras_is1" = B/Works for Digital Cameras
"Babarosa Gif Animator 3.6" = Babarosa Gif Animator 3.6 (Remove only)
"BSPlayer1" = BSPlayer
"CCleaner" = CCleaner (remove only)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ffdshow" = ffdshow (remove only)
"FLVPlayer" = FLV Player 1.3.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoFiltre" = PhotoFiltre
"PhotoScape" = PhotoScape
"Secunia PSI" = Secunia PSI
"Total Video Converter 3.12_is1" = Total Video Converter 3.12 080330
"Totalcmd" = Total Commander (Remove or Repair)
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"szn-software-postak" = Seznam Pošťák 2 (Pouze já.)

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 9.9.2009 9:23:25 | Computer Name = JAKUB-GN8G3KS7K | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\WINDOWS\SoftwareDistribution\Download\805e34e596e447f1c06e29dafea311a6\BIT6.tmp
failed, 00000026.

Error - 26.10.2009 16:51:56 | Computer Name = JAKUB-GN8G3KS7K | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of D:\104NIKON\DSCN0209.JPG failed, 0000001E.

Error - 6.11.2009 11:15:41 | Computer Name = JAKUB-GN8G3KS7K | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://www.flickr.com/photos/ts3simposi ... 7487182319
failed, 0000A413.

Error - 8.11.2009 12:20:35 | Computer Name = JAKUB-GN8G3KS7K | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://media.adtitan.net/160x600/160_Swarm_002.swf failed, 0000A413.

Error - 8.11.2009 12:27:15 | Computer Name = JAKUB-GN8G3KS7K | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://www.flickr.com/photos/ts3simposi ... 1207818687
failed, 0000A413.

[ Application Events ]
Error - 21.8.2009 9:34:37 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace showtime.exe, verze 4.3.2.0, chybující modul vp6dec.ax,
verze 6.4.2.0, adresa chyby 0x00001b02.

Error - 21.8.2009 18:56:58 | Computer Name = JAKUB-GN8G3KS7K | Source = ASWLSVC | ID = 0
Description =

Error - 22.8.2009 15:51:49 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.2900.3156, chybující modul
shell32.dll, verze 6.0.2900.3402, adresa chyby 0x0002af84.

Error - 22.8.2009 16:01:09 | Computer Name = JAKUB-GN8G3KS7K | Source = ASWLSVC | ID = 0
Description =

Error - 24.8.2009 17:39:36 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace , verze 0.0.0.0, chybující modul ntdll.dll, verze
5.1.2600.3520, adresa chyby 0x000119b3.

Error - 28.8.2009 9:11:52 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1004
Description = Chybující aplikace winlogon.exe, verze 0.0.0.0, chybující modul ntdll.dll,
verze 5.1.2600.3520, adresa chyby 0x000119b3.

Error - 3.9.2009 10:02:12 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace icq.exe, verze 6.5.0.1042, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x002f0031.

Error - 4.9.2009 8:53:51 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace icq.exe, verze 6.5.0.1042, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x002f0031.

Error - 3.10.2009 10:08:09 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace icq.exe, verze 6.5.0.1042, chybující modul mshtml.dll,
verze 7.0.6000.16890, adresa chyby 0x000b232c.

Error - 9.10.2009 14:15:56 | Computer Name = JAKUB-GN8G3KS7K | Source = Application Error | ID = 1000
Description = Chybující aplikace icq.exe, verze 6.5.0.1042, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x002f00fb.

[ System Events ]
Error - 13.5.2010 11:55:34 | Computer Name = JAKUB-GN8G3KS7K | Source = Service Control Manager | ID = 7000
Description = Služba Windows Driver Foundation - User-mode Driver Framework Reflector
neuspěla při spuštění v důsledku následující chyby: %%2

Error - 13.5.2010 12:30:27 | Computer Name = JAKUB-GN8G3KS7K | Source = Service Control Manager | ID = 7034
Description = Služba ASWLSVC byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error - 13.5.2010 12:30:27 | Computer Name = JAKUB-GN8G3KS7K | Source = Service Control Manager | ID = 7034
Description = Služba STI Simulator byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 15.5.2010 11:28:33 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.

Error - 19.5.2010 12:15:36 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.

Error - 19.5.2010 14:09:43 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.

Error - 19.5.2010 14:09:48 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1001
Description = Počítači nebyla přiřazena síťová adresa (serverem DHCP) pro síťovou
kartu se síťovou adresou 000C6EA88E3D. Došlo k následující chybě: %%1223. Počítač
se bude pokoušet získat síťovou adresu samostatně ze serveru DHCP.

Error - 20.5.2010 15:50:33 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.

Error - 21.5.2010 14:58:55 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.

Error - 23.5.2010 11:22:48 | Computer Name = JAKUB-GN8G3KS7K | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.8 pro síťovou kartu se síťovou
adresou 000C6EA88E3D byla ukončena.


< End of report >

OTL.txt:

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#4 Příspěvek od jackdoppelherz »

OTL.txt:
OTL logfile created on: 24.5.2010 18:47:25 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Jakub Sirovátko\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 56,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 5,48 Gb Free Space | 7,36% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAKUB-GN8G3KS7K
Current User Name: Jakub Sirovátko
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.05.24 18:46:36 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\OTL.exe
PRC - [2010.04.03 23:31:20 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.11.25 01:51:40 | 000,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009.11.25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009.11.25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009.11.25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009.11.25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009.11.02 15:05:06 | 000,448,664 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\Seznam.cz\postak.exe
PRC - [2008.06.05 10:19:18 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008.04.14 05:22:51 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\utilman.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.02.07 23:06:10 | 000,049,152 | ---- | M] (UltiDev LLC) -- C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
PRC - [2005.01.14 10:32:38 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe


========== Modules (SafeList) ==========

MOD - [2010.05.24 18:46:36 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2009.11.25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.11.25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.11.25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.11.25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2007.02.07 23:06:10 | 000,049,152 | ---- | M] (UltiDev LLC) [Auto | Running] -- C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe -- (UltiDev Cassini Web Server for ASP.NET 2.0)
SRV - [2005.01.14 10:32:38 | 000,053,248 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PAStiSvc.exe -- (STI Simulator)


========== Driver Services (SafeList) ==========

DRV - [2009.11.25 01:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.11.25 01:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.11.25 01:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.11.25 01:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.11.25 01:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.11.25 01:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009.06.17 14:20:34 | 000,012,648 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI)
DRV - [2009.05.22 19:19:19 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008.04.13 20:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007.02.07 13:11:38 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2007.02.07 13:11:38 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2005.05.04 04:28:34 | 001,133,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004.08.03 16:31:36 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2003.07.18 09:58:20 | 000,036,992 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys -- (sisagp)
DRV - [2003.03.25 17:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\siside.sys -- (SiSide)
DRV - [2002.10.17 15:14:46 | 000,049,024 | R--- | M] (Windows (R) 2000 DDK provider) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex)
DRV - [2002.09.09 13:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5)
DRV - [2002.08.20 17:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
IE - HKU\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-1757981266-329068152-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-329068152-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.05.24 07:26:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.05.24 07:26:12 | 000,000,000 | ---D | M]

[2008.07.15 18:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Mozilla\Extensions
[2010.04.18 16:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Mozilla\Firefox\Profiles\quuitt82.default\extensions
[2010.05.24 16:30:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.05.24 07:19:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.05.24 07:17:50 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.25 21:49:08 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.03.25 21:49:08 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.03.25 21:49:08 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.03.25 21:49:08 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.03.25 21:49:08 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.05.22 20:00:13 | 000,394,534 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13649 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKU\S-1-5-21-1757981266-329068152-725345543-1003..\Run: [Seznam Postak] C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\Seznam.cz\postak.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\Jakub Sirovátko\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Jakub Sirovátko\Nabídka Start\Programy\Po spuštění\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.06.03 21:44:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006.06.03 21:43:46 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)

========== Files/Folders - Created Within 30 Days ==========

[2010.05.24 18:46:28 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\OTL.exe
[2010.05.24 18:25:06 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.05.24 17:32:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010.05.24 17:01:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood.Tmp
[2010.05.24 16:55:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010.05.24 16:55:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs
[2010.05.24 16:55:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010.05.24 07:24:31 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010.05.24 07:19:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Sun
[2010.05.24 07:19:22 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.05.24 07:19:22 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.05.24 07:19:22 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.05.24 07:19:22 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.05.23 23:11:25 | 000,000,000 | ---D | C] -- C:\Program Files\Secunia
[2010.05.23 22:42:52 | 000,716,320 | ---- | C] (Secunia) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\PSISetup.exe
[2010.05.16 14:44:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Plocha\Apocalypse
[2010.05.16 00:03:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Office Genuine Advantage
[2010.05.16 00:03:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
[2010.05.15 13:07:48 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Jakub Sirovátko\Recent
[2010.05.13 23:29:12 | 000,129,520 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxafs.dll
[2010.05.13 23:29:12 | 000,072,176 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxhpinst.exe
[2010.05.13 22:06:46 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.05.13 18:59:56 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010.05.13 18:59:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
[2010.05.13 17:38:46 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\drivers\lbrtfdc.sys
[2010.05.13 17:35:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\changer.sys
[2010.05.13 17:35:55 | 000,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdaudio.sys
[2010.05.12 21:09:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Plocha\galerka2
[2010.05.12 20:42:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Plocha\na fb
[2010.05.12 20:28:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Plocha\Do galerie
[2010.05.12 18:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Nikon
[2010.05.12 16:23:40 | 000,000,000 | ---D | C] -- C:\123
[2010.05.11 20:38:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\muvee Technologies
[2010.05.11 20:37:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nikon
[2010.05.11 20:37:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Nikon
[2010.05.11 20:37:35 | 000,000,000 | ---D | C] -- C:\Program Files\Nikon
[2010.05.11 20:35:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Ultima_T15
[2010.05.11 20:35:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\EnterNHelp
[2010.05.06 22:23:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Opera
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[61 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.05.24 18:46:36 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\OTL.exe
[2010.05.24 18:13:27 | 000,824,681 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\RSIT.exe
[2010.05.24 18:08:21 | 012,058,624 | -H-- | M] () -- C:\Documents and Settings\Jakub Sirovátko\NTUSER.DAT
[2010.05.24 17:34:02 | 000,000,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.05.24 17:32:46 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.05.24 17:32:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.05.24 17:31:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.05.24 17:31:46 | 000,442,920 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.05.24 17:30:36 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Jakub Sirovátko\ntuser.ini
[2010.05.24 16:47:24 | 000,250,576 | RHS- | M] () -- C:\ntldr
[2010.05.24 07:25:40 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\QuickTime Player.lnk
[2010.05.24 07:17:48 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.05.24 07:17:48 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.05.24 07:17:48 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.05.24 07:17:47 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.05.24 07:17:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.05.24 07:02:19 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Nabídka Start\Programy\Po spuštění\Secunia PSI.lnk
[2010.05.23 22:43:13 | 000,716,320 | ---- | M] (Secunia) -- C:\Documents and Settings\Jakub Sirovátko\Plocha\PSISetup.exe
[2010.05.23 21:41:56 | 000,142,862 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Dokumenty\cc_20100523_213658.reg
[2010.05.23 19:30:45 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2010.05.23 15:59:29 | 000,136,192 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.22 20:00:13 | 000,394,534 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.05.22 11:41:57 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2010.05.20 15:57:33 | 001,124,276 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0568-1-2.jpg
[2010.05.18 22:39:49 | 000,482,776 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0650-1.jpg
[2010.05.18 22:07:50 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2010.05.16 21:06:05 | 000,001,019 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.05.16 20:37:23 | 000,000,201 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2010.05.16 20:32:15 | 000,577,581 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0207-1.jpg
[2010.05.16 20:31:54 | 000,533,656 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0211-1.jpg
[2010.05.16 20:31:09 | 000,606,982 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0311-1.jpg
[2010.05.16 20:29:06 | 000,575,038 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0235-1.jpg
[2010.05.16 20:28:45 | 000,556,503 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0217-1.jpg
[2010.05.16 13:36:50 | 000,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.05.16 13:30:05 | 001,239,311 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0589-1.jpg
[2010.05.16 00:27:00 | 000,033,792 | -H-- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\photothumb.db
[2010.05.16 00:26:48 | 000,632,009 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\pizzapec-1.jpg
[2010.05.15 23:56:57 | 000,000,074 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100522-200013.backup
[2010.05.15 23:29:21 | 000,018,882 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\key.jpg
[2010.05.15 13:17:41 | 000,036,840 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Dokumenty\cc_20100515_131414.reg
[2010.05.13 23:29:06 | 000,001,834 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Photoshop Lightroom 2.3.lnk
[2010.05.13 22:13:41 | 000,000,099 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010.05.13 18:36:39 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.05.13 18:13:25 | 003,688,590 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\ComboFix.exe
[2010.05.13 17:26:08 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\qvjsge.dat
[2010.05.13 17:25:58 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\avdrn.dat
[2010.05.13 17:02:55 | 000,001,150 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon5.ico
[2010.05.13 17:02:23 | 000,001,150 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon1.ico
[2010.05.13 10:25:32 | 000,005,998 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon.ico
[2010.05.12 20:47:59 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ViewNX.INI
[2010.05.12 20:15:13 | 000,001,150 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon123.ico
[2010.05.11 20:48:07 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\ViewNX.lnk
[2010.05.11 20:46:00 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\Chorus
[2010.05.11 20:46:00 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Calibrators
[2010.05.11 20:46:00 | 000,000,012 | RH-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\Colors
[2010.05.11 20:40:19 | 000,001,815 | ---- | M] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Nikon Monitor.lnk
[2010.05.11 20:38:56 | 000,001,755 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Nikon Transfer.lnk
[2010.05.11 20:35:07 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\Channel
[2010.05.11 20:35:06 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\CMMs
[2010.05.11 20:35:06 | 000,000,012 | RH-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\Clips
[2010.05.11 20:33:52 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ATL71.DLL
[2010.05.08 20:39:04 | 000,128,120 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.05.06 22:23:18 | 000,000,612 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.04.26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[61 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.05.24 18:13:16 | 000,824,681 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\RSIT.exe
[2010.05.24 07:25:40 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\QuickTime Player.lnk
[2010.05.24 07:02:19 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Nabídka Start\Programy\Po spuštění\Secunia PSI.lnk
[2010.05.23 21:37:00 | 000,142,862 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Dokumenty\cc_20100523_213658.reg
[2010.05.18 22:35:04 | 000,482,776 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0650-1.jpg
[2010.05.18 22:26:19 | 001,124,276 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0568-1-2.jpg
[2010.05.16 13:29:53 | 001,239,311 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0589-1.jpg
[2010.05.16 00:26:45 | 000,632,009 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\pizzapec-1.jpg
[2010.05.15 23:29:20 | 000,018,882 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\key.jpg
[2010.05.15 14:15:49 | 000,533,656 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0211-1.jpg
[2010.05.15 14:11:43 | 000,577,581 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0207-1.jpg
[2010.05.15 14:08:33 | 000,556,503 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0217-1.jpg
[2010.05.15 14:03:18 | 000,575,038 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0235-1.jpg
[2010.05.15 13:56:30 | 000,606,982 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\DSC_0311-1.jpg
[2010.05.15 13:14:16 | 000,036,840 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Dokumenty\cc_20100515_131414.reg
[2010.05.13 23:29:06 | 000,001,834 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Adobe Photoshop Lightroom 2.3.lnk
[2010.05.13 22:13:41 | 000,000,099 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010.05.13 18:27:31 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.05.13 18:27:31 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.05.13 17:34:01 | 003,688,590 | R--- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\ComboFix.exe
[2010.05.13 17:26:08 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\qvjsge.dat
[2010.05.13 17:25:58 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\avdrn.dat
[2010.05.13 17:02:22 | 000,001,150 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon1.ico
[2010.05.12 20:47:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX.INI
[2010.05.12 20:15:12 | 000,001,150 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon123.ico
[2010.05.12 18:19:36 | 000,005,998 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon.ico
[2010.05.12 18:19:36 | 000,001,150 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\favicon5.ico
[2010.05.12 16:07:54 | 000,000,201 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2010.05.11 20:48:07 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\ViewNX.lnk
[2010.05.11 20:46:00 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Chorus
[2010.05.11 20:46:00 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Calibrators
[2010.05.11 20:46:00 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2010.05.11 20:46:00 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Colors
[2010.05.11 20:40:17 | 000,001,815 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Nikon Monitor.lnk
[2010.05.11 20:38:56 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nikon Transfer.lnk
[2010.05.11 20:35:07 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Channel
[2010.05.11 20:35:06 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\CMMs
[2010.05.11 20:35:06 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Clips
[2010.05.11 20:35:05 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2010.05.04 23:18:38 | 004,422,063 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\101 Tipů fotorádce.pdf
[2010.04.25 18:16:11 | 000,000,870 | ---- | C] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\San Andreas Multiplayer.lnk
[2010.03.03 21:18:54 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfmonnt.dll
[2009.12.07 20:04:19 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009.10.22 18:25:27 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009.06.03 15:58:56 | 000,001,152 | ---- | C] () -- C:\WINDOWS\System32\windrv.sys
[2008.02.29 06:14:04 | 000,223,744 | ---- | C] () -- C:\WINDOWS\System32\b4fm.dll
[2007.02.12 12:04:03 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2007.02.12 12:03:58 | 000,845,312 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2007.02.07 13:11:38 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007.02.07 13:11:38 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007.02.04 09:40:33 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2006.07.13 16:46:45 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2006.07.13 16:30:26 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2006.06.29 16:42:32 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.06.26 14:33:28 | 000,000,449 | ---- | C] () -- C:\WINDOWS\level.ini
[2006.06.03 22:59:09 | 000,139,264 | R--- | C] () -- C:\WINDOWS\System32\IDEproperty.dll
[2006.06.03 22:54:36 | 000,001,019 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.01.25 16:15:42 | 000,010,240 | R--- | C] () -- C:\WINDOWS\System32\PA207USD.DLL
[1993.07.23 19:31:02 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll

========== LOP Check ==========

[2009.05.22 20:42:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2010.05.11 20:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EnterNHelp
[2010.01.15 16:41:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EPSON
[2010.05.11 20:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nikon
[2010.04.16 19:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.01.15 17:29:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\UDL
[2010.04.09 14:57:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
[2009.10.04 14:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\UltiDev
[2010.05.11 20:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ultima_T15
[2009.07.31 17:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009.07.15 16:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Canneverbe_Limited
[2009.11.22 01:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\CoSoSys
[2009.08.21 16:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Desktopicon
[2010.04.01 17:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\EPSON
[2010.03.17 00:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\gtk-2.0
[2010.05.17 15:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQ
[2007.10.04 09:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQ6
[2007.04.03 08:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQLite
[2006.12.18 13:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Leadertech
[2010.05.15 22:10:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Nikon
[2010.05.06 22:23:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Opera
[2010.04.16 19:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Publish Providers
[2010.04.16 21:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Sony
[2006.06.23 21:40:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Teleca
[2009.11.13 20:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Ulead Systems
[2010.05.23 22:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\uTorrent
[2009.11.03 20:00:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Watermark Master
[2009.06.23 17:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Zoner

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Seznam Postak" = "C:\Documents and Settings\Jakub Sirovátko\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s -- [2009.11.02 15:05:06 | 000,448,664 | ---- | M] ()
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)

< c:\windows\*.* /U >
[7 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[2001.05.24 06:59:30 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2010.03.03 19:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Adobe
[2006.12.18 13:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\AdobeUM
[2009.07.31 17:33:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Apple Computer
[2006.11.15 13:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ATI
[2009.07.15 16:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Canneverbe_Limited
[2009.11.22 01:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\CoSoSys
[2009.08.21 16:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Desktopicon
[2010.04.01 17:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\EPSON
[2010.03.17 00:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\gtk-2.0
[2006.10.03 14:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Help
[2010.05.17 15:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQ
[2007.10.04 09:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQ6
[2007.04.03 08:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\ICQLite
[2006.06.03 22:11:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Identities
[2008.01.30 17:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\InstallShield
[2006.12.18 13:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Leadertech
[2006.11.23 09:53:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Macromedia
[2010.04.14 23:07:16 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft
[2008.07.15 18:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Mozilla
[2007.04.10 13:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\MSN6
[2009.07.17 17:38:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Nero
[2010.05.15 22:10:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Nikon
[2010.05.06 22:23:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Opera
[2010.04.16 19:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Publish Providers
[2007.07.03 11:07:46 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\SecuROM
[2010.04.05 14:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\skypePM
[2010.04.16 21:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Sony
[2006.06.23 21:48:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Sony Ericsson
[2008.08.08 16:43:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Sun
[2006.06.23 21:40:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Teleca
[2009.11.13 20:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Ulead Systems
[2010.05.23 22:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\uTorrent
[2009.11.03 20:00:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Watermark Master
[2009.06.23 17:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Zoner

< %APPDATA%\*.exe /s >
[2008.10.28 18:20:32 | 000,089,088 | ---- | M] (AD ON Multimedia Advertising GmbH) -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Desktopicon\eBayShortcuts.exe
[2006.12.07 15:27:29 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\ARPPRODUCTICON.exe
[2006.12.07 15:27:29 | 000,008,854 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\Uninstall_WD_Diagnos_0AB76F69E7614CFAB9B0A1906B4E9E4B.exe
[2006.12.07 15:27:29 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe
[2009.10.04 14:50:02 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{40247AAC-AB0D-449C-882F-90401C3351E8}\_69525f90.exe
[2010.05.11 20:56:27 | 000,057,344 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
[2010.05.11 20:57:34 | 000,049,152 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
[2009.05.22 20:21:15 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#5 Příspěvek od jackdoppelherz »

druhá část otl.txt, nevešel se celej

< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\agp440.sys

< MD5 for: ATAPI.SYS >
[2002.12.05 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys

< MD5 for: CDROM.SYS >
[2002.12.05 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\ERDNT\cache\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 15:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007.06.13 15:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\ERDNT\cache\explorer.exe

< MD5 for: HAL.DLL >
[2002.12.05 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\hal.dll
[2008.04.13 20:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.03 22:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:Changer.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\drivers\changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\$NtServicePackUninstall$\changer.sys

< MD5 for: ISAPNP.SYS >
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2010.05.24 16:40:18 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:isapnp.sys
[2002.12.05 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\ERDNT\cache\svchost.exe

< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys


< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\ERDNT\cache\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[61 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.05.22 19:19:19 | 000,721,904 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2006.06.03 23:29:44 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006.06.03 23:29:44 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006.06.03 23:29:44 | 000,389,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[61 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2010.05.24 07:17:47 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\deployJava1.dll
[2010.05.24 17:31:46 | 000,442,920 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2010.05.24 07:17:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\java.exe
[2010.05.24 07:17:48 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\javacpl.cpl
[2010.05.24 07:17:48 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\javaw.exe
[2010.05.24 07:17:48 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\javaws.exe
[2010.05.24 17:33:15 | 000,000,090 | ---- | M] () -- C:\WINDOWS\system32\spupdwxp.log
[2010.05.24 17:32:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[61 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#6 Příspěvek od Caroprd111 »

Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
O3 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O15 - HKU\S-1-5-21-1757981266-329068152-725345543-1003\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[61 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2010.05.13 18:13:25 | 003,688,590 | R--- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Plocha\ComboFix.exe
[2010.05.13 17:26:08 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\qvjsge.dat
[2010.05.13 17:25:58 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Jakub Sirovátko\Data aplikací\avdrn.dat
[2001.05.24 06:59:30 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[RESETHOSTS] 
[CREATERESTOREPOINT]
Poté klikněte na Opravit, PC se restartuje, log vložte sem.



Obrázek Zkopírujte sem log C:\ComboFix.txt


Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#7 Příspěvek od jackdoppelherz »

omlouvám se za zpoždění, počítač se stále zapíná strašně pomalu - teď jsem čekal téměř 20 minut..
http://uloz.to/4913735/combofix.txt - jestli vám nebude vadit takhle, má přes 300 000 znaků a tady je limit 60 000..

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#8 Příspěvek od Caroprd111 »

Vynechte část ((((((((((((((((((((((((((((( SnapShot@2009-06-03_14.18.29 ))))))))))))))))))))))))))))))))))))))))) a vložte log normálně do příspěvku.
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#9 Příspěvek od jackdoppelherz »

ComboFix 10-05-13.01 - Jakub Sirovátko 13.05.2010 18:30:39.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1280.798 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jakub Sirovátko\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100513-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\SET403.tmp
c:\program files\Internet Explorer\SET408.tmp
c:\program files\Internet Explorer\SET49D.tmp
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-13 do 2010-05-13 )))))))))))))))))))))))))))))))
.

2010-05-13 15:53 . 2004-08-03 20:59 11392 -c--a-w- c:\windows\system32\dllcache\sfloppy.sys
2010-05-13 15:53 . 2004-08-03 20:59 11392 ----a-w- c:\windows\system32\drivers\Sfloppy.sys
2010-05-13 15:38 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-05-13 15:38 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-05-13 15:36 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-05-13 15:36 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-05-13 15:35 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-05-13 15:35 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-05-13 15:35 . 2002-12-05 12:00 18688 -c--a-w- c:\windows\system32\dllcache\cdaudio.sys
2010-05-13 15:35 . 2002-12-05 12:00 18688 ----a-w- c:\windows\system32\drivers\Cdaudio.sys
2010-05-12 14:23 . 2010-05-13 15:08 -------- d-----w- C:\123
2010-05-11 18:38 . 2010-05-11 18:38 -------- d-----w- c:\program files\Common Files\muvee Technologies
2010-05-11 18:37 . 2010-05-11 18:57 -------- d-----w- c:\program files\Common Files\Nikon
2010-05-11 18:37 . 2010-05-11 18:47 -------- d-----w- c:\program files\Nikon
2010-04-16 17:29 . 2010-04-16 17:29 -------- d-----w- c:\program files\Vstplugins
2010-04-16 17:28 . 2010-04-16 17:28 -------- d-----w- c:\program files\Sony
2010-04-16 17:26 . 2010-04-16 17:26 -------- d-----w- c:\program files\Sony Setup

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-13 14:14 . 2006-07-13 14:50 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-11 18:33 . 2003-03-17 21:00 106496 ----a-w- c:\windows\system32\ATL71.DLL
2010-04-23 13:13 . 2006-06-03 21:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-20 19:13 . 2009-04-03 19:38 -------- d-----w- c:\program files\Total Video Converter
2010-04-18 16:35 . 2010-04-10 20:52 -------- d-----w- c:\program files\PhotoScape
2010-04-09 13:00 . 2009-04-03 22:01 -------- d-----w- c:\program files\Windows Media Connect 2
2010-03-30 19:45 . 2006-06-26 12:42 -------- d-----w- c:\program files\Ahead
2010-03-30 19:45 . 2010-03-30 19:45 -------- d-----w- c:\program files\Common Files\Ahead
2010-03-28 10:44 . 2002-12-05 12:00 83742 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 10:44 . 2002-12-05 12:00 441086 ----a-w- c:\windows\system32\perfh005.dat
2010-03-11 12:36 . 2002-12-05 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:36 . 2006-06-03 20:44 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:36 . 2002-12-05 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:11 . 2002-12-05 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 12:31 . 2002-12-05 12:00 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:34 . 2002-12-05 12:00 2183552 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:34 . 2002-09-20 17:12 2060544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-12-24 14:00 . 2006-12-24 14:00 467 ----a-w- c:\program files\Common Files\Zástupce - Common Files.lnk
.


-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\documents and settings\Jakub Sirovátko\Local Settings\Data aplikací\Seznam.cz\postak.exe" [2009-11-02 448664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 344064]
"googleTalk MeBeam plugin"="c:\windows\system32\mebeam.exe" [2008-07-28 310272]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\Jakub Sirov tko\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2008-6-5 479232]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [17.7.2009 20:35 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.7.2009 20:35 20560]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0;c:\program files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [8.2.2007 0:06 49152]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.7.2006 16:30 721904]
.
Obsah adresáře 'Naplánované úlohy'

2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Jakub Sirovátko\Data aplikací\Mozilla\Firefox\Profiles\quuitt82.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
MSConfigStartUp-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
MSConfigStartUp-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
MSConfigStartUp-New - c:\progra~1\NEWDOT~1\NEWDOT~1.DLL
MSConfigStartUp-RemoteControl - c:\program files\CyberLink\PowerDVD\PDVDServ.exe
MSConfigStartUp-saap - c:\program files\search-assistant\saap.exe
MSConfigStartUp-VVSN - c:\program files\VVSN\VVSN.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-13 18:36
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1757981266-329068152-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7f,32,83,18,bf,bf,52,54,59,79,9b,79,ca,63,40,68,c2,39,0e,f9,57,d7,da,
52,e2,a9,a7,8b,81,9c,e3,f3,07,ef,5c,54,4f,f5,38,7b,2a,4c,25,d6,31,11,d2,bf,\
"??"=hex:ab,9a,c5,08,e5,90,3a,ec,ba,d1,76,7b,7e,73,07,a4

[HKEY_USERS\S-1-5-21-1757981266-329068152-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:26,ae,8b,0c,9d,81,a3,42,4d,c1,d9,61,95,6c,2b,1f,73,3b,81,55,44,
b7,73,e9,e1,02,0a,d4,67,28,15,0f,79,ee,9f,ee,10,ee,d6,14,1e,74,57,88,26,53,\
"rkeysecu"=hex:0b,47,7b,55,d4,e7,ec,4c,4d,9b,b4,8d,04,49,6d,56
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(512)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-05-13 18:39:32
ComboFix-quarantined-files.txt 2010-05-13 16:39
ComboFix2.txt 2009-06-03 20:01
ComboFix3.txt 2009-06-03 20:34

Před spuštěním: Volných bajtů: 10 105 262 080
Po spuštění: Volných bajtů: 10 090 242 048

- - End Of File - - 09455320EA45B5D27A879831C06AC63C

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#10 Příspěvek od Caroprd111 »

Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#11 Příspěvek od jackdoppelherz »

mbr.log
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys siside.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

gmer1.log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-24 21:54:28
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JAKUBS~1\LOCALS~1\Temp\uwpcakod.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----

gmer2.log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-24 22:34:22
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JAKUBS~1\LOCALS~1\Temp\uwpcakod.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1DE26B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1DE2574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1DE2A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1DE214C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1DE264E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1DE208C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1DE20F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1DE276E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1DE272E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1DE28AE]

---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xAF3DF300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB20DB300, 0x1B7E, 0xE8000020]
? C:\DOCUME~1\JAKUBS~1\LOCALS~1\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[3612] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[544] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[544] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE6 0x87 0x5D 0x8E ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9E 0x4C 0x8E 0xEC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE6 0x87 0x5D 0x8E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9E 0x4C 0x8E 0xEC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE6 0x87 0x5D 0x8E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9E 0x4C 0x8E 0xEC ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE6 0x87 0x5D 0x8E ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9E 0x4C 0x8E 0xEC ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109030000000000000000F01FEC\Usage@ProductFiles 1018691886
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109030000000000000000F01FEC\Usage@WORDFiles 1017381446

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#12 Příspěvek od Caroprd111 »

Obrázek Stáhněte MBAM http://www.viry.cz/forum/viewtopic.php?f=29&t=67229
  • Podle návodu v odkazu nainstalujte, poté dejte úplný sken.
  • Nic nemažte :!: MBAM má občas falešné detekce a mohl by smazat např. systémové soubory.
  • Log vložte sem.
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#13 Příspěvek od jackdoppelherz »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4145

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

26.5.2010 20:58:59
mbam-log-2010-05-26 (20-58-59).txt

Typ skenu: Úplný sken (C:\|)
Skenované objekty: 203825
Uplynulý čas: 1 hodina(y), 9 minuta(y), 10 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 1
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Documents and Settings\User\Data aplikací\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> No action taken.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: 100% využití CPU, často neodpovídající programy atd.

#14 Příspěvek od Caroprd111 »

Obrázek Vše, co našel MBAM smažte.


Obrázek Podívejte se do správce zařízení, zda tam nejsou nějaké otazníky.
Obrázek

jackdoppelherz
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 24 kvě 2010 17:16

Re: 100% využití CPU, často neodpovídající programy atd.

#15 Příspěvek od jackdoppelherz »

Jen tyto:
Přílohy
Nepojmenovaný 1.png
Nepojmenovaný 1.png (2.63 KiB) Zobrazeno 802 x

Odpovědět