Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

kontrola logu

#1 Příspěvek od zack111 »

zdravím, dostala sa mi do pc nejaka haveď...urobil som kontrolu logu online, odstranil čo sa dalo ale keď som urobil kontrolu znova po reštarte tak to tam bolo zas...prosim pozrite sa mi na to...diki moc :-)

Logfile of HijackThis v1.99.1
Scan saved at 12:30:26, on 6.6.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\1695065792z.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\WINDOWS\system32\AcSignExtResu.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1695065792c.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\programy\ochrana proti vírusom\Hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=15187&l=dis
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET HTTP Server EhttpSrv Licensing Service (EhttpSrv Licensing Service) - Unknown owner - C:\WINDOWS\system32\1695065792z.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: Network DDE NetDDEAudioSrv (NetDDEAudioSrv) - - C:\WINDOWS\system32\AcSignExtResu.exe
O23 - Service: Remote Registry RemoteRegistryERSvc (RemoteRegistryERSvc) - - C:\WINDOWS\system32\1041u.exe
O23 - Service: Performance Logs and Alerts SysmonLogekrn (SysmonLogekrn) - - C:\WINDOWS\system32\12520850h.exe
O23 - Service: Performance Logs and Alerts SysmonLogERSvc (SysmonLogERSvc) - Unknown owner - C:\WINDOWS\system32\adsntu.exe (file missing)
O23 - Service: Windows Time W32Timeidsvc (W32Timeidsvc) - - C:\WINDOWS\system32\1695065792c.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#2 Příspěvek od Caroprd111 »

Zdravím :)

Obrázek Doporučuji odinstalovat Spybot - Search & Destroy a Advanced SystemCare 3.


Obrázek Přečtěte si pravidla fóra a dejte log z RSIT.
Obrázek

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#3 Příspěvek od zack111 »

zdravim...Spybot aj Advanced mám, čistil som pc cez ccleaner aj cez advanced, potom som urobil kontorlu cez spybot aj cez este...no hijackthis to stale najde ....posielam log rsit

Logfile of random's system information tool 1.06 (written by random/random)
Run by Vilec at 2010-06-06 19:49:39
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (17%) free of 20 GB
Total RAM: 894 MB (26% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:50:27, on 6.6.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1695065792c.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
D:\programy\ochrana proti vírusom\RSIT.exe
C:\Program Files\trend micro\Vilec.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=15187&l=dis
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET HTTP Server EhttpSrv Licensing Service (EhttpSrv Licensing Service) - Unknown owner - C:\WINDOWS\system32\1695065792z.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: Network DDE NetDDEAudioSrv (NetDDEAudioSrv) - - C:\WINDOWS\system32\AcSignExtResu.exe
O23 - Service: Remote Registry RemoteRegistryERSvc (RemoteRegistryERSvc) - - C:\WINDOWS\system32\1041u.exe
O23 - Service: Performance Logs and Alerts SysmonLogekrn (SysmonLogekrn) - - C:\WINDOWS\system32\12520850h.exe
O23 - Service: Performance Logs and Alerts SysmonLogERSvc (SysmonLogERSvc) - Unknown owner - C:\WINDOWS\system32\adsntu.exe (file missing)
O23 - Service: Windows Time W32Timeidsvc (W32Timeidsvc) - - C:\WINDOWS\system32\1695065792c.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 7764 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2007-02-19 303104]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-27 851968]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2007-03-16 1392640]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2007-05-14 1191936]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-01-10 385024]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-02-12 188416]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-02-12 77824]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Advanced SystemCare 3"=C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe [2009-06-30 2329224]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2007-12-29 486856]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2006-03-28 323392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-03-02 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Autodesk\Backburner\monitor.exe"="C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\Backburner\manager.exe"="C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\Backburner\server.exe"="C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe"="C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe:*:Enabled:Autodesk 3ds Max 2008 32-bit"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3663960-5cf6-11df-870a-001c23a5e0e0}]
shell\AutoRun\command - F:\jeti\\sumadinac.exe
shell\explore\command - F:\jeti\sumadinac.exe
shell\install\command - F:\jeti\sumadinac.exe
shell\open\command - F:\jeti\sumadinac.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}]
shell\AutoRun\command - G:\jeti\\sumadinac.exe
shell\explore\command - G:\jeti\sumadinac.exe
shell\install\command - G:\jeti\sumadinac.exe
shell\open\command - G:\jeti\sumadinac.exe


======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-06-06 19:49:40 ----D---- C:\Program Files\trend micro
2010-06-06 19:49:39 ----D---- C:\rsit
2010-06-05 18:42:42 ----D---- C:\AutoCAD 2010 CZ 64-bit
2010-06-04 10:35:35 ----A---- C:\WINDOWS\system32\TwnLib20.dll
2010-06-04 10:34:58 ----N---- C:\WINDOWS\system32\ImagXRA7.dll
2010-06-04 10:34:58 ----N---- C:\WINDOWS\system32\ImagXR7.dll
2010-06-04 10:34:58 ----N---- C:\WINDOWS\system32\ImagXpr7.dll
2010-06-04 10:34:58 ----N---- C:\WINDOWS\system32\ImagX7.dll
2010-06-04 10:34:53 ----D---- C:\Program Files\Common Files\Ahead
2010-06-04 10:34:53 ----A---- C:\WINDOWS\system32\NeroCheck.exe
2010-06-04 10:34:50 ----D---- C:\Program Files\Ahead
2010-05-31 22:38:06 ----D---- C:\Documents and Settings\Vilec\Application Data\vlc
2010-05-30 15:06:48 ----D---- C:\Program Files\Common Files\AB Studio Shared
2010-05-30 15:06:48 ----D---- C:\Program Files\AB Studio
2010-05-30 14:56:21 ----D---- C:\Program Files\Common Files\Wextech Shared
2010-05-30 14:55:58 ----D---- C:\Program Files\AutoCAD 2002 Cz
2010-05-27 15:41:18 ----A---- C:\WINDOWS\system32\vbzlib1.dll
2010-05-27 15:41:05 ----D---- C:\Program Files\DsNET Corp
2010-05-26 23:08:15 ----D---- C:\Program Files\PDFCreator
2010-05-24 14:23:27 ----A---- C:\WINDOWS\system32\dopdfmn6.dll
2010-05-24 14:23:27 ----A---- C:\WINDOWS\system32\dopdfmi6.dll
2010-05-24 14:23:20 ----D---- C:\Program Files\Softland
2010-05-24 14:12:56 ----D---- C:\Documents and Settings\Vilec\Application Data\WordToPDF
2010-05-24 14:12:44 ----D---- C:\Program Files\WordToPDF
2010-05-22 12:09:00 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-05-22 12:03:49 ----D---- C:\Program Files\Logitech
2010-05-22 12:03:25 ----A---- C:\WINDOWS\system32\lvcoinst.ini
2010-05-22 12:03:25 ----A---- C:\WINDOWS\system32\lvcoinst.dll
2010-05-22 12:03:23 ----A---- C:\WINDOWS\system32\LVUI2RC.dll
2010-05-22 12:03:23 ----A---- C:\WINDOWS\system32\LVUI2.dll
2010-05-22 12:03:22 ----A---- C:\WINDOWS\system32\LVComC.dll
2010-05-22 12:03:21 ----A---- C:\WINDOWS\system32\LVComS.exe
2010-05-22 12:03:20 ----A---- C:\WINDOWS\system32\lvcodec2.dll
2010-05-22 12:02:23 ----D---- C:\Program Files\Common Files\Labtec
2010-05-22 12:02:18 ----A---- C:\WINDOWS\IsUninst.exe
2010-05-20 18:33:42 ----RSH---- C:\Documents and Settings\Vilec\Application Data\hztxr.exe
2010-05-11 19:36:06 ----D---- C:\Documents and Settings\Vilec\Application Data\Abvent
2010-05-11 19:36:06 ----D---- C:\Documents and Settings\All Users\Application Data\Abvent
2010-05-11 19:35:57 ----D---- C:\Documents and Settings\Vilec\Application Data\Abvent_Artlantis2
2010-05-11 19:29:59 ----D---- C:\Program Files\Artlantis Studio 2

======List of files/folders modified in the last 1 months======

2010-06-06 19:49:40 ----RD---- C:\Program Files
2010-06-06 19:43:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-06 19:41:33 ----D---- C:\Documents and Settings\Vilec\Application Data\DNA
2010-06-06 19:35:35 ----D---- C:\WINDOWS\system32
2010-06-06 19:35:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-06 19:32:30 ----D---- C:\WINDOWS\Temp
2010-06-06 19:31:56 ----D---- C:\WINDOWS
2010-06-06 19:31:31 ----D---- C:\Program Files\DNA
2010-06-06 16:35:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-06 16:25:04 ----D---- C:\WINDOWS\Prefetch
2010-06-06 15:57:01 ----D---- C:\Documents and Settings\Vilec\Application Data\BitTorrent
2010-06-06 11:57:07 ----D---- C:\Program Files\DAEMON Tools Lite
2010-06-05 15:43:03 ----D---- C:\Documents and Settings\Vilec\Application Data\Skype
2010-06-05 13:41:00 ----D---- C:\Documents and Settings\Vilec\Application Data\skypePM
2010-06-04 10:35:59 ----D---- C:\WINDOWS\system32\drivers
2010-06-04 10:34:53 ----D---- C:\Program Files\Common Files
2010-06-04 10:26:06 ----SHD---- C:\WINDOWS\Installer
2010-06-04 08:42:42 ----D---- C:\Documents and Settings\Vilec\Application Data\ICQ
2010-06-03 18:13:01 ----A---- C:\WINDOWS\win.ini
2010-05-31 19:17:34 ----D---- C:\Program Files\Lingea
2010-05-31 10:08:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-30 15:11:33 ----HD---- C:\WINDOWS\inf
2010-05-30 15:03:38 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-30 14:53:57 ----D---- C:\Program Files\Microsoft Office
2010-05-30 14:53:55 ----D---- C:\Program Files\Common Files\Autodesk Shared
2010-05-30 14:33:02 ----HD---- C:\C_DILLA
2010-05-29 20:43:11 ----SD---- C:\Documents and Settings\Vilec\Application Data\Microsoft
2010-05-29 16:45:58 ----D---- C:\Program Files\Common Files\Svoboda Software
2010-05-26 11:50:54 ----D---- C:\Program Files\Mozilla Firefox
2010-05-25 16:04:03 ----SD---- C:\WINDOWS\Tasks
2010-05-23 22:02:38 ----D---- C:\Documents and Settings\Vilec\Application Data\IObit
2010-05-23 21:59:00 ----D---- C:\WINDOWS\system32\config
2010-05-22 12:09:05 ----D---- C:\WINDOWS\twain_32
2010-05-19 06:25:57 ----D---- C:\Program Files\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-04-09 55768]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-03-02 1972224]
R3 BCM43XX;Ovládač karty Dell bezdrôtovej WLAN; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2007-03-16 604928]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2006-11-21 45568]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-23 9600]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-11-02 989696]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-11-02 209152]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-02-19 1228296]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-04-27 202912]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-11-02 730112]
S3 adbq68b3;adbq68b3; C:\WINDOWS\system32\drivers\adbq68b3.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2004-01-21 5915]
S3 PID_08A0;Labtec WebCam Pro(PID_08A0); C:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2004-01-21 271360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-03-02 446464]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-03-12 85096]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2007-03-16 20480]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 EhttpSrv Licensing Service;ESET HTTP Server EhttpSrv Licensing Service; C:\WINDOWS\system32\1695065792z.exe [2004-08-04 208896]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2007-03-15 135664]
S2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit; C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe [2007-09-24 65536]
S2 NetDDEAudioSrv;Network DDE NetDDEAudioSrv; C:\WINDOWS\system32\AcSignExtResu.exe [2004-08-04 208896]
S2 RemoteRegistryERSvc;Remote Registry RemoteRegistryERSvc; C:\WINDOWS\system32\1041u.exe [2004-08-04 208896]
S2 SysmonLogekrn;Performance Logs and Alerts SysmonLogekrn; C:\WINDOWS\system32\12520850h.exe [2004-08-04 208896]
S2 SysmonLogERSvc;Performance Logs and Alerts SysmonLogERSvc; C:\WINDOWS\system32\adsntu.exe srv []
S2 W32Timeidsvc;Windows Time W32Timeidsvc; C:\WINDOWS\system32\1695065792c.exe [2004-08-04 208896]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Network Licensing Service;Autodesk Network Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe [2006-08-11 902760]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#4 Příspěvek od Caroprd111 »

Caroprd111 píše: Obrázek Doporučuji odinstalovat Spybot - Search & Destroy a Advanced SystemCare 3.
Obrázek Doporučuji odinstalovat:
C:\Program Files\DNA\btdna.exe
C:\Program Files\BitTorrent\bittorrent.exe

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.


Obrázek Stáhněte na plochu UsbFix http://pagesperso-orange.fr/NosTools/Ch ... UsbFix.exe
  • Spusťte, poté klikněte na Deletion.
  • Po dokončení na Vás vyskočí log, vložte mi ho sem, případně ho najdete v C:\UsbFix.txt

Obrázek Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#5 Příspěvek od zack111 »

############################## | Usbfix 7.005 | [Deletion]

User: Vilec (Administrator) # WILLIAM [ ]
Updated 07/06/10 by El Desaparecido / C_XX
Started at 16:41:54 | 07/06/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Mobile AMD Sempron(tm) Processor 3600+
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 2
Internet Explorer 6.0.2900.2180

Windows Firewall: Disabled /!\
Antivirus: ESET Smart Security 4.0 4.0 [Enabled | Updated]
Firewall: ESET personal firewall 4.0.424.0 [Enabled]

RAM -> 894 Mb
C:\ (%systemdrive%) -> Fixed drive # 20 Gb (3 Mb free - 17%) [] # NTFS
D:\ -> Fixed drive # 55 Gb (1 Mb free - 3%) [] # NTFS
E:\ -> CD-ROM

################## | Files # Infected Folders |

Deleted ! C:\Recycler\S-1-5-21-1606980848-1972579041-725345543-1003
Deleted ! D:\Recycler\S-1-5-21-1004336348-1078145449-725345543-1003
Deleted ! D:\Recycler\S-1-5-21-1606980848-1972579041-725345543-1003

################## | Registry |


################## | Mountpoints2 |

Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{a3663960-5cf6-11df-870a-001c23a5e0e0}

################## | Listing |

[06/06/2010 - 05:31:26 | D ] C:\AutoCAD 2010 CZ 64-bit
[12/03/2010 - 13:32:21 | SH | 211] C:\boot.ini
[01/05/2010 - 19:38:55 | A | 10] C:\CONFIG.SYS
[30/05/2010 - 14:33:02 | HD ] C:\C_DILLA
[12/03/2010 - 13:54:49 | D ] C:\dell
[22/03/2007 - 00:11:15 | D ] C:\Documents and Settings
[18/04/2010 - 11:42:06 | D ] C:\flexlm
[12/03/2010 - 13:41:04 | RASH | 0] C:\IO.SYS
[12/03/2010 - 13:41:04 | RASH | 0] C:\MSDOS.SYS
[12/03/2010 - 16:32:06 | RHD ] C:\MSOCache
[04/08/2004 - 00:38:34 | RASH | 47564] C:\NTDETECT.COM
[04/08/2004 - 00:59:34 | RASH | 250032] C:\ntldr
[07/06/2010 - 16:10:36 | ASH | 1409286144] C:\pagefile.sys
[06/06/2010 - 20:30:35 | RD ] C:\Program Files
[07/06/2010 - 16:44:12 | SHD ] C:\RECYCLER
[06/06/2010 - 19:50:31 | D ] C:\rsit
[12/03/2010 - 13:45:45 | SHD ] C:\System Volume Information
[07/06/2010 - 16:44:12 | D ] C:\UsbFix
[07/06/2010 - 16:44:12 | A | 1041] C:\Usbfix.txt
[07/06/2010 - 16:10:56 | D ] C:\WINDOWS
[06/06/2010 - 12:12:02 | D ] D:\Chlieb náš každodenný (2005)
[04/03/2010 - 21:23:57 | D ] D:\CS 1.6
[05/06/2010 - 14:06:36 | D ] D:\faktúry
[30/04/2010 - 19:18:13 | D ] D:\fotky
[06/06/2010 - 12:06:39 | D ] D:\inspire
[31/05/2010 - 19:16:07 | D ] D:\MP3
[04/06/2010 - 15:17:24 | D ] D:\my downloads
[06/06/2010 - 15:29:58 | D ] D:\pracovňa
[31/05/2010 - 19:19:56 | D ] D:\programy
[06/06/2010 - 15:27:52 | D ] D:\prospekty a detaily
[07/06/2010 - 16:44:12 | SHD ] D:\RECYCLER
[06/06/2010 - 12:48:18 | D ] D:\rozpracovane
[06/06/2010 - 15:54:59 | D ] D:\skola
[20/02/2010 - 19:45:44 | SHD ] D:\System Volume Information
[06/06/2010 - 15:32:33 | D ] D:\various
[21/02/2010 - 00:36:31 | D ] D:\vypisy SLSP

################## | Vaccin |

C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_WILLIAM.zip
http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution.

################## | E.O.F |

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#6 Příspěvek od zack111 »

OTL Extras logfile created on: 7.6.2010 16:48:55 - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Vilec\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy

894,00 Mb Total Physical Memory | 415,00 Mb Available Physical Memory | 46,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 3,33 Gb Free Space | 17,02% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 1,46 Gb Free Space | 2,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILLIAM
Current User Name: Vilec
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe" "%1" (ACD Systems, Ltd.)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Autodesk\Backburner\monitor.exe" = C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor -- (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\manager.exe" = C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager -- (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\server.exe" = C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server -- (Autodesk, Inc.)
"C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe" = C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe:*:Enabled:Autodesk 3ds Max 2008 32-bit -- (Autodesk, Inc.)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0CCF6926-479F-FE86-FE27-9C944A8D242C}" = Catalyst Control Center Localization German
"{0FADBFEF-FC83-CC42-4951-E3D9FCFBB84F}" = Catalyst Control Center Graphics Full New
"{14359DB5-5F07-6773-3E17-C7388229CCFC}" = CCC Help English
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 17
"{2FA1A75E-AE60-FA59-D036-366D7F00B567}" = CCC Help French
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38EC4486-44FF-49da-8FFF-87DA9DCBC06B}" = Autodesk 3ds Max 2008 32-bit Help
"{3C106CBD-3E5A-4275-94F9-23FFE687D090}" = Autodesk 3ds Max 2008 32-bit Architectural Materials Library
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Backburner
"{4097ADD8-7890-4CBD-953A-1187EF2C6FA5}_is1" = JPEG to PDF 1.0
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4EE78BB8-5538-1186-8EA8-F12BD40185F9}" = Catalyst Control Center Graphics Full Existing
"{547C9628-C490-48AB-94F4-7F2495562930}" = PDF to DWG Converter
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-0101-0405-0002-0060B0CE6BBA}" = AutoCAD 2002 česká verze
"{5783F2D7-7001-0405-0002-0060B0CE6BBA}" = AutoCAD 2009 - český
"{58E653BE-BD68-4D68-BB2E-3AE1B925AAD0}" = Labtec WebCam
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{611131AF-3475-B625-A987-9FBEA8584D39}" = Catalyst Control Center Localization Italian
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{679035C8-CEB8-4a5c-847A-5FB3FFADC0EB}" = Autodesk 3ds Max 2008 32-bit Vault 2008 Plug-In
"{6CCA5CB8-3332-D10A-96C4-B114C1D04704}" = Catalyst Control Center Graphics Light
"{6E0A0C2C-7D63-9786-6519-C94C9EC22599}" = Catalyst Control Center Localization Japanese
"{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}" = QuickTime
"{72019134-3A61-4C39-A540-245600C4CDFA}" = Turbo Squid Tentacles 3ds Max 2008
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{82E86238-89F5-758D-4B10-44229F980D2D}" = ccc-utility
"{8CF86054-49F7-D6E0-078A-CF7E2C03F487}" = Catalyst Control Center Localization Spanish
"{90120000-0010-041B-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Slovak) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-041B-0000-0000000FF1CE}" = Microsoft Office Access MUI (Slovak) 2007
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-0044-041B-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{921F7EF3-D850-9CB6-2811-180F7AC1358B}" = Catalyst Control Center Localization Chinese Standard
"{A3A37DA6-70C0-497C-BCB1-148E9EC1D32E}" = Revit Architecture 2009 (AutoCAD Suite)
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB2037C6-FE46-41fd-B1B2-4D62FBB1E57A}" = Autodesk 3ds Max 2008 32-bit Videos
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AE1EBD4A-9162-497A-8E1E-21C9A52F81B6}" = ESET Smart Security
"{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}" = ACDSee 5.0 Standard
"{AFEB71C8-5A1F-4D3B-FD57-5E08166FE2EE}" = Skins
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B48DBEEB-9EEF-9F27-E1D8-339340FC7178}" = Catalyst Control Center Localization Korean
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B9F49E54-FEF1-1940-CA96-73DADDFEF2A2}" = CCC Help Chinese Standard
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BAFCD194-FBC5-EA66-02E3-A44EBFAB7E27}" = CCC Help Italian
"{BF658A51-6D4F-4CB0-8D40-D183692B995D}" = Autodesk 3ds Max 2008 32-bit
"{C084FA87-793F-9590-C96B-9DE325C5FA6E}" = CCC Help Korean
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}" = Balík TT 2009
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C29B157B-96F6-AEBC-B2A4-001ABB08B1D1}" = CCC Help Portuguese
"{C346B1F7-277F-8C0E-8961-56E6D543AA54}" = CCC Help Japanese
"{C4E60A38-F0C1-AD6B-E130-CE214C98BD4B}" = CCC Help Spanish
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{C9C13822-A638-4331-99A3-4498A5901693}" = Media Go
"{D08C5590-7875-0E44-65EE-EE1D9C4A6FB1}" = CCC Help German
"{D1B7094B-8CAC-492a-9EE6-D1576ED35208}" = Autodesk 3ds Max 2008 32-bit Vault 5 Plug-In
"{D5CF17D4-A616-0853-4EE8-50852BE6CA01}" = ccc-core-static
"{DE8AC8C4-D7D2-D6A7-B28B-9043DD65AA09}" = Catalyst Control Center Localization Chinese Traditional
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5
"{EDC8D89C-DC3D-4a3d-ABE7-97D281C0A13A}" = Autodesk 3ds Max 2008 32-bit Additional Maps and Material Libraries
"{F4CF6586-4426-793B-1E7E-5871A85EDE78}" = Catalyst Control Center Core Implementation
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Zem
"{F868ADD5-65FC-97FB-D083-096292FA6E2F}" = CCC Help Chinese Traditional
"{F88F9DF7-042F-80D3-8883-19A8BF2A9DC7}" = Catalyst Control Center Localization French
"{FE055AD6-C23A-B1B8-C0E6-A45C177E2E03}" = Catalyst Control Center Localization Portuguese
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.6
"All ATI Software" = ATI - Software Uninstall Utility
"ALZip_is1" = ALZip
"ArchShaders for V-Ray vol.1_is1" = ArchShaders for V-Ray vol.1
"Artlantis Studio 2" = Artlantis Studio 2 2.0.2
"Artlantis Studio 2.0.2 (české prostředí a nápověda)" = Artlantis Studio 2.0.2 (české prostředí a nápověda)
"ATI Display Driver" = ATI Display Driver
"AutoCAD 2009 - český" = AutoCAD 2009 - český
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"BSPlayerf" = BS.Player FREE
"CADKON 2000" = CADKON 2002+
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"doPDF 6 printer_is1" = doPDF 6.3 printer
"FBX Plugin 2006.11.1 for Max 2008" = FBX Plugin 2006.11.1 for Max 2008
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Free YouTube Downloader Converter" = Free YouTube Downloader Converter
"HijackThis" = HijackThis 2.0.2
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.2.0
"LabtecDrv" = ##CAMERADRIVERNAME##
"Lexicon 4.0" = Lingea Lexicon 2002
"LMS" = C-Dilla Licence Management System
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Native Instruments Traktor DJ Studio 3" = Native Instruments Traktor DJ Studio 3
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NEXIS32 3.40.13" = IDA NEXIS 32 rel. 3.40
"PDF Editor 2" = PDF Editor 2
"PROPLUS" = Microsoft Office Professional Plus 2007
"SynTPDeinstKey" = Dell Touchpad
"TagScanner_is1" = TagScanner 5.1 build 559
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"Usbfix" = Usbfix By C_XX & El Desaparecido
"VLC media player" = VLC media player 1.0.2
"V-Ray for 3dsmax 2008 for x86" = V-Ray for 3dsmax 2008 for x86
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"QIP Infium" = QIP Infium 2.0.9034

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2.6.2010 16:07:37 | Computer Name = WILLIAM | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie icq.exe, verzia 6.5.0.2024, zlyhanie modulu mshtml.dll,
verzia 6.0.2900.2180, adresa zlyhania 0x00052bd0.

[ OSession Events ]
Error - 1.4.2006 10:48:31 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20148
seconds with 8100 seconds of active time. This session ended with a crash.

Error - 1.4.2006 10:53:18 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 218
seconds with 180 seconds of active time. This session ended with a crash.

Error - 1.4.2006 11:54:36 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3653
seconds with 2520 seconds of active time. This session ended with a crash.

Error - 24.4.2010 10:40:58 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2330
seconds with 1380 seconds of active time. This session ended with a crash.

Error - 24.4.2010 11:33:52 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3145
seconds with 2340 seconds of active time. This session ended with a crash.

Error - 11.5.2010 5:22:10 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1146
seconds with 1140 seconds of active time. This session ended with a crash.

Error - 20.5.2010 17:17:12 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 33060
seconds with 17340 seconds of active time. This session ended with a crash.

Error - 22.5.2010 9:32:30 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 12020
seconds with 1920 seconds of active time. This session ended with a crash.

Error - 22.5.2010 9:44:36 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 638
seconds with 600 seconds of active time. This session ended with a crash.

Error - 23.5.2010 6:23:02 | Computer Name = WILLIAM | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6848
seconds with 2700 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba Ati HotKey Poller sa neočakávane ukončila. Služba sa týmto
spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba Dell Wireless WLAN Tray Service sa neočakávane ukončila. Služba
sa týmto spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba C-DillaSrv sa neočakávane ukončila. Služba sa týmto spôsobom
ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit
sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba Autodesk Licensing Service sa neočakávane ukončila. Služba
sa týmto spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7031
Description = Služba Print Spooler sa neočakávane ukončila. Služba sa týmto spôsobom
ukončila už 1 krát. O 60000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať
službu.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba Java Quick Starter sa neočakávane ukončila. Služba sa týmto
spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:41:59 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7034
Description = Služba Application Layer Gateway Service sa neočakávane ukončila.
Služba sa týmto spôsobom ukončila už 1 krát.

Error - 7.6.2010 10:49:16 | Computer Name = WILLIAM | Source = SRService | ID = 104
Description = Proces inicializácie služby Obnovovanie systému zlyhal.

Error - 7.6.2010 10:49:16 | Computer Name = WILLIAM | Source = Service Control Manager | ID = 7023
Description = Služba System Restore Service bola ukončená s nasledujúcou chybou:
%%2


< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#7 Příspěvek od Caroprd111 »

OK, ještě log OTL.txt
Obrázek

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#8 Příspěvek od zack111 »

OTL logfile created on: 7.6.2010 16:48:55 - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Vilec\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy

894,00 Mb Total Physical Memory | 415,00 Mb Available Physical Memory | 46,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 3,33 Gb Free Space | 17,02% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 1,46 Gb Free Space | 2,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILLIAM
Current User Name: Vilec
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.06.07 16:45:51 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vilec\Desktop\OTL.exe
PRC - [2010.04.08 08:38:00 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.04.09 16:19:08 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2004.08.04 02:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010.06.07 16:45:51 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vilec\Desktop\OTL.exe
MOD - [2004.08.04 02:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004.08.04 01:01:18 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (SysmonLogERSvc)
SRV - [2010.03.12 16:24:06 | 000,085,096 | ---- | M] (Autodesk) [Auto | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2009.04.09 16:29:20 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.04.09 16:19:08 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2007.09.24 18:05:26 | 000,065,536 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe -- (mi-raysat_3dsMax2008_32)
SRV - [2006.10.30 04:34:02 | 000,122,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2006.08.11 23:51:42 | 000,902,760 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1695065792c.exe -- (W32Timeidsvc)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\12520850h.exe -- (SysmonLogekrn)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1041u.exe -- (RemoteRegistryERSvc)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\AcSignExtResu.exe -- (NetDDEAudioSrv)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1695065792z.exe -- (EhttpSrv Licensing Service)
SRV - [2001.09.10 08:08:50 | 000,032,256 | ---- | M] (C-Dilla Ltd) [Auto | Stopped] -- C:\WINDOWS\system32\drivers\CDANTSRV.EXE -- (C-DillaSrv)


========== Driver Services (SafeList) ==========

DRV - [2010.03.12 15:03:34 | 000,715,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.04.09 16:21:12 | 000,055,768 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2009.04.09 16:21:10 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2009.04.09 16:21:06 | 000,133,000 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2009.04.09 16:18:02 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.04.09 16:10:30 | 000,113,960 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2007.04.27 16:37:24 | 000,202,912 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2007.03.16 19:10:46 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007.03.02 17:53:20 | 001,972,224 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.02.19 15:27:34 | 001,228,296 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006.11.21 05:25:44 | 000,045,568 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006.11.15 01:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006.11.02 19:47:36 | 000,989,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006.11.02 19:47:00 | 000,209,152 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006.11.02 19:46:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006.07.01 23:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.08.12 18:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004.08.12 18:45:54 | 000,137,728 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.08.03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2004.01.21 03:14:46 | 000,005,915 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2004.01.21 03:14:42 | 000,271,360 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302AV.SYS -- (PID_08A0) Labtec WebCam Pro(PID_08A0)
DRV - [2001.09.10 08:09:46 | 000,057,392 | ---- | M] (Macrovision) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CDANT.SYS -- (C-Dilla)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1606980848-1972579041-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Wikipédia (sk)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&o ... &gfns=1&q="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.05.09 12:32:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.08 08:38:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.03.12 14:21:13 | 000,000,000 | ---D | M]

[2010.03.12 14:36:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Mozilla\Extensions
[2010.03.12 15:40:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Mozilla\Firefox\Profiles\1g9yfxtt.default\extensions
[2010.03.12 15:39:42 | 000,002,255 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\Mozilla\Firefox\Profiles\1g9yfxtt.default\searchplugins\askcom.xml
[2010.06.07 16:22:29 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008.01.04 10:38:50 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010.04.08 08:38:04 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.04.08 08:38:04 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.04.08 08:38:04 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.04.08 08:38:04 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.04.08 08:38:04 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.04.08 08:38:04 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2010.03.12 14:26:17 | 000,380,636 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13114 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Labtec Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Labtec Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\RunOnce: [] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx (InstaFred)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx (Ovládací prvek AcDcToday)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx (Prvek AcPreview)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 147.232.191.2 147.232.3.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\Documents and Settings\Vilec\Application Data\hztxr.exe) - C:\Documents and Settings\Vilec\Application Data\hztxr.exe ( )
O20 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Vilec\Application Data\hztxr.exe) - C:\Documents and Settings\Vilec\Application Data\hztxr.exe ( )
O20 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003 Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Vilec\Application Data\mrpky.exe) - C:\Documents and Settings\Vilec\Application Data\mrpky.exe File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Vilec\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Vilec\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.06.06 05:31:26 | 000,000,000 | ---D | M] - C:\AutoCAD 2010 CZ 64-bit -- [ NTFS ]
O32 - AutoRun File - [2010.06.07 16:44:16 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.06.07 16:44:16 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\AutoRun\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\explore\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\install\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\open\command - "" = G:\jeti\sumadinac.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010.03.12 13:40:17 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.enc - C:\WINDOWS\System32\ITIG726.acm (Ingenient Technologies, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Unable to start service SrService!

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#9 Příspěvek od zack111 »

========== Files/Folders - Created Within 30 Days ==========

[2010.06.07 16:45:20 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Vilec\Desktop\OTL.exe
[2010.06.07 16:44:16 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
[2010.06.07 16:41:28 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.06.07 16:39:01 | 001,213,853 | ---- | C] (C_XX & El Desaparecido) -- C:\Documents and Settings\Vilec\Desktop\UsbFix.exe
[2010.06.07 12:06:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Desktop\predmety tvorba budov a psroterdia
[2010.06.06 20:30:35 | 000,000,000 | ---D | C] -- C:\Program Files\Free PDF to Word Doc Converter
[2010.06.06 20:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\PDF Editor 2
[2010.06.06 20:09:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\My Documents\Preberanie
[2010.06.06 19:49:40 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.06.06 19:49:39 | 000,000,000 | ---D | C] -- C:\rsit
[2010.06.06 11:58:45 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Vilec\Recent
[2010.06.05 18:42:42 | 000,000,000 | ---D | C] -- C:\AutoCAD 2010 CZ 64-bit
[2010.06.04 10:35:59 | 000,125,184 | ---- | C] (Ahead Software AG) -- C:\WINDOWS\System32\drivers\imagesrv.sys
[2010.06.04 10:35:59 | 000,005,504 | ---- | C] (Ahead Software AG) -- C:\WINDOWS\System32\drivers\imagedrv.sys
[2010.06.04 10:35:35 | 000,106,496 | ---- | C] (Pegasus Software) -- C:\WINDOWS\System32\TwnLib20.dll
[2010.06.04 10:34:58 | 001,568,768 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\ImagX7.dll
[2010.06.04 10:34:58 | 000,476,320 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\ImagXpr7.dll
[2010.06.04 10:34:58 | 000,471,040 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\ImagXRA7.dll
[2010.06.04 10:34:58 | 000,262,144 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\ImagXR7.dll
[2010.06.04 10:34:53 | 000,155,648 | ---- | C] (Ahead Software Gmbh) -- C:\WINDOWS\System32\NeroCheck.exe
[2010.06.04 10:34:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Ahead
[2010.06.04 10:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\Ahead
[2010.06.01 20:24:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Desktop\Helix
[2010.05.31 22:38:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Application Data\vlc
[2010.05.30 15:06:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AB Studio Shared
[2010.05.30 15:06:48 | 000,000,000 | ---D | C] -- C:\Program Files\AB Studio
[2010.05.30 14:56:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wextech Shared
[2010.05.30 14:55:58 | 000,000,000 | ---D | C] -- C:\Program Files\AutoCAD 2002 Cz
[2010.05.27 15:41:12 | 000,124,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSWINSCK.OCX
[2010.05.27 15:41:05 | 000,000,000 | ---D | C] -- C:\Program Files\DsNET Corp
[2010.05.26 23:08:15 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2010.05.24 14:24:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Softland
[2010.05.24 14:23:27 | 000,021,192 | ---- | C] (Softland) -- C:\WINDOWS\System32\dopdfmn6.dll
[2010.05.24 14:23:27 | 000,018,632 | ---- | C] (Softland) -- C:\WINDOWS\System32\dopdfmi6.dll
[2010.05.24 14:23:20 | 000,000,000 | ---D | C] -- C:\Program Files\Softland
[2010.05.24 14:12:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Application Data\WordToPDF
[2010.05.24 14:12:44 | 000,000,000 | ---D | C] -- C:\Program Files\WordToPDF
[2010.05.23 18:19:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Desktop\Erasmus
[2010.05.22 12:10:30 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys
[2010.05.22 12:10:18 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys
[2010.05.22 12:10:13 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys
[2010.05.22 12:10:12 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax
[2010.05.22 12:10:12 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax
[2010.05.22 12:10:05 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys
[2010.05.22 12:10:00 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys
[2010.05.22 12:09:55 | 000,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2010.05.22 12:09:48 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys
[2010.05.22 12:09:04 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax
[2010.05.22 12:09:04 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2010.05.22 12:09:04 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
[2010.05.22 12:09:04 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vidcap.ax
[2010.05.22 12:09:03 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax
[2010.05.22 12:09:03 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax
[2010.05.22 12:09:00 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2010.05.22 12:09:00 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010.05.22 12:09:00 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax
[2010.05.22 12:09:00 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax
[2010.05.22 12:03:49 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2010.05.22 12:03:25 | 000,086,016 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\lvcoinst.dll
[2010.05.22 12:03:24 | 000,012,080 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2010.05.22 12:03:23 | 000,360,448 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\LVUI2RC.dll
[2010.05.22 12:03:23 | 000,122,880 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\LVUI2.dll
[2010.05.22 12:03:22 | 000,057,344 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\LVComC.dll
[2010.05.22 12:03:21 | 000,135,214 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\LVComS.exe
[2010.05.22 12:03:20 | 000,172,032 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\lvcodec2.dll
[2010.05.22 12:03:15 | 000,271,360 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\drivers\LV302AV.SYS
[2010.05.22 12:03:15 | 000,005,915 | ---- | C] (Labtec Inc.) -- C:\WINDOWS\System32\drivers\lv302af.sys
[2010.05.22 12:02:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Labtec
[2010.05.22 12:02:18 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2010.05.22 11:59:56 | 000,059,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010.05.22 11:59:56 | 000,059,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010.05.20 18:33:42 | 000,262,144 | RHS- | C] ( ) -- C:\Documents and Settings\Vilec\Application Data\hztxr.exe
[2010.05.11 19:36:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Application Data\Abvent
[2010.05.11 19:36:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Abvent
[2010.05.11 19:35:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vilec\Application Data\Abvent_Artlantis2
[2010.05.11 19:29:59 | 000,000,000 | ---D | C] -- C:\Program Files\Artlantis Studio 2
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.06.07 16:51:01 | 008,650,752 | -H-- | M] () -- C:\Documents and Settings\Vilec\NTUSER.DAT
[2010.06.07 16:45:51 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vilec\Desktop\OTL.exe
[2010.06.07 16:44:16 | 000,004,875 | ---- | M] () -- C:\UsbFix_Upload_Me_WILLIAM.zip
[2010.06.07 16:41:23 | 001,213,853 | ---- | M] (C_XX & El Desaparecido) -- C:\Documents and Settings\Vilec\Desktop\UsbFix.exe
[2010.06.07 16:23:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.07 16:14:56 | 000,512,960 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.06.07 16:14:56 | 000,435,594 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.06.07 16:14:56 | 000,068,490 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.06.07 16:10:53 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.07 16:10:45 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.06.07 16:10:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.06.07 14:05:33 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Vilec\ntuser.ini
[2010.06.07 10:11:20 | 021,921,562 | -H-- | M] () -- C:\Documents and Settings\Vilec\Local Settings\Application Data\IconCache.db
[2010.06.07 10:10:42 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\Erasmus predmety.doc
[2010.06.07 09:37:21 | 000,000,032 | --S- | M] () -- C:\WINDOWS\System32\3929206058.dat
[2010.06.07 08:32:22 | 000,039,972 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\TECHNICKÁ SPRÁVA - TZB.docx
[2010.06.07 00:52:31 | 000,189,952 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\ing_dipl_prace_10-11_dopl.doc
[2010.06.07 00:51:57 | 001,990,277 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\bakalárksa práca - TZB.dwg
[2010.06.07 00:31:55 | 000,020,487 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\dohoda o štúdiu vyplnená.docx
[2010.06.07 00:23:26 | 000,021,937 | ---- | M] () -- C:\Documents and Settings\Vilec\Desktop\predmety erasmus.docx
[2010.06.06 20:12:56 | 000,074,752 | ---- | M] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2010.06.06 15:45:33 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Vilec\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.03 18:13:01 | 000,000,604 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.05.31 22:36:23 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010.05.30 15:11:32 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\config.nt
[2010.05.30 15:09:00 | 000,000,824 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CADKON 2002+.lnk
[2010.05.30 14:56:38 | 000,001,675 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AutoCAD 2002 Cz.lnk
[2010.05.27 15:42:08 | 000,001,643 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2010.05.22 11:40:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.05.20 18:33:40 | 000,262,144 | RHS- | M] ( ) -- C:\Documents and Settings\Vilec\Application Data\hztxr.exe
[2010.05.19 06:26:18 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Zem.lnk
[2010.05.16 12:59:46 | 000,000,685 | --S- | M] () -- C:\WINDOWS\System32\1695065792.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.06.07 16:44:16 | 000,004,875 | ---- | C] () -- C:\UsbFix_Upload_Me_WILLIAM.zip
[2010.06.07 10:10:34 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\Erasmus predmety.doc
[2010.06.07 00:52:49 | 001,990,277 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\bakalárksa práca - TZB.dwg
[2010.06.07 00:52:49 | 000,039,972 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\TECHNICKÁ SPRÁVA - TZB.docx
[2010.06.07 00:52:30 | 000,189,952 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\ing_dipl_prace_10-11_dopl.doc
[2010.06.07 00:33:26 | 000,020,487 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\dohoda o štúdiu vyplnená.docx
[2010.06.07 00:13:31 | 000,021,937 | ---- | C] () -- C:\Documents and Settings\Vilec\Desktop\predmety erasmus.docx
[2010.06.06 20:12:56 | 000,074,752 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2010.05.31 22:36:23 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010.05.30 15:09:00 | 000,000,824 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CADKON 2002+.lnk
[2010.05.30 14:56:38 | 000,001,675 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AutoCAD 2002 Cz.lnk
[2010.05.27 15:42:08 | 000,001,643 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2010.05.27 15:41:18 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\vbzlib1.dll
[2010.05.24 14:23:27 | 000,007,537 | ---- | C] () -- C:\WINDOWS\System32\dopdf6.ctm
[2010.05.22 12:03:25 | 000,017,191 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010.05.22 11:41:56 | 000,000,032 | --S- | C] () -- C:\WINDOWS\System32\3929206058.dat
[2010.05.19 06:26:18 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Zem.lnk
[2010.05.16 12:56:39 | 000,000,685 | --S- | C] () -- C:\WINDOWS\System32\1695065792.dat
[2010.03.12 18:11:34 | 000,000,231 | ---- | C] () -- C:\WINDOWS\System32\3dsmax.ini
[2010.03.12 18:11:34 | 000,000,043 | ---- | C] () -- C:\WINDOWS\System32\InstallSettings.ini
[2010.03.12 15:31:00 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\acdbres.dll
[2010.03.12 15:17:02 | 000,001,180 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.03.12 15:07:56 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.03.12 15:07:54 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.03.12 15:07:44 | 002,378,752 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2010.03.12 15:07:43 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.03.12 15:07:42 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.03.12 15:07:42 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.03.12 15:07:33 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.03.12 15:07:32 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.03.12 15:03:34 | 000,715,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.03.12 14:08:14 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2010.03.12 14:08:12 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006.03.25 20:54:27 | 000,000,050 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2004.08.04 02:56:44 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004.07.17 13:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2002.03.21 14:51:52 | 000,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll
[2002.03.21 14:51:52 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll
[2002.03.21 14:51:52 | 000,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll
[2002.03.21 14:51:52 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll
[2002.03.21 14:51:52 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll
[2002.03.21 14:51:52 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll
[2002.03.21 14:51:52 | 000,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll
[2002.03.20 23:01:06 | 000,006,688 | R--- | C] () -- C:\WINDOWS\System32\Digita.sys
[2002.03.20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportUSB.dll
[2002.03.20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportSerial.dll
[2002.03.20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrDA.dll
[2002.03.20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrCOMM.dll
[2001.10.28 17:42:30 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2000.09.19 01:50:28 | 000,202,752 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[1999.01.27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997.06.13 07:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010.05.11 19:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Abvent
[2010.03.12 15:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2007.03.24 14:15:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010.03.12 14:21:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.05.24 14:24:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Softland
[2010.05.11 19:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Abvent
[2010.05.11 22:47:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Abvent_Artlantis2
[2010.03.12 15:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ACD Systems
[2007.03.16 12:15:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Autodesk
[2010.06.06 15:57:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BitTorrent
[2006.03.26 19:00:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BSplayer
[2006.03.25 21:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BSplayer Pro
[2010.03.12 15:06:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\DAEMON Tools
[2010.06.07 16:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\DNA
[2010.03.12 14:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ESET
[2010.06.04 08:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ICQ
[2010.05.23 22:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\IObit
[2010.03.12 17:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\QIP
[2010.04.12 17:37:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Sony
[2010.05.24 14:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\WordToPDF

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"StartCCC" = C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe -- [2006.11.10 14:35:24 | 000,090,112 | ---- | M] ()
"SpybotSD TeaTimer" = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -- [2009.03.05 17:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.)
"Advanced SystemCare 3" = "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup -- [2009.06.30 10:55:40 | 002,329,224 | ---- | M] (IObit)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\daemon.exe" -- [2007.12.29 14:05:17 | 000,486,856 | ---- | M] (DT Soft Ltd)
"BitTorrent DNA" = "C:\Program Files\DNA\btdna.exe" -- [2006.03.28 19:51:59 | 000,323,392 | ---- | M] (BitTorrent, Inc.)

< c:\windows\*.* /U >
[3 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2010.05.11 19:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Abvent
[2010.03.12 15:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2010.03.12 16:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010.03.12 15:10:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010.03.12 15:10:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007.03.24 14:15:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010.03.12 14:21:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.03.12 15:03:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESTsoft
[2010.04.12 17:39:48 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2010.05.06 09:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010.03.12 15:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2010.03.12 14:26:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2010.05.11 19:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Abvent
[2010.05.11 22:47:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Abvent_Artlantis2
[2010.03.12 15:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ACD Systems
[2007.03.13 13:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Adobe
[2010.03.12 14:18:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ATI
[2007.03.16 12:15:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Autodesk
[2010.06.06 15:57:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BitTorrent
[2006.03.26 19:00:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BSplayer
[2006.03.25 21:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\BSplayer Pro
[2010.03.12 15:06:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\DAEMON Tools
[2010.03.12 14:19:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Dell
[2010.06.07 16:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\DNA
[2010.03.12 14:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ESET
[2010.03.12 15:03:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ESTsoft
[2007.03.15 22:11:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Google
[2010.03.12 15:43:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Help
[2010.06.04 08:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\ICQ
[2010.03.12 13:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Identities
[2010.03.12 14:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\InstallShield
[2010.05.23 22:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\IObit
[2010.03.12 15:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Macromedia
[2010.05.29 20:43:11 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Vilec\Application Data\Microsoft
[2010.03.12 14:35:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Mozilla
[2010.03.12 17:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\QIP
[2010.06.07 01:00:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Skype
[2010.06.06 19:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\skypePM
[2010.04.12 17:37:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Sony
[2010.03.12 15:08:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Sun
[2010.06.07 16:41:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\vlc
[2010.03.12 15:16:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\Winamp
[2010.05.24 14:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vilec\Application Data\WordToPDF

< %APPDATA%\*.exe /s >
[2010.05.20 18:33:40 | 000,262,144 | RHS- | M] ( ) -- C:\Documents and Settings\Vilec\Application Data\hztxr.exe
[2009.08.11 22:21:26 | 000,087,552 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 22:21:30 | 000,090,112 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 15:52:04 | 000,697,690 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\AC3 Filter\unins000.exe
[2010.02.23 18:01:52 | 001,185,871 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\FFDShow\unins000.exe
[2009.11.14 20:11:36 | 000,113,152 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\Haali media splitter\dsmux.exe
[2009.11.14 20:33:40 | 000,357,888 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\Haali media splitter\gdsmux.exe
[2009.11.14 20:11:36 | 000,136,704 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.02.23 17:00:42 | 000,042,288 | ---- | M] () -- C:\Documents and Settings\Vilec\Application Data\BSplayer\Haali media splitter\uninstall.exe
[2010.03.12 14:14:43 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{0CCF6926-479F-FE86-FE27-9C944A8D242C}\ARPPRODUCTICON.exe
[2010.03.12 14:15:17 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{14359DB5-5F07-6773-3E17-C7388229CCFC}\ARPPRODUCTICON.exe
[2010.03.12 14:15:23 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{2FA1A75E-AE60-FA59-D036-366D7F00B567}\ARPPRODUCTICON.exe
[2010.03.12 13:54:12 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
[2010.03.12 13:54:12 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
[2010.03.12 14:14:54 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{611131AF-3475-B625-A987-9FBEA8584D39}\ARPPRODUCTICON.exe
[2010.03.12 14:14:57 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{6E0A0C2C-7D63-9786-6519-C94C9EC22599}\ARPPRODUCTICON.exe
[2010.03.12 18:14:21 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{72019134-3A61-4C39-A540-245600C4CDFA}\ARPPRODUCTICON.exe
[2010.03.12 18:14:22 | 000,532,480 | R--- | M] (Turbo Squid) -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{72019134-3A61-4C39-A540-245600C4CDFA}\TSStore.exe21_720191343A614C39A540245600C4CDFA.exe
[2010.03.12 18:14:22 | 000,532,480 | R--- | M] (Turbo Squid) -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{72019134-3A61-4C39-A540-245600C4CDFA}\TSStore.exe2_720191343A614C39A540245600C4CDFA.exe
[2010.03.12 14:14:47 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{8CF86054-49F7-D6E0-078A-CF7E2C03F487}\ARPPRODUCTICON.exe
[2010.03.12 14:15:08 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{921F7EF3-D850-9CB6-2811-180F7AC1358B}\ARPPRODUCTICON.exe
[2010.03.12 14:15:01 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{B48DBEEB-9EEF-9F27-E1D8-339340FC7178}\ARPPRODUCTICON.exe
[2010.03.12 14:15:45 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{B9F49E54-FEF1-1940-CA96-73DADDFEF2A2}\ARPPRODUCTICON.exe
[2010.03.12 14:15:25 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{BAFCD194-FBC5-EA66-02E3-A44EBFAB7E27}\ARPPRODUCTICON.exe
[2010.03.12 14:15:29 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C084FA87-793F-9590-C96B-9DE325C5FA6E}\ARPPRODUCTICON.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_1d6e55e7.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_1d717fe3.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_1d7429df.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_38434207.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_43d47e06.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_559e7de4.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_7de9d3b.exe
[2010.05.29 16:46:53 | 000,003,262 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C0A29958-D766-4D23-8CDE-B9CAD0DD0AD3}\_7e0c2006.exe
[2010.03.12 14:15:32 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C29B157B-96F6-AEBC-B2A4-001ABB08B1D1}\ARPPRODUCTICON.exe
[2010.03.12 14:15:27 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C346B1F7-277F-8C0E-8961-56E6D543AA54}\ARPPRODUCTICON.exe
[2010.03.12 14:15:20 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{C4E60A38-F0C1-AD6B-E130-CE214C98BD4B}\ARPPRODUCTICON.exe
[2010.03.12 14:15:14 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{D08C5590-7875-0E44-65EE-EE1D9C4A6FB1}\ARPPRODUCTICON.exe
[2010.03.12 14:15:12 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{DE8AC8C4-D7D2-D6A7-B28B-9043DD65AA09}\ARPPRODUCTICON.exe
[2010.03.12 14:15:47 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{F868ADD5-65FC-97FB-D083-096292FA6E2F}\ARPPRODUCTICON.exe
[2010.03.12 14:14:50 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{F88F9DF7-042F-80D3-8883-19A8BF2A9DC7}\ARPPRODUCTICON.exe
[2010.03.12 14:15:04 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Vilec\Application Data\Microsoft\Installer\{FE055AD6-C23A-B1B8-C0E6-A45C177E2E03}\ARPPRODUCTICON.exe


< MD5 for: AGP440.SYS >
[2004.08.04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2004.08.04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.04 00:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: CDROM.SYS >
[2004.08.04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2004.08.04 00:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.04 02:56:42 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.04 02:56:42 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2004.08.04 02:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.04 02:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2004.08.04 02:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe
[2004.08.04 02:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.04 00:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys

< MD5 for: ISAPNP.SYS >
[2001.08.23 17:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=E504F706CCB699C2596E9A3DA1596E87 -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.04 02:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.04 02:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2004.08.04 01:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.04 01:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2004.08.04 02:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.04 02:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.04 02:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.04 02:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.04 02:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.04 02:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2004.08.04 02:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.04 02:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2004.08.22 04:26:08 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=09EB23A4567BDD56D9580A059E616E23 -- C:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2004.08.04 02:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.04 02:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.04 02:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.04 02:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.04 02:56:48 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.04 02:56:48 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.03.12 15:03:34 | 000,715,248 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2010.03.12 14:21:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.03.12 14:21:48 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.03.12 14:21:48 | 000,905,216 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2010.06.07 09:37:21 | 000,000,032 | --S- | M] () -- C:\WINDOWS\system32\3929206058.dat
[2010.06.07 16:14:56 | 000,068,490 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2010.06.07 16:14:56 | 000,435,594 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2010.06.07 16:14:56 | 000,512,960 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#10 Příspěvek od Caroprd111 »

Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
SRV - File not found [Auto | Stopped] -- -- (SysmonLogERSvc)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1695065792c.exe -- (W32Timeidsvc)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\12520850h.exe -- (SysmonLogekrn)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1041u.exe -- (RemoteRegistryERSvc)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\AcSignExtResu.exe -- (NetDDEAudioSrv)
SRV - [2004.08.04 02:56:58 | 000,208,896 | RHS- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\1695065792z.exe -- (EhttpSrv Licensing Service)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
O4 - HKLM..\RunOnce: [] File not found
O20 - HKLM Winlogon: TaskMan - (C:\Documents and Settings\Vilec\Application Data\hztxr.exe) - C:\Documents and Settings\Vilec\Application Data\hztxr.exe ( )
O20 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Vilec\Application Data\hztxr.exe) - C:\Documents and Settings\Vilec\Application Data\hztxr.exe ( )
O20 - HKU\S-1-5-21-1606980848-1972579041-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Vilec\Application Data\mrpky.exe) - C:\Documents and Settings\Vilec\Application Data\mrpky.exe File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\AutoRun\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\explore\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\install\command - "" = G:\jeti\sumadinac.exe -- File not found
O33 - MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\Shell\open\command - "" = G:\jeti\sumadinac.exe -- File not found
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2010.06.06 20:12:56 | 000,074,752 | ---- | M] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2010.05.16 12:59:46 | 000,000,685 | --S- | M] () -- C:\WINDOWS\System32\1695065792.dat
[2010.05.22 11:41:56 | 000,000,032 | --S- | C] () -- C:\WINDOWS\System32\3929206058.dat
[2010.05.20 18:33:40 | 000,262,144 | RHS- | M] ( ) -- C:\Documents and Settings\Vilec\Application Data\hztxr.exe

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[RESETHOSTS] 
[CREATERESTOREPOINT]
Poté klikněte na Opravit, PC se restartuje, log vložte sem.
Obrázek

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#11 Příspěvek od zack111 »

All processes killed
========== OTL ==========
Service SysmonLogERSvc stopped successfully!
Service SysmonLogERSvc deleted successfully!
Service W32Timeidsvc stopped successfully!
Service W32Timeidsvc deleted successfully!
C:\WINDOWS\system32\1695065792c.exe moved successfully.
Service SysmonLogekrn stopped successfully!
Service SysmonLogekrn deleted successfully!
C:\WINDOWS\system32\12520850h.exe moved successfully.
Service RemoteRegistryERSvc stopped successfully!
Service RemoteRegistryERSvc deleted successfully!
C:\WINDOWS\system32\1041u.exe moved successfully.
Service NetDDEAudioSrv stopped successfully!
Service NetDDEAudioSrv deleted successfully!
C:\WINDOWS\system32\AcSignExtResu.exe moved successfully.
Service EhttpSrv Licensing Service stopped successfully!
Service EhttpSrv Licensing Service deleted successfully!
C:\WINDOWS\system32\1695065792z.exe moved successfully.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan:C:\Documents and Settings\Vilec\Application Data\hztxr.exe deleted successfully.
C:\Documents and Settings\Vilec\Application Data\hztxr.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Vilec\Application Data\hztxr.exe deleted successfully.
File C:\Documents and Settings\Vilec\Application Data\hztxr.exe not found.
Registry value HKEY_USERS\S-1-5-21-1606980848-1972579041-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Vilec\Application Data\mrpky.exe deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
File G:\jeti\sumadinac.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
File G:\jeti\sumadinac.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
File G:\jeti\sumadinac.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3663961-5cf6-11df-870a-001c23a5e0e0}\ not found.
File G:\jeti\sumadinac.exe not found.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\cadkasdeinst01e.exe moved successfully.
C:\WINDOWS\system32\1695065792.dat moved successfully.
C:\WINDOWS\system32\3929206058.dat moved successfully.
File C:\Documents and Settings\Vilec\Application Data\hztxr.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Vilec
->Temp folder emptied: 11281048 bytes
->Temporary Internet Files folder emptied: 176395 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 39840504 bytes
->Flash cache emptied: 1901 bytes

User: Vilo

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 49,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Vilec
->Flash cache emptied: 0 bytes

User: Vilo

Total Flash Files Cleaned = 0,00 mb

Unable to start service SRService!
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Unable to start service SrService!

OTL by OldTimer - Version 3.2.5.3 log created on 06072010_183629

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#12 Příspěvek od zack111 »

ak to je všetko tak diki moc za pomoc :worship:

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#13 Příspěvek od Caroprd111 »

Ještě prověříme počítač na rootkity a dočistíme. :)


Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: kontrola logu

#14 Příspěvek od zack111 »

napisal som do Start > Spustit (Win + R) no nič sa nespustilo :?:

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu

#15 Příspěvek od Caroprd111 »

Win + R je klávesová zkratka pro "Spustit". Do spustit musíte zkopírovat:

Kód: Vybrat vše

 "%userprofile%\plocha\mbr" -t
Obrázek

Odpovědět