
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosim o kontrolu děkuji
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosim o kontrolu děkuji
Logfile of random's system information tool 1.07 (written by random/random)
Run by mirin at 2010-07-08 21:07:21
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 94 GB (62%) free of 153 GB
Total RAM: 1015 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:07:42, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\WINDOWS\system32\ctfmon.exe
H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
R3 - URLSearchHook: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WindowsSysControl] H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
O4 - HKCU\..\Run: [EWABQAF7KL] H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 7004 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{511131f1-4629-4254-a85f-ed7b6d75dd3c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{511131f1-4629-4254-a85f-ed7b6d75dd3c}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
"WindowsSysControl"=H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe [2010-07-06 73728]
"EWABQAF7KL"=H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe [2010-07-06 200704]
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe [2009-12-26 289584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\uTorrent\uTorrent.exe"="H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe"="H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe:*:Enabled:WindowsSysControl"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}]
shell\AutoRun\command - I:\Menu.exe
======List of files/folders created in the last 1 months======
2010-07-06 17:29:07 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
2010-07-06 17:29:06 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp
2010-07-06 17:28:31 ----A---- H:\WINDOWS\system32\sshnas21.dll
2010-07-06 17:28:24 ----RSH---- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-07-06 17:28:23 ----RA---- H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt
2010-07-06 17:28:23 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
2010-07-06 17:28:22 ----RA---- H:\Documents and Settings\mirin\Data aplikací\BgMek.txt
2010-07-06 17:28:22 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 21:07:34 ----D---- H:\Program Files\Trend Micro
2010-07-08 21:07:32 ----D---- H:\WINDOWS\temp
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-08 20:59:59 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 20:59:18 ----D---- H:\WINDOWS\Prefetch
2010-07-08 20:51:55 ----SD---- H:\WINDOWS\Tasks
2010-07-08 20:28:28 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 16:09:59 ----A---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 14:13:54 ----D---- H:\WINDOWS
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-06 17:28:31 ----D---- H:\WINDOWS\system32
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-29 23:49:50 ----SHD---- H:\WINDOWS\Installer
2010-06-29 23:49:50 ----D---- H:\Config.Msi
2010-06-29 23:49:32 ----HD---- H:\WINDOWS\inf
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:14:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 20:59:44 ----D---- H:\Program Files
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\H:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BT;Bluetooth PAN Network Adapter; H:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 btaudio;Bluetooth Audio Device; H:\WINDOWS\system32\drivers\btaudio.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; H:\WINDOWS\System32\Drivers\btcusb.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; H:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 BTWDNDIS;Bluetooth LAN Access Server; H:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 btwhid;btwhid; H:\WINDOWS\system32\DRIVERS\btwhid.sys []
S3 catchme;catchme; \??\H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 VComm;Virtual Serial port driver; H:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; H:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 SSHNAS;SSHNAS; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AcrSch2Svc;Acronis Scheduler2 Service; H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Run by mirin at 2010-07-08 21:07:21
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 94 GB (62%) free of 153 GB
Total RAM: 1015 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:07:42, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\WINDOWS\system32\ctfmon.exe
H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
R3 - URLSearchHook: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - (no file)
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WindowsSysControl] H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
O4 - HKCU\..\Run: [EWABQAF7KL] H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 7004 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{511131f1-4629-4254-a85f-ed7b6d75dd3c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{511131f1-4629-4254-a85f-ed7b6d75dd3c}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
"WindowsSysControl"=H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe [2010-07-06 73728]
"EWABQAF7KL"=H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe [2010-07-06 200704]
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe [2009-12-26 289584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\uTorrent\uTorrent.exe"="H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe"="H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe:*:Enabled:WindowsSysControl"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}]
shell\AutoRun\command - I:\Menu.exe
======List of files/folders created in the last 1 months======
2010-07-06 17:29:07 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
2010-07-06 17:29:06 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp
2010-07-06 17:28:31 ----A---- H:\WINDOWS\system32\sshnas21.dll
2010-07-06 17:28:24 ----RSH---- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-07-06 17:28:23 ----RA---- H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt
2010-07-06 17:28:23 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
2010-07-06 17:28:22 ----RA---- H:\Documents and Settings\mirin\Data aplikací\BgMek.txt
2010-07-06 17:28:22 ----A---- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 21:07:34 ----D---- H:\Program Files\Trend Micro
2010-07-08 21:07:32 ----D---- H:\WINDOWS\temp
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-08 20:59:59 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 20:59:18 ----D---- H:\WINDOWS\Prefetch
2010-07-08 20:51:55 ----SD---- H:\WINDOWS\Tasks
2010-07-08 20:28:28 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 16:09:59 ----A---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 14:13:54 ----D---- H:\WINDOWS
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-06 17:28:31 ----D---- H:\WINDOWS\system32
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-29 23:49:50 ----SHD---- H:\WINDOWS\Installer
2010-06-29 23:49:50 ----D---- H:\Config.Msi
2010-06-29 23:49:32 ----HD---- H:\WINDOWS\inf
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:14:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 20:59:44 ----D---- H:\Program Files
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\H:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BT;Bluetooth PAN Network Adapter; H:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 btaudio;Bluetooth Audio Device; H:\WINDOWS\system32\drivers\btaudio.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; H:\WINDOWS\System32\Drivers\btcusb.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; H:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 BTWDNDIS;Bluetooth LAN Access Server; H:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 btwhid;btwhid; H:\WINDOWS\system32\DRIVERS\btwhid.sys []
S3 catchme;catchme; \??\H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 VComm;Virtual Serial port driver; H:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; H:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 SSHNAS;SSHNAS; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AcrSch2Svc;Acronis Scheduler2 Service; H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji
Zdravím
Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu


- Spusťte, poté do spodního políčka vložte následující skript.
Kód: Vybrat vše
netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys
cdrom.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT
- Označte položku Pro všechny uživatele.
- Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
- Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Re: prosim o kontrolu děkuji
OTL Extras logfile created on: 8.7.2010 21:32:56 - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = H:\Documents and Settings\mirin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 015,00 Mb Total Physical Memory | 460,00 Mb Available Physical Memory | 45,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): h:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 149,04 Gb Total Space | 91,70 Gb Free Space | 61,53% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: VERA
Current User Name: mirin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- H:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "H:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "H:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "H:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "H:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"H:\Program Files\ICQ6.5\ICQ.exe" = H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"H:\Program Files\VideoLAN\VLC\vlc.exe" = H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"H:\Program Files\Real\RealPlayer\realplay.exe" = H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"H:\Program Files\uTorrent\uTorrent.exe" = H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation)
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation)
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" = H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2 -- (Nokia)
"H:\Documents and Settings\mirin\Plocha\Skype.exe" = H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe" = H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe:*:Enabled:WindowsSysControl -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero BurningROM
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{09C468CA-2940-466A-AAE8-DCC0C6E9323C}" = Nokia Software Updater
"{1373559F-6DC6-44EA-9079-6ABDCCE8CDAD}" = OviMPlatform
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{2D10FC46-1D96-44C4-8855-85F21B9B011E}" = Ovi Desktop Sync Engine
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{564D0000-547B-4ED8-8070-85286CC8C9BF}" = OpenOffice.org 3.0
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.2.9.94c
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7B01FD07-1790-4EE9-B5E0-149527D70C7D}" = Nokia Ovi Suite
"{7B1AF68B-4606-4152-9991-1E9D4FF5F0FA}" = Microsoft Antimalware Service CS-CZ Language Pack
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{862546CA-19C6-4D42-A6EB-352820682FA3}" = VideoCAM Messenger
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
"{8E9047C0-B8DA-4969-8868-86A9BEE2047F}" = 602XML Filler rozšíření pro Mozilla Firefox
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A0D65C73-F2C5-432F-8788-90F8A2E99B98}" = Nokia Ovi Suite Software Updater
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.2 - Czech
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed
"{e5ff6785-a392-4f39-bafc-0fe69e22f056}" = Nero 9
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.3
"Around the World in 80 Days_is1" = Around the World in 80 Days
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"CCleaner" = CCleaner
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"hp psc 1200 series_Driver" = hp psc 1200 series
"IcoFX_is1" = IcoFX 1.6.4
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Mp3 Knife_is1" = Mp3 Knife 3.2
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia Maps Updater_is1" = Nokia Maps Updater 1.0.12
"Nokia Ovi Suite" = Nokia Ovi Suite
"NSS" = NSS (remove only)
"OpenAL" = OpenAL
"RealPlayer 6.0" = RealPlayer
"RocketDock_is1" = RocketDock 1.3.5
"szn-software-postak" = Seznam Pošťák 2 (Všichni uživatelé tohoto počítače.)
"The Treasures of Montezuma 2 1.00" = The Treasures of Montezuma 2 1.00
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 30.6.2010 10:43:00 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Error - 30.6.2010 11:23:21 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
OTL by OldTimer - Version 3.2.8.1 Folder = H:\Documents and Settings\mirin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 015,00 Mb Total Physical Memory | 460,00 Mb Available Physical Memory | 45,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): h:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 149,04 Gb Total Space | 91,70 Gb Free Space | 61,53% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: VERA
Current User Name: mirin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- H:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "H:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "H:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "H:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "H:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"H:\Program Files\ICQ6.5\ICQ.exe" = H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"H:\Program Files\VideoLAN\VLC\vlc.exe" = H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"H:\Program Files\Real\RealPlayer\realplay.exe" = H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"H:\Program Files\uTorrent\uTorrent.exe" = H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation)
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation)
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" = H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2 -- (Nokia)
"H:\Documents and Settings\mirin\Plocha\Skype.exe" = H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe" = H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe:*:Enabled:WindowsSysControl -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero BurningROM
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{09C468CA-2940-466A-AAE8-DCC0C6E9323C}" = Nokia Software Updater
"{1373559F-6DC6-44EA-9079-6ABDCCE8CDAD}" = OviMPlatform
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{2D10FC46-1D96-44C4-8855-85F21B9B011E}" = Ovi Desktop Sync Engine
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{564D0000-547B-4ED8-8070-85286CC8C9BF}" = OpenOffice.org 3.0
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.2.9.94c
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7B01FD07-1790-4EE9-B5E0-149527D70C7D}" = Nokia Ovi Suite
"{7B1AF68B-4606-4152-9991-1E9D4FF5F0FA}" = Microsoft Antimalware Service CS-CZ Language Pack
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{862546CA-19C6-4D42-A6EB-352820682FA3}" = VideoCAM Messenger
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
"{8E9047C0-B8DA-4969-8868-86A9BEE2047F}" = 602XML Filler rozšíření pro Mozilla Firefox
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A0D65C73-F2C5-432F-8788-90F8A2E99B98}" = Nokia Ovi Suite Software Updater
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.2 - Czech
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed
"{e5ff6785-a392-4f39-bafc-0fe69e22f056}" = Nero 9
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.3
"Around the World in 80 Days_is1" = Around the World in 80 Days
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"CCleaner" = CCleaner
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"hp psc 1200 series_Driver" = hp psc 1200 series
"IcoFX_is1" = IcoFX 1.6.4
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Mp3 Knife_is1" = Mp3 Knife 3.2
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia Maps Updater_is1" = Nokia Maps Updater 1.0.12
"Nokia Ovi Suite" = Nokia Ovi Suite
"NSS" = NSS (remove only)
"OpenAL" = OpenAL
"RealPlayer 6.0" = RealPlayer
"RocketDock_is1" = RocketDock 1.3.5
"szn-software-postak" = Seznam Pošťák 2 (Všichni uživatelé tohoto počítače.)
"The Treasures of Montezuma 2 1.00" = The Treasures of Montezuma 2 1.00
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 30.6.2010 10:43:00 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Error - 30.6.2010 11:23:21 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Re: prosim o kontrolu děkuji
Error - 30.6.2010 11:23:21 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Error - 30.6.2010 11:23:21 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Error - 3.7.2010 13:57:31 | Computer Name = VERA | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 6.7.2010 11:30:34 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1457.0, P4 1.85.1457.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 6.7.2010 14:16:42 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1457.0, P4 1.85.1457.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 9:30:14 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 14:38:41 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 15:17:07 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 6.7.2010 7:00:35 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 6.7.2010 11:31:11 | Computer Name = VERA | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid= ... 2147608412
User:
VERA\mirin Name: Worm:Win32/Slenping.gen!B ID: 2147608412 Severity: Severe Category:
Worm Path: Action: %%809 Error Code: 0x80508023 Error description: The program could
not find the spyware and other potentially unwanted software on this computer.
Status: Signature Version: AV: 1.85.1457.0, AS: 1.85.1457.0 Engine Version: 1.1.5902.0
Error - 6.7.2010 14:13:01 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 7.7.2010 11:04:38 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 8:00:21 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 9:26:39 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 14:28:24 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 15:13:39 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 15:13:42 | Computer Name = VERA | Source = sr | ID = 1
Description = Filtr nástroje Obnovení systému zjistil neočekávanou chybu 0xC0000001
při zpracování souboru na svazku HarddiskVolume1. Sledování svazku bylo ukončeno.
Error - 8.7.2010 15:23:14 | Computer Name = VERA | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid= ... 2147608412
User:
VERA\mirin Name: Worm:Win32/Slenping.gen!B ID: 2147608412 Severity: Severe Category:
Worm Path: Action: %%809 Error Code: 0x80508023 Error description: The program could
not find the spyware and other potentially unwanted software on this computer.
Status: Signature Version: AV: 1.85.1695.0, AS: 1.85.1695.0 Engine Version: 1.1.5902.0
[ TuneUp Events ]
Error - 26.4.2010 16:14:35 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-26 22:14:35', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','1720',0)
Error - 26.4.2010 16:15:10 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-26 22:15:10', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2116',0)
Error - 21.5.2010 8:11:33 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:11:33', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\vmidi.exe','1856',0)
Error - 21.5.2010 8:20:13 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:20:13', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\vmidi.exe','1644',0)
Error - 21.5.2010 8:20:33 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:20:33', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\uninst.exe','4032',0)
Error - 8.7.2010 14:58:10 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:58:10', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2844',0)
Error - 8.7.2010 14:59:15 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:59:15', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','4044',0)
Error - 8.7.2010 14:59:50 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:59:50', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','508',0)
Error - 8.7.2010 15:00:00 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 21:00:00', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','264',0)
Error - 8.7.2010 15:01:00 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 21:01:00', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2496',0)
< End of report >
Description =
Error - 30.6.2010 11:23:21 | Computer Name = VERA | Source = OviSuite | ID = 1
Description =
Error - 3.7.2010 13:57:31 | Computer Name = VERA | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 6.7.2010 11:30:34 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1457.0, P4 1.85.1457.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 6.7.2010 14:16:42 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1457.0, P4 1.85.1457.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 9:30:14 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 14:38:41 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 8.7.2010 15:17:07 | Computer Name = VERA | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P2 1.1.5902.0, P3 1.85.1695.0, P4 1.85.1695.0, P5 worm_win32_slenping.gen!b, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 6.7.2010 7:00:35 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 6.7.2010 11:31:11 | Computer Name = VERA | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid= ... 2147608412
User:
VERA\mirin Name: Worm:Win32/Slenping.gen!B ID: 2147608412 Severity: Severe Category:
Worm Path: Action: %%809 Error Code: 0x80508023 Error description: The program could
not find the spyware and other potentially unwanted software on this computer.
Status: Signature Version: AV: 1.85.1457.0, AS: 1.85.1457.0 Engine Version: 1.1.5902.0
Error - 6.7.2010 14:13:01 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 7.7.2010 11:04:38 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 8:00:21 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 9:26:39 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 14:28:24 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 15:13:39 | Computer Name = VERA | Source = Service Control Manager | ID = 7000
Description = Služba Acronis Scheduler2 Service neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.7.2010 15:13:42 | Computer Name = VERA | Source = sr | ID = 1
Description = Filtr nástroje Obnovení systému zjistil neočekávanou chybu 0xC0000001
při zpracování souboru na svazku HarddiskVolume1. Sledování svazku bylo ukončeno.
Error - 8.7.2010 15:23:14 | Computer Name = VERA | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid= ... 2147608412
User:
VERA\mirin Name: Worm:Win32/Slenping.gen!B ID: 2147608412 Severity: Severe Category:
Worm Path: Action: %%809 Error Code: 0x80508023 Error description: The program could
not find the spyware and other potentially unwanted software on this computer.
Status: Signature Version: AV: 1.85.1695.0, AS: 1.85.1695.0 Engine Version: 1.1.5902.0
[ TuneUp Events ]
Error - 26.4.2010 16:14:35 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-26 22:14:35', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','1720',0)
Error - 26.4.2010 16:15:10 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-26 22:15:10', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2116',0)
Error - 21.5.2010 8:11:33 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:11:33', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\vmidi.exe','1856',0)
Error - 21.5.2010 8:20:13 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:20:13', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\vmidi.exe','1644',0)
Error - 21.5.2010 8:20:33 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-21 14:20:33', '\device\harddiskvolume1\program
files\vanbasco's karaoke player\uninst.exe','4032',0)
Error - 8.7.2010 14:58:10 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:58:10', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2844',0)
Error - 8.7.2010 14:59:15 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:59:15', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','4044',0)
Error - 8.7.2010 14:59:50 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 20:59:50', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','508',0)
Error - 8.7.2010 15:00:00 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 21:00:00', '\device\harddiskvolume1\documents
and settings\all users.windows\data aplikací\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','264',0)
Error - 8.7.2010 15:01:00 | Computer Name = VERA | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-08 21:01:00', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2496',0)
< End of report >
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji
OTL logfile created on: 8.7.2010 21:32:56 - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = H:\Documents and Settings\mirin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 015,00 Mb Total Physical Memory | 460,00 Mb Available Physical Memory | 45,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): h:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 149,04 Gb Total Space | 91,70 Gb Free Space | 61,53% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: VERA
Current User Name: mirin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
PRC - [2010.07.06 17:28:38 | 000,200,704 | ---- | M] (Electronic Arts) -- H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe
PRC - [2010.06.28 18:08:37 | 000,014,808 | ---- | M] (Mozilla Corporation) -- H:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010.06.28 18:08:36 | 000,910,296 | ---- | M] (Mozilla Corporation) -- H:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.06.09 01:47:48 | 001,531,904 | ---- | M] (Nokia) -- H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2010.06.01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- H:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.04.14 11:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) -- H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010.03.07 20:31:01 | 000,603,904 | ---- | M] (TuneUp Software) -- H:\WINDOWS\system32\TUProgSt.exe
PRC - [2010.03.01 14:15:28 | 000,451,224 | ---- | M] () -- H:\Program Files\Seznam.cz\postak.exe
PRC - [2008.09.30 13:48:28 | 000,935,208 | ---- | M] (Nero AG) -- H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\explorer.exe
PRC - [2007.09.02 13:58:52 | 000,495,616 | ---- | M] () -- H:\Program Files\RocketDock\RocketDock.exe
========== Modules (SafeList) ==========
MOD - [2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\system32\msscript.ocx
MOD - [2007.09.02 13:57:36 | 000,069,632 | ---- | M] () -- H:\Program Files\RocketDock\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- H:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010.06.14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- H:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.04.14 11:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) [Auto | Running] -- H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- h:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.03.07 20:31:01 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- H:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2010.03.07 20:30:59 | 000,360,192 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- H:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.12.11 14:31:36 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- H:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.09.30 13:48:28 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2003.04.07 07:32:06 | 000,065,795 | ---- | M] (HP) [On_Demand | Stopped] -- H:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwhid.sys -- (btwhid)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwdndis.sys -- (BTWDNDIS)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btport.sys -- (BTDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\drivers\btaudio.sys -- (btaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT)
DRV - [2010.06.16 18:48:56 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- H:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.03.25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- H:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2010.02.26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010.02.26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010.02.26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010.02.26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010.02.26 14:21:22 | 000,137,344 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2010.02.26 14:21:22 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2009.01.08 00:39:36 | 000,020,744 | ---- | M] (IVT Corporation.) [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008.12.07 13:44:54 | 000,030,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008.11.19 10:41:08 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys -- (WsAudioDevice_383)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.07.02 15:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.08.07 11:40:38 | 000,098,944 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.07.18 13:26:04 | 004,547,584 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006.08.29 16:56:20 | 000,032,377 | ---- | M] (B-phreaks) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\prodigy.sys -- (PRODIGY)
DRV - [2004.06.25 11:44:54 | 000,331,008 | ---- | M] () [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\snpstd.sys -- (snpstd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {511131f1-4629-4254-a85f-ed7b6d75dd3c} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/sli ... ie7&query="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Seznam"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11
FF - prefs.js..extensions.enabledItems: xmlfiller@software602.cz:3.1.6
FF - prefs.js..extensions.enabledItems: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.0.9
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=FF_5&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: H:\Program Files\Real\RealPlayer\browserrecord [2009.03.17 21:48:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: H:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.06.23 19:59:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: H:\Program Files\Mozilla Firefox\components [2010.07.07 22:07:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: H:\Program Files\Mozilla Firefox\plugins [2010.06.28 18:08:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: H:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.06.23 19:59:47 | 000,000,000 | ---D | M]
[2009.11.22 22:40:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Extensions
[2009.11.22 22:40:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Extensions\home2@tomtom.com
[2010.07.08 20:47:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions
[2010.04.28 13:36:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.16 18:52:46 | 000,000,000 | ---D | M] (free-downloads.net Toolbar) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
[2010.04.21 16:23:24 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\extensions
[2010.02.20 01:22:16 | 000,000,000 | ---D | M] (Adblock Plus) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.12.26 19:45:14 | 000,002,257 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\askcom.xml
[2010.04.18 08:54:15 | 000,000,950 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\icqplugin.xml
[2009.03.27 19:15:40 | 000,001,196 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\winamp-search.xml
[2010.07.08 20:47:17 | 000,000,000 | ---D | M] -- H:\Program Files\Mozilla Firefox\extensions
[2010.04.21 16:23:05 | 000,000,000 | ---D | M] (Seznam lištička) -- H:\Program Files\Mozilla Firefox\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2010.05.24 11:25:42 | 000,000,000 | ---D | M] -- H:\Program Files\Mozilla Firefox\extensions\xmlfiller@software602.cz
[2010.03.29 13:04:14 | 000,081,920 | ---- | M] () -- H:\Program Files\Mozilla Firefox\plugins\npfiller.dll
[2010.04.13 21:24:08 | 000,002,046 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\firmycz.xml
[2010.04.13 21:24:30 | 000,002,041 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\mapycz.xml
[2010.04.13 21:24:42 | 000,001,367 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.04.13 21:24:54 | 000,002,207 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\zbocz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - H:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O2 - BHO: (Ukazatel S-Rank) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll ()
O3 - HKLM\..\Toolbar: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O4 - HKLM..\Run: [MSSE] h:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [SkyTel] H:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EWABQAF7KL] H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe (Electronic Arts)
O4 - HKCU..\Run: [ICQ] H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [RocketDock] H:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [Seznam Postak] H:\Program Files\Seznam.cz\postak.exe ()
O4 - HKCU..\Run: [WindowsSysControl] H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resour ... se8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 6706363312 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9383834953 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - H:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - H:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: H:\Documents and Settings\mirin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: H:\Documents and Settings\mirin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{594870da-d7a6-11de-8e85-0009dd109f16}\Shell\AutoRun\command - "" = I:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\Shell - "" = AutoRun
O33 - MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\Shell\AutoRun\command - "" = I:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - H:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - H:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: Wmi - H:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found
Drivers32: msacm.ac3acm - H:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - H:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - H:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - H:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - H:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - H:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - H:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - H:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - H:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - H:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - H:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - H:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - H:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - H:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - H:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - H:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - H:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ==========
[2010.07.08 21:31:41 | 000,574,976 | ---- | C] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
[2010.07.05 18:10:25 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Plocha\¨písničy
[2010.07.03 20:58:04 | 000,000,000 | RH-D | C] -- H:\Documents and Settings\mirin\Recent
[2010.06.23 19:59:08 | 000,018,816 | ---- | C] (Nokia) -- H:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010.06.23 19:57:58 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
[2010.06.23 17:58:27 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Plocha\zaloha85
[2010.06.21 20:59:44 | 000,000,000 | ---D | C] -- H:\Program Files\Games
[2010.06.20 22:14:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\STARGAZE_IMAGE_CACHE
[2010.06.20 22:14:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
[2010.06.20 22:14:37 | 000,000,000 | ---D | C] -- H:\Program Files\Alawar.com
[2010.06.20 21:26:59 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.06.20 21:26:59 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
[2010.06.20 21:26:26 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ
[2010.06.20 21:26:14 | 000,000,000 | ---D | C] -- H:\Program Files\Alawar
[2010.06.17 18:30:43 | 000,000,000 | --SD | C] -- H:\Documents and Settings\mirin\Dokumenty\Zdroje dat
[2010.06.16 18:58:02 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Dokumenty\Alcohol 120%
[2010.06.16 18:52:49 | 000,000,000 | ---D | C] -- H:\Program Files\Conduit
[2010.06.16 18:52:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\Conduit
[2010.06.10 19:57:46 | 000,743,424 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iedvtool.dll
[2009.05.07 20:48:31 | 000,061,440 | ---- | C] ( ) -- H:\WINDOWS\System32\csnpstd.dll
[2009.05.07 20:48:31 | 000,057,344 | ---- | C] ( ) -- H:\WINDOWS\System32\rsnpstd.dll
[2009.05.07 20:48:31 | 000,036,864 | ---- | C] ( ) -- H:\WINDOWS\System32\vsnpstd.dll
[9 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
[2010.07.08 21:20:00 | 000,001,026 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
[2010.07.08 21:18:37 | 000,000,408 | -H-- | M] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.07.08 21:16:01 | 000,000,282 | -H-- | M] () -- H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.08 21:13:59 | 000,000,486 | ---- | M] () -- H:\WINDOWS\tasks\1-Click Maintenance.job
[2010.07.08 21:13:59 | 000,000,478 | ---- | M] () -- H:\WINDOWS\tasks\Úklid 1 kliknutím.job
[2010.07.08 21:13:49 | 000,000,934 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.07.08 21:13:27 | 000,000,006 | -H-- | M] () -- H:\WINDOWS\tasks\SA.DAT
[2010.07.08 21:13:23 | 000,002,048 | --S- | M] () -- H:\WINDOWS\bootstat.dat
[2010.07.08 21:12:23 | 008,388,608 | ---- | M] () -- H:\Documents and Settings\mirin\ntuser.dat
[2010.07.08 21:12:23 | 000,000,272 | -HS- | M] () -- H:\Documents and Settings\mirin\ntuser.ini
[2010.07.08 21:05:31 | 000,824,681 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\RSIT.exe
[2010.07.08 20:42:00 | 000,000,938 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.07.07 21:03:18 | 909,290,606 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Duch ohně.avi
[2010.07.07 20:20:01 | 000,000,974 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
[2010.07.07 19:28:09 | 000,077,824 | ---- | M] () -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.06 17:29:07 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.07.06 17:28:23 | 000,073,728 | RHS- | M] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2010.07.06 17:28:23 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.03 20:17:59 | 000,000,671 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\vso_ts_preview.xml
[2010.07.02 15:09:55 | 000,013,646 | ---- | M] () -- H:\WINDOWS\System32\wpa.dbl
[2010.06.29 21:06:12 | 000,002,522 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\hpothb07.dat
[2010.06.29 21:05:56 | 001,264,194 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\hpothb07.tif
[2010.06.24 00:14:01 | 000,552,084 | ---- | M] () -- H:\WINDOWS\System32\perfh005.dat
[2010.06.24 00:14:01 | 000,547,622 | ---- | M] () -- H:\WINDOWS\System32\perfh009.dat
[2010.06.24 00:14:01 | 000,139,948 | ---- | M] () -- H:\WINDOWS\System32\perfc005.dat
[2010.06.24 00:14:01 | 000,118,732 | ---- | M] () -- H:\WINDOWS\System32\perfc009.dat
[2010.06.24 00:14:01 | 000,005,222 | ---- | M] () -- H:\WINDOWS\System32\PerfStringBackup.INI
[2010.06.23 12:45:04 | 000,019,456 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\produkce.xls
[2010.06.21 20:59:56 | 000,001,917 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Montezuma 2.lnk
[2010.06.21 20:58:24 | 063,812,228 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\the-treasures-of-montezuma-2.rar
[2010.06.21 20:15:03 | 1027,006,616 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\toy-story-3-2009-draha-cz.avi
[2010.06.21 13:47:23 | 000,041,472 | ---- | M] () -- H:\Documents and Settings\mirin\Dokumenty\Prezenční listina schůze Bytového družstva Rozkvět.doc
[2010.06.20 22:57:37 | 002,108,476 | -H-- | M] () -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\IconCache.db
[2010.06.17 22:57:37 | 1541,978,028 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Ctvrty Druh - The Fourth Kind novinky 2010 CZ.avi
[2010.06.17 18:50:58 | 000,000,162 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\~$běžník.doc
[2010.06.16 19:06:30 | 000,000,290 | ---- | M] () -- H:\Documents and Settings\mirin\Dokumenty\ax_files.xml
[2010.06.16 18:48:56 | 000,691,696 | ---- | M] () -- H:\WINDOWS\System32\drivers\sptd.sys
[2010.06.16 18:39:51 | 000,000,166 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\default.rss
[2010.06.16 18:39:42 | 000,000,069 | ---- | M] () -- H:\WINDOWS\NeroDigital.ini
[2010.06.12 22:16:10 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.06.12 22:16:09 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.06.11 17:27:10 | 000,288,496 | ---- | M] () -- H:\WINDOWS\System32\FNTCACHE.DAT
[2010.06.10 23:21:53 | 000,001,298 | ---- | M] () -- H:\WINDOWS\win.ini
[9 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.07.08 21:05:28 | 000,824,681 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\RSIT.exe
[2010.07.07 20:01:30 | 909,290,606 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Duch ohně.avi
[2010.07.06 17:29:07 | 000,073,728 | ---- | C] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.07.06 17:28:39 | 000,000,282 | -H-- | C] () -- H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.06 17:28:24 | 000,073,728 | RHS- | C] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2010.07.06 17:28:23 | 000,073,728 | ---- | C] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.06 17:28:23 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt
[2010.07.06 17:28:22 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\BgMek.txt
[2010.07.03 20:50:17 | 000,019,456 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\produkce.xls
[2010.06.30 13:08:05 | 000,000,408 | -H-- | C] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.06.27 12:33:07 | 000,316,892 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Dock.jpg
[2010.06.21 20:59:56 | 000,001,917 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Montezuma 2.lnk
[2010.06.21 20:54:22 | 063,812,228 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\the-treasures-of-montezuma-2.rar
[2010.06.21 17:25:49 | 1027,006,616 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\toy-story-3-2009-draha-cz.avi
[2010.06.21 13:47:23 | 000,041,472 | ---- | C] () -- H:\Documents and Settings\mirin\Dokumenty\Prezenční listina schůze Bytového družstva Rozkvět.doc
[2010.06.17 21:31:13 | 1541,978,028 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Ctvrty Druh - The Fourth Kind novinky 2010 CZ.avi
[2010.06.17 18:50:58 | 000,000,162 | -H-- | C] () -- H:\Documents and Settings\mirin\Plocha\~$běžník.doc
[2010.06.16 18:53:49 | 000,000,290 | ---- | C] () -- H:\Documents and Settings\mirin\Dokumenty\ax_files.xml
[2010.06.12 22:16:10 | 000,000,000 | -H-- | C] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.06.12 22:16:09 | 000,000,000 | -H-- | C] () -- H:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.03.20 19:40:01 | 000,000,993 | ---- | C] () -- H:\WINDOWS\disney.ini
[2010.02.07 00:49:04 | 000,001,812 | ---- | C] () -- H:\WINDOWS\System32\mp3rec.dll
[2009.12.26 18:23:31 | 000,000,390 | ---- | C] () -- H:\WINDOWS\ODBC.INI
[2009.12.12 13:45:48 | 000,000,141 | ---- | C] () -- H:\WINDOWS\ALIK.INI
[2009.09.08 14:22:14 | 000,691,696 | ---- | C] () -- H:\WINDOWS\System32\drivers\sptd.sys
[2009.07.19 23:14:27 | 000,000,069 | ---- | C] () -- H:\WINDOWS\NeroDigital.ini
[2009.05.07 20:48:35 | 000,053,248 | ---- | C] () -- H:\WINDOWS\System32\dsnpstd.dll
[2009.05.07 20:48:35 | 000,015,541 | ---- | C] () -- H:\WINDOWS\snpstd.ini
[2009.05.07 20:48:33 | 000,331,008 | ---- | C] () -- H:\WINDOWS\System32\drivers\snpstd.sys
[2009.03.27 20:05:32 | 000,139,264 | ---- | C] () -- H:\WINDOWS\System32\xvidvfw.dll
[2009.03.25 15:04:32 | 000,012,288 | ---- | C] () -- H:\WINDOWS\impborl.dll
[2009.03.18 13:57:43 | 000,004,767 | ---- | C] () -- H:\WINDOWS\Irremote.ini
[2009.03.17 21:48:34 | 000,000,025 | ---- | C] () -- H:\WINDOWS\cdplayer.ini
[2009.03.15 15:24:37 | 000,000,754 | ---- | C] () -- H:\WINDOWS\WORDPAD.INI
[2008.12.07 13:44:54 | 000,030,088 | ---- | C] () -- H:\WINDOWS\System32\drivers\btnetBus.sys
[2008.05.22 21:24:18 | 000,153,088 | ---- | C] () -- H:\WINDOWS\System32\unrar_mpfc.dll
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- H:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- H:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,524,288 | ---- | C] () -- H:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- H:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- H:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- H:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- H:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- H:\WINDOWS\System32\ogg.dll
[2004.07.29 01:19:46 | 000,175,104 | ---- | C] () -- H:\WINDOWS\System32\lame_enc.dll
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- H:\WINDOWS\System32\OUTLPERF.INI
[2003.04.07 07:32:14 | 000,561,152 | ---- | C] () -- H:\WINDOWS\System32\hpotscl.dll
[1999.08.12 00:00:00 | 000,036,864 | ---- | C] () -- H:\WINDOWS\System32\DOCOBJ.DLL
[1999.08.12 00:00:00 | 000,032,768 | ---- | C] () -- H:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2009.06.08 17:57:23 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Acronis
[2010.06.20 22:14:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
[2010.06.21 14:03:06 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
[2009.10.03 23:46:39 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\ESET
[2010.01.22 21:39:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\FarmFrenzy2
[2009.05.06 14:58:18 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Friends Games
[2009.03.10 22:20:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\ICQ
[2010.06.07 22:32:24 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Installations
[2010.03.30 16:02:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Nokia
[2010.06.23 19:57:58 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
[2009.07.13 15:15:00 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaMusic
[2010.06.23 20:05:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
[2009.06.02 13:12:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\PC Suite
[2009.05.06 14:28:05 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\PopCap Games
[2010.02.05 23:20:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\SuperMP3Download
[2010.03.05 10:00:07 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
[2009.11.22 22:40:37 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TomTom
[2009.11.05 21:15:00 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TuneUp Software
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
[2009.04.08 22:11:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\vsosdk
[2009.05.31 17:39:45 | 000,000,000 | -HSD | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2009.11.05 21:14:52 | 000,000,000 | -HSD | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010.05.24 11:25:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\602XML
[2010.02.07 22:51:38 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Advanced Audio Recorder
[2010.03.02 00:01:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AnvSoft
[2009.08.03 21:13:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Any Video Converter
[2010.04.10 18:31:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Record Edit Toolbox
[2010.04.10 18:28:25 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder for Free
[2010.02.12 22:55:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder Titanium
[2009.03.10 17:53:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AvniTech
[2010.02.06 20:15:40 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Cool Record Edit Pro
[2009.10.03 23:47:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ESET
[2010.02.11 21:47:55 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Free Audio Editor
[2010.02.07 22:21:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Get from YouTube
[2009.03.18 14:17:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\IcoFX
[2010.07.06 18:52:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ICQ
[2010.02.07 22:21:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Import Audio from Video
[2009.08.21 13:06:09 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Jpeg Resampler
[2009.05.06 21:58:50 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Magic Match
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\MagicMatch
[2009.05.01 23:18:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Navigator
[2009.12.04 22:18:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia
[2009.12.04 22:18:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia Ovi Suite
[2009.08.15 21:17:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nseries
[2009.03.28 22:45:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\OpenOffice.org
[2010.03.30 15:00:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\PC Suite
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Saqqarah
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\StoneLoops!
[2010.02.05 23:16:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\SuperMP3Download
[2009.11.22 22:40:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TomTom
[2010.06.04 11:58:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Trio
[2009.05.31 17:40:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TuneUp Software
[2009.04.08 21:19:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Uniblue
[2010.03.05 09:59:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\URSoft
[2010.02.05 23:24:30 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\uTorrent
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.07.03 20:14:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Vso
[2010.07.08 21:13:59 | 000,000,486 | ---- | M] () -- H:\WINDOWS\Tasks\1-Click Maintenance.job
[2009.08.29 10:58:05 | 000,000,342 | ---- | M] () -- H:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
[2010.07.08 21:18:37 | 000,000,408 | -H-- | M] () -- H:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010.07.08 21:16:01 | 000,000,282 | -H-- | M] () -- H:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.08 21:13:59 | 000,000,478 | ---- | M] () -- H:\WINDOWS\Tasks\Úklid 1 kliknutím.job
========== Purity Check ==========
OTL by OldTimer - Version 3.2.8.1 Folder = H:\Documents and Settings\mirin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 015,00 Mb Total Physical Memory | 460,00 Mb Available Physical Memory | 45,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): h:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 149,04 Gb Total Space | 91,70 Gb Free Space | 61,53% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: VERA
Current User Name: mirin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
PRC - [2010.07.06 17:28:38 | 000,200,704 | ---- | M] (Electronic Arts) -- H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe
PRC - [2010.06.28 18:08:37 | 000,014,808 | ---- | M] (Mozilla Corporation) -- H:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010.06.28 18:08:36 | 000,910,296 | ---- | M] (Mozilla Corporation) -- H:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.06.09 01:47:48 | 001,531,904 | ---- | M] (Nokia) -- H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2010.06.01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- H:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.04.14 11:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) -- H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010.03.07 20:31:01 | 000,603,904 | ---- | M] (TuneUp Software) -- H:\WINDOWS\system32\TUProgSt.exe
PRC - [2010.03.01 14:15:28 | 000,451,224 | ---- | M] () -- H:\Program Files\Seznam.cz\postak.exe
PRC - [2008.09.30 13:48:28 | 000,935,208 | ---- | M] (Nero AG) -- H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\explorer.exe
PRC - [2007.09.02 13:58:52 | 000,495,616 | ---- | M] () -- H:\Program Files\RocketDock\RocketDock.exe
========== Modules (SafeList) ==========
MOD - [2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\system32\msscript.ocx
MOD - [2007.09.02 13:57:36 | 000,069,632 | ---- | M] () -- H:\Program Files\RocketDock\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- H:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010.06.14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- H:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.04.14 11:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) [Auto | Running] -- H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- h:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.03.07 20:31:01 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- H:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2010.03.07 20:30:59 | 000,360,192 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- H:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.12.11 14:31:36 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- H:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.09.30 13:48:28 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2003.04.07 07:32:06 | 000,065,795 | ---- | M] (HP) [On_Demand | Stopped] -- H:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwhid.sys -- (btwhid)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwdndis.sys -- (BTWDNDIS)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btport.sys -- (BTDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\drivers\btaudio.sys -- (btaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT)
DRV - [2010.06.16 18:48:56 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- H:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.03.25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- H:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2010.02.26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010.02.26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010.02.26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010.02.26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010.02.26 14:21:22 | 000,137,344 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2010.02.26 14:21:22 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2009.01.08 00:39:36 | 000,020,744 | ---- | M] (IVT Corporation.) [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008.12.07 13:44:54 | 000,030,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008.11.19 10:41:08 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys -- (WsAudioDevice_383)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.07.02 15:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.08.07 11:40:38 | 000,098,944 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.07.18 13:26:04 | 004,547,584 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006.08.29 16:56:20 | 000,032,377 | ---- | M] (B-phreaks) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\prodigy.sys -- (PRODIGY)
DRV - [2004.06.25 11:44:54 | 000,331,008 | ---- | M] () [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\snpstd.sys -- (snpstd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {511131f1-4629-4254-a85f-ed7b6d75dd3c} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/sli ... ie7&query="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Seznam"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11
FF - prefs.js..extensions.enabledItems: xmlfiller@software602.cz:3.1.6
FF - prefs.js..extensions.enabledItems: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.0.9
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=FF_5&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: H:\Program Files\Real\RealPlayer\browserrecord [2009.03.17 21:48:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: H:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.06.23 19:59:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: H:\Program Files\Mozilla Firefox\components [2010.07.07 22:07:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: H:\Program Files\Mozilla Firefox\plugins [2010.06.28 18:08:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: H:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.06.23 19:59:47 | 000,000,000 | ---D | M]
[2009.11.22 22:40:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Extensions
[2009.11.22 22:40:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Extensions\home2@tomtom.com
[2010.07.08 20:47:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions
[2010.04.28 13:36:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.16 18:52:46 | 000,000,000 | ---D | M] (free-downloads.net Toolbar) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\7j9tmj1p.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
[2010.04.21 16:23:24 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\extensions
[2010.02.20 01:22:16 | 000,000,000 | ---D | M] (Adblock Plus) -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.12.26 19:45:14 | 000,002,257 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\askcom.xml
[2010.04.18 08:54:15 | 000,000,950 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\icqplugin.xml
[2009.03.27 19:15:40 | 000,001,196 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Mozilla\Firefox\Profiles\m89up20e.default\searchplugins\winamp-search.xml
[2010.07.08 20:47:17 | 000,000,000 | ---D | M] -- H:\Program Files\Mozilla Firefox\extensions
[2010.04.21 16:23:05 | 000,000,000 | ---D | M] (Seznam lištička) -- H:\Program Files\Mozilla Firefox\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2010.05.24 11:25:42 | 000,000,000 | ---D | M] -- H:\Program Files\Mozilla Firefox\extensions\xmlfiller@software602.cz
[2010.03.29 13:04:14 | 000,081,920 | ---- | M] () -- H:\Program Files\Mozilla Firefox\plugins\npfiller.dll
[2010.04.13 21:24:08 | 000,002,046 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\firmycz.xml
[2010.04.13 21:24:30 | 000,002,041 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\mapycz.xml
[2010.04.13 21:24:42 | 000,001,367 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.04.13 21:24:54 | 000,002,207 | ---- | M] () -- H:\Program Files\Mozilla Firefox\searchplugins\zbocz.xml
O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - H:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O2 - BHO: (Ukazatel S-Rank) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll ()
O3 - HKLM\..\Toolbar: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O4 - HKLM..\Run: [MSSE] h:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [SkyTel] H:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EWABQAF7KL] H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe (Electronic Arts)
O4 - HKCU..\Run: [ICQ] H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [RocketDock] H:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [Seznam Postak] H:\Program Files\Seznam.cz\postak.exe ()
O4 - HKCU..\Run: [WindowsSysControl] H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resour ... se8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 6706363312 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9383834953 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - H:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - H:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: H:\Documents and Settings\mirin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: H:\Documents and Settings\mirin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{594870da-d7a6-11de-8e85-0009dd109f16}\Shell\AutoRun\command - "" = I:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\Shell - "" = AutoRun
O33 - MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\Shell\AutoRun\command - "" = I:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - H:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - H:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: Wmi - H:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found
Drivers32: msacm.ac3acm - H:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - H:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - H:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - H:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - H:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - H:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - H:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - H:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - H:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - H:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - H:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - H:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - H:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - H:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - H:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - H:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - H:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ==========
[2010.07.08 21:31:41 | 000,574,976 | ---- | C] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
[2010.07.05 18:10:25 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Plocha\¨písničy
[2010.07.03 20:58:04 | 000,000,000 | RH-D | C] -- H:\Documents and Settings\mirin\Recent
[2010.06.23 19:59:08 | 000,018,816 | ---- | C] (Nokia) -- H:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010.06.23 19:57:58 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
[2010.06.23 17:58:27 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Plocha\zaloha85
[2010.06.21 20:59:44 | 000,000,000 | ---D | C] -- H:\Program Files\Games
[2010.06.20 22:14:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\STARGAZE_IMAGE_CACHE
[2010.06.20 22:14:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
[2010.06.20 22:14:37 | 000,000,000 | ---D | C] -- H:\Program Files\Alawar.com
[2010.06.20 21:26:59 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.06.20 21:26:59 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
[2010.06.20 21:26:26 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ
[2010.06.20 21:26:14 | 000,000,000 | ---D | C] -- H:\Program Files\Alawar
[2010.06.17 18:30:43 | 000,000,000 | --SD | C] -- H:\Documents and Settings\mirin\Dokumenty\Zdroje dat
[2010.06.16 18:58:02 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Dokumenty\Alcohol 120%
[2010.06.16 18:52:49 | 000,000,000 | ---D | C] -- H:\Program Files\Conduit
[2010.06.16 18:52:49 | 000,000,000 | ---D | C] -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\Conduit
[2010.06.10 19:57:46 | 000,743,424 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iedvtool.dll
[2009.05.07 20:48:31 | 000,061,440 | ---- | C] ( ) -- H:\WINDOWS\System32\csnpstd.dll
[2009.05.07 20:48:31 | 000,057,344 | ---- | C] ( ) -- H:\WINDOWS\System32\rsnpstd.dll
[2009.05.07 20:48:31 | 000,036,864 | ---- | C] ( ) -- H:\WINDOWS\System32\vsnpstd.dll
[9 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.07.08 21:31:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- H:\Documents and Settings\mirin\Plocha\OTL.exe
[2010.07.08 21:20:00 | 000,001,026 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
[2010.07.08 21:18:37 | 000,000,408 | -H-- | M] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.07.08 21:16:01 | 000,000,282 | -H-- | M] () -- H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.08 21:13:59 | 000,000,486 | ---- | M] () -- H:\WINDOWS\tasks\1-Click Maintenance.job
[2010.07.08 21:13:59 | 000,000,478 | ---- | M] () -- H:\WINDOWS\tasks\Úklid 1 kliknutím.job
[2010.07.08 21:13:49 | 000,000,934 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.07.08 21:13:27 | 000,000,006 | -H-- | M] () -- H:\WINDOWS\tasks\SA.DAT
[2010.07.08 21:13:23 | 000,002,048 | --S- | M] () -- H:\WINDOWS\bootstat.dat
[2010.07.08 21:12:23 | 008,388,608 | ---- | M] () -- H:\Documents and Settings\mirin\ntuser.dat
[2010.07.08 21:12:23 | 000,000,272 | -HS- | M] () -- H:\Documents and Settings\mirin\ntuser.ini
[2010.07.08 21:05:31 | 000,824,681 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\RSIT.exe
[2010.07.08 20:42:00 | 000,000,938 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.07.07 21:03:18 | 909,290,606 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Duch ohně.avi
[2010.07.07 20:20:01 | 000,000,974 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
[2010.07.07 19:28:09 | 000,077,824 | ---- | M] () -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.06 17:29:07 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.07.06 17:28:23 | 000,073,728 | RHS- | M] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2010.07.06 17:28:23 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.03 20:17:59 | 000,000,671 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\vso_ts_preview.xml
[2010.07.02 15:09:55 | 000,013,646 | ---- | M] () -- H:\WINDOWS\System32\wpa.dbl
[2010.06.29 21:06:12 | 000,002,522 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\hpothb07.dat
[2010.06.29 21:05:56 | 001,264,194 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\hpothb07.tif
[2010.06.24 00:14:01 | 000,552,084 | ---- | M] () -- H:\WINDOWS\System32\perfh005.dat
[2010.06.24 00:14:01 | 000,547,622 | ---- | M] () -- H:\WINDOWS\System32\perfh009.dat
[2010.06.24 00:14:01 | 000,139,948 | ---- | M] () -- H:\WINDOWS\System32\perfc005.dat
[2010.06.24 00:14:01 | 000,118,732 | ---- | M] () -- H:\WINDOWS\System32\perfc009.dat
[2010.06.24 00:14:01 | 000,005,222 | ---- | M] () -- H:\WINDOWS\System32\PerfStringBackup.INI
[2010.06.23 12:45:04 | 000,019,456 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\produkce.xls
[2010.06.21 20:59:56 | 000,001,917 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Montezuma 2.lnk
[2010.06.21 20:58:24 | 063,812,228 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\the-treasures-of-montezuma-2.rar
[2010.06.21 20:15:03 | 1027,006,616 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\toy-story-3-2009-draha-cz.avi
[2010.06.21 13:47:23 | 000,041,472 | ---- | M] () -- H:\Documents and Settings\mirin\Dokumenty\Prezenční listina schůze Bytového družstva Rozkvět.doc
[2010.06.20 22:57:37 | 002,108,476 | -H-- | M] () -- H:\Documents and Settings\mirin\Local Settings\Data aplikací\IconCache.db
[2010.06.17 22:57:37 | 1541,978,028 | ---- | M] () -- H:\Documents and Settings\mirin\Plocha\Ctvrty Druh - The Fourth Kind novinky 2010 CZ.avi
[2010.06.17 18:50:58 | 000,000,162 | -H-- | M] () -- H:\Documents and Settings\mirin\Plocha\~$běžník.doc
[2010.06.16 19:06:30 | 000,000,290 | ---- | M] () -- H:\Documents and Settings\mirin\Dokumenty\ax_files.xml
[2010.06.16 18:48:56 | 000,691,696 | ---- | M] () -- H:\WINDOWS\System32\drivers\sptd.sys
[2010.06.16 18:39:51 | 000,000,166 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\default.rss
[2010.06.16 18:39:42 | 000,000,069 | ---- | M] () -- H:\WINDOWS\NeroDigital.ini
[2010.06.12 22:16:10 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.06.12 22:16:09 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.06.11 17:27:10 | 000,288,496 | ---- | M] () -- H:\WINDOWS\System32\FNTCACHE.DAT
[2010.06.10 23:21:53 | 000,001,298 | ---- | M] () -- H:\WINDOWS\win.ini
[9 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.07.08 21:05:28 | 000,824,681 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\RSIT.exe
[2010.07.07 20:01:30 | 909,290,606 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Duch ohně.avi
[2010.07.06 17:29:07 | 000,073,728 | ---- | C] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.07.06 17:28:39 | 000,000,282 | -H-- | C] () -- H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.06 17:28:24 | 000,073,728 | RHS- | C] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2010.07.06 17:28:23 | 000,073,728 | ---- | C] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.06 17:28:23 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt
[2010.07.06 17:28:22 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\BgMek.txt
[2010.07.03 20:50:17 | 000,019,456 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\produkce.xls
[2010.06.30 13:08:05 | 000,000,408 | -H-- | C] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.06.27 12:33:07 | 000,316,892 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Dock.jpg
[2010.06.21 20:59:56 | 000,001,917 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Montezuma 2.lnk
[2010.06.21 20:54:22 | 063,812,228 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\the-treasures-of-montezuma-2.rar
[2010.06.21 17:25:49 | 1027,006,616 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\toy-story-3-2009-draha-cz.avi
[2010.06.21 13:47:23 | 000,041,472 | ---- | C] () -- H:\Documents and Settings\mirin\Dokumenty\Prezenční listina schůze Bytového družstva Rozkvět.doc
[2010.06.17 21:31:13 | 1541,978,028 | ---- | C] () -- H:\Documents and Settings\mirin\Plocha\Ctvrty Druh - The Fourth Kind novinky 2010 CZ.avi
[2010.06.17 18:50:58 | 000,000,162 | -H-- | C] () -- H:\Documents and Settings\mirin\Plocha\~$běžník.doc
[2010.06.16 18:53:49 | 000,000,290 | ---- | C] () -- H:\Documents and Settings\mirin\Dokumenty\ax_files.xml
[2010.06.12 22:16:10 | 000,000,000 | -H-- | C] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.06.12 22:16:09 | 000,000,000 | -H-- | C] () -- H:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.03.20 19:40:01 | 000,000,993 | ---- | C] () -- H:\WINDOWS\disney.ini
[2010.02.07 00:49:04 | 000,001,812 | ---- | C] () -- H:\WINDOWS\System32\mp3rec.dll
[2009.12.26 18:23:31 | 000,000,390 | ---- | C] () -- H:\WINDOWS\ODBC.INI
[2009.12.12 13:45:48 | 000,000,141 | ---- | C] () -- H:\WINDOWS\ALIK.INI
[2009.09.08 14:22:14 | 000,691,696 | ---- | C] () -- H:\WINDOWS\System32\drivers\sptd.sys
[2009.07.19 23:14:27 | 000,000,069 | ---- | C] () -- H:\WINDOWS\NeroDigital.ini
[2009.05.07 20:48:35 | 000,053,248 | ---- | C] () -- H:\WINDOWS\System32\dsnpstd.dll
[2009.05.07 20:48:35 | 000,015,541 | ---- | C] () -- H:\WINDOWS\snpstd.ini
[2009.05.07 20:48:33 | 000,331,008 | ---- | C] () -- H:\WINDOWS\System32\drivers\snpstd.sys
[2009.03.27 20:05:32 | 000,139,264 | ---- | C] () -- H:\WINDOWS\System32\xvidvfw.dll
[2009.03.25 15:04:32 | 000,012,288 | ---- | C] () -- H:\WINDOWS\impborl.dll
[2009.03.18 13:57:43 | 000,004,767 | ---- | C] () -- H:\WINDOWS\Irremote.ini
[2009.03.17 21:48:34 | 000,000,025 | ---- | C] () -- H:\WINDOWS\cdplayer.ini
[2009.03.15 15:24:37 | 000,000,754 | ---- | C] () -- H:\WINDOWS\WORDPAD.INI
[2008.12.07 13:44:54 | 000,030,088 | ---- | C] () -- H:\WINDOWS\System32\drivers\btnetBus.sys
[2008.05.22 21:24:18 | 000,153,088 | ---- | C] () -- H:\WINDOWS\System32\unrar_mpfc.dll
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- H:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- H:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,524,288 | ---- | C] () -- H:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- H:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- H:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- H:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- H:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- H:\WINDOWS\System32\ogg.dll
[2004.07.29 01:19:46 | 000,175,104 | ---- | C] () -- H:\WINDOWS\System32\lame_enc.dll
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- H:\WINDOWS\System32\OUTLPERF.INI
[2003.04.07 07:32:14 | 000,561,152 | ---- | C] () -- H:\WINDOWS\System32\hpotscl.dll
[1999.08.12 00:00:00 | 000,036,864 | ---- | C] () -- H:\WINDOWS\System32\DOCOBJ.DLL
[1999.08.12 00:00:00 | 000,032,768 | ---- | C] () -- H:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2009.06.08 17:57:23 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Acronis
[2010.06.20 22:14:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
[2010.06.21 14:03:06 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
[2009.10.03 23:46:39 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\ESET
[2010.01.22 21:39:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\FarmFrenzy2
[2009.05.06 14:58:18 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Friends Games
[2009.03.10 22:20:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\ICQ
[2010.06.07 22:32:24 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Installations
[2010.03.30 16:02:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Nokia
[2010.06.23 19:57:58 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
[2009.07.13 15:15:00 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaMusic
[2010.06.23 20:05:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
[2009.06.02 13:12:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\PC Suite
[2009.05.06 14:28:05 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\PopCap Games
[2010.02.05 23:20:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\SuperMP3Download
[2010.03.05 10:00:07 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
[2009.11.22 22:40:37 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TomTom
[2009.11.05 21:15:00 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TuneUp Software
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
[2009.04.08 22:11:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\vsosdk
[2009.05.31 17:39:45 | 000,000,000 | -HSD | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2009.11.05 21:14:52 | 000,000,000 | -HSD | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010.05.24 11:25:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\602XML
[2010.02.07 22:51:38 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Advanced Audio Recorder
[2010.03.02 00:01:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AnvSoft
[2009.08.03 21:13:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Any Video Converter
[2010.04.10 18:31:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Record Edit Toolbox
[2010.04.10 18:28:25 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder for Free
[2010.02.12 22:55:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder Titanium
[2009.03.10 17:53:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AvniTech
[2010.02.06 20:15:40 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Cool Record Edit Pro
[2009.10.03 23:47:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ESET
[2010.02.11 21:47:55 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Free Audio Editor
[2010.02.07 22:21:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Get from YouTube
[2009.03.18 14:17:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\IcoFX
[2010.07.06 18:52:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ICQ
[2010.02.07 22:21:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Import Audio from Video
[2009.08.21 13:06:09 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Jpeg Resampler
[2009.05.06 21:58:50 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Magic Match
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\MagicMatch
[2009.05.01 23:18:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Navigator
[2009.12.04 22:18:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia
[2009.12.04 22:18:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia Ovi Suite
[2009.08.15 21:17:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nseries
[2009.03.28 22:45:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\OpenOffice.org
[2010.03.30 15:00:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\PC Suite
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Saqqarah
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\StoneLoops!
[2010.02.05 23:16:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\SuperMP3Download
[2009.11.22 22:40:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TomTom
[2010.06.04 11:58:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Trio
[2009.05.31 17:40:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TuneUp Software
[2009.04.08 21:19:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Uniblue
[2010.03.05 09:59:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\URSoft
[2010.02.05 23:24:30 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\uTorrent
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.07.03 20:14:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Vso
[2010.07.08 21:13:59 | 000,000,486 | ---- | M] () -- H:\WINDOWS\Tasks\1-Click Maintenance.job
[2009.08.29 10:58:05 | 000,000,342 | ---- | M] () -- H:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
[2010.07.08 21:18:37 | 000,000,408 | -H-- | M] () -- H:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010.07.08 21:16:01 | 000,000,282 | -H-- | M] () -- H:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.08 21:13:59 | 000,000,478 | ---- | M] () -- H:\WINDOWS\Tasks\Úklid 1 kliknutím.job
========== Purity Check ==========
Re: prosim o kontrolu děkuji
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"RocketDock" = "H:\Program Files\RocketDock\RocketDock.exe" -- [2007.09.02 13:58:52 | 000,495,616 | ---- | M] ()
"Seznam Postak" = "H:\Program Files\Seznam.cz\postak.exe" -s -- [2010.03.01 14:15:28 | 000,451,224 | ---- | M] ()
"ctfmon.exe" = H:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"" =
"ICQ" = "H:\Program Files\ICQ6.5\ICQ.exe" silent -- [2009.11.16 17:36:19 | 000,172,792 | ---- | M] (ICQ, LLC.)
"Google Update" = "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2009.11.17 22:00:38 | 000,135,664 | ---- | M] (Google Inc.)
"WindowsSysControl" = H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe -- [2010.07.06 17:28:23 | 000,073,728 | RHS- | M] ()
"EWABQAF7KL" = H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe -- [2010.07.06 17:28:38 | 000,200,704 | ---- | M] (Electronic Arts)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- H:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.05.24 11:25:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\602XML
[2009.03.11 22:37:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Adobe
[2010.02.07 22:51:38 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Advanced Audio Recorder
[2010.03.02 00:01:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AnvSoft
[2009.08.03 21:13:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Any Video Converter
[2010.04.10 18:31:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Record Edit Toolbox
[2010.04.10 18:28:25 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder for Free
[2010.02.12 22:55:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder Titanium
[2009.03.10 17:53:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AvniTech
[2010.02.06 20:15:40 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Cool Record Edit Pro
[2010.07.05 18:12:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\dvdcss
[2009.10.03 23:47:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ESET
[2010.02.11 21:47:55 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Free Audio Editor
[2010.02.07 22:21:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Get from YouTube
[2010.04.26 21:37:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Google
[2009.05.03 08:46:53 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Hewlett-Packard
[2009.03.18 14:17:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\IcoFX
[2010.07.06 18:52:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ICQ
[2009.03.10 16:55:32 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Identities
[2010.02.07 22:21:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Import Audio from Video
[2009.03.10 17:06:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\InstallShield
[2009.08.21 13:06:09 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Jpeg Resampler
[2009.03.10 20:11:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Macromedia
[2009.05.06 21:58:50 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Magic Match
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\MagicMatch
[2009.09.14 20:42:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Malwarebytes
[2010.06.17 18:30:43 | 000,000,000 | --SD | M] -- H:\Documents and Settings\mirin\Data aplikací\Microsoft
[2009.03.10 21:50:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla
[2009.05.01 23:18:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Navigator
[2010.06.01 12:40:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nero
[2009.12.04 22:18:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia
[2009.12.04 22:18:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia Ovi Suite
[2009.08.15 21:17:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nseries
[2009.03.28 22:45:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\OpenOffice.org
[2010.03.30 15:00:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\PC Suite
[2009.06.20 21:21:11 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Real
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Saqqarah
[2010.06.18 14:14:12 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Skype
[2010.06.14 00:01:16 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\skypePM
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\StoneLoops!
[2009.12.26 17:41:32 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Sun
[2010.02.05 23:16:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\SuperMP3Download
[2009.11.22 22:40:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TomTom
[2010.06.04 11:58:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Trio
[2009.05.31 17:40:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TuneUp Software
[2009.04.08 21:19:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Uniblue
[2010.03.05 09:59:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\URSoft
[2010.02.05 23:24:30 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\uTorrent
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.07.05 18:25:21 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\vlc
[2010.07.03 20:14:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Vso
[2009.03.28 18:22:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2010.07.06 17:28:23 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.06 17:29:07 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.04.18 14:02:47 | 000,087,608 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\inst.exe
[2010.07.06 17:28:23 | 000,073,728 | RHS- | M] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[2010.06.22 21:52:38 | 069,214,784 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
[2009.06.20 21:21:15 | 000,390,664 | ---- | M] (RealNetworks, Inc.) -- H:\Documents and Settings\mirin\Data aplikací\Real\RealPlayer\Update\realplayer11gold.exe
< MD5 for: AGP440.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\system32\drivers\agp440.sys
[2006.03.02 14:00:00 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- H:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- H:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- H:\WINDOWS\system32\drivers\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- H:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: CDROM.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- H:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- H:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- H:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2006.03.02 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- H:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\system32\eventlog.dll
[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- H:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- H:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- H:\WINDOWS\system32\HAL.DLL
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- H:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.03.02 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- H:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- H:\WINDOWS\ServicePackFiles\i386\changer.sys
< MD5 for: ISAPNP.SYS >
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- H:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- H:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- H:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2006.03.02 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- H:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\system32\drivers\ndis.sys
[2006.03.02 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- H:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- H:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- H:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2006.03.02 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- H:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 16:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- H:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- H:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- H:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\system32\svchost.exe
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- H:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- H:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- H:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- H:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- H:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\system32\userinit.exe
[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- H:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- H:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2006.03.02 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- H:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.06.16 18:48:56 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- H:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2009.03.10 19:40:15 | 000,262,144 | ---- | M] () -- H:\WINDOWS\system32\config\default.sav
[2009.03.10 18:23:02 | 000,262,144 | ---- | M] () -- H:\WINDOWS\system32\config\security.sav
[2009.03.10 19:40:15 | 009,175,040 | ---- | M] () -- H:\WINDOWS\system32\config\software.sav
[2009.03.10 19:40:15 | 003,407,872 | ---- | M] () -- H:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.07.08 21:14:34 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\system32\winrtsnr.txt
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
========== Files - Unicode (All) ==========
[2010.06.23 23:31:10 | 000,000,000 | ---D | M](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
[2010.06.23 23:31:10 | 000,000,000 | ---D | C](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B3D74A13
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B7ADB4DA
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:3BD4D405
@Alternate Data Stream - 110 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 107 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:88D03673
< End of report >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"RocketDock" = "H:\Program Files\RocketDock\RocketDock.exe" -- [2007.09.02 13:58:52 | 000,495,616 | ---- | M] ()
"Seznam Postak" = "H:\Program Files\Seznam.cz\postak.exe" -s -- [2010.03.01 14:15:28 | 000,451,224 | ---- | M] ()
"ctfmon.exe" = H:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"" =
"ICQ" = "H:\Program Files\ICQ6.5\ICQ.exe" silent -- [2009.11.16 17:36:19 | 000,172,792 | ---- | M] (ICQ, LLC.)
"Google Update" = "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2009.11.17 22:00:38 | 000,135,664 | ---- | M] (Google Inc.)
"WindowsSysControl" = H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe -- [2010.07.06 17:28:23 | 000,073,728 | RHS- | M] ()
"EWABQAF7KL" = H:\DOCUME~1\mirin\LOCALS~1\Temp\Kzh.exe -- [2010.07.06 17:28:38 | 000,200,704 | ---- | M] (Electronic Arts)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- H:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.05.24 11:25:43 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\602XML
[2009.03.11 22:37:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Adobe
[2010.02.07 22:51:38 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Advanced Audio Recorder
[2010.03.02 00:01:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AnvSoft
[2009.08.03 21:13:20 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Any Video Converter
[2010.04.10 18:31:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Record Edit Toolbox
[2010.04.10 18:28:25 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder for Free
[2010.02.12 22:55:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Audio Recorder Titanium
[2009.03.10 17:53:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\AvniTech
[2010.02.06 20:15:40 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Cool Record Edit Pro
[2010.07.05 18:12:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\dvdcss
[2009.10.03 23:47:45 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ESET
[2010.02.11 21:47:55 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Free Audio Editor
[2010.02.07 22:21:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Get from YouTube
[2010.04.26 21:37:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Google
[2009.05.03 08:46:53 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Hewlett-Packard
[2009.03.18 14:17:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\IcoFX
[2010.07.06 18:52:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\ICQ
[2009.03.10 16:55:32 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Identities
[2010.02.07 22:21:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Import Audio from Video
[2009.03.10 17:06:01 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\InstallShield
[2009.08.21 13:06:09 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Jpeg Resampler
[2009.03.10 20:11:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Macromedia
[2009.05.06 21:58:50 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Magic Match
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\MagicMatch
[2009.09.14 20:42:04 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Malwarebytes
[2010.06.17 18:30:43 | 000,000,000 | --SD | M] -- H:\Documents and Settings\mirin\Data aplikací\Microsoft
[2009.03.10 21:50:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Mozilla
[2009.05.01 23:18:56 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Navigator
[2010.06.01 12:40:41 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nero
[2009.12.04 22:18:52 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia
[2009.12.04 22:18:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nokia Ovi Suite
[2009.08.15 21:17:31 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Nseries
[2009.03.28 22:45:54 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\OpenOffice.org
[2010.03.30 15:00:29 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\PC Suite
[2009.06.20 21:21:11 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Real
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Saqqarah
[2010.06.18 14:14:12 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Skype
[2010.06.14 00:01:16 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\skypePM
[2009.05.06 21:58:36 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\StoneLoops!
[2009.12.26 17:41:32 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Sun
[2010.02.05 23:16:49 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\SuperMP3Download
[2009.11.22 22:40:17 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TomTom
[2010.06.04 11:58:27 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Trio
[2009.05.31 17:40:33 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\TuneUp Software
[2009.04.08 21:19:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Uniblue
[2010.03.05 09:59:08 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\URSoft
[2010.02.05 23:24:30 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\uTorrent
[2010.06.20 21:26:59 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\VisualShape
[2010.07.05 18:25:21 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\vlc
[2010.07.03 20:14:14 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\Vso
[2009.03.28 18:22:51 | 000,000,000 | ---D | M] -- H:\Documents and Settings\mirin\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2010.07.06 17:28:23 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.06 17:29:07 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.04.18 14:02:47 | 000,087,608 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\inst.exe
[2010.07.06 17:28:23 | 000,073,728 | RHS- | M] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[2010.06.22 21:52:38 | 069,214,784 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
[2009.06.20 21:21:15 | 000,390,664 | ---- | M] (RealNetworks, Inc.) -- H:\Documents and Settings\mirin\Data aplikací\Real\RealPlayer\Update\realplayer11gold.exe
< MD5 for: AGP440.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- H:\WINDOWS\system32\drivers\agp440.sys
[2006.03.02 14:00:00 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- H:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- H:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- H:\WINDOWS\system32\drivers\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- H:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: CDROM.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- H:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- H:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- H:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2006.03.02 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- H:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- H:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- H:\WINDOWS\system32\eventlog.dll
[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- H:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- H:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- H:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- H:\WINDOWS\system32\HAL.DLL
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- H:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.03.02 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- H:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- H:\WINDOWS\ServicePackFiles\i386\changer.sys
< MD5 for: ISAPNP.SYS >
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2009.03.10 19:43:30 | 023,890,583 | ---- | M] () .cab file -- H:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- H:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- H:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- H:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2006.03.02 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- H:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- H:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- H:\WINDOWS\system32\drivers\ndis.sys
[2006.03.02 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- H:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- H:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- H:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- H:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- H:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2006.03.02 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- H:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 16:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- H:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- H:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- H:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- H:\WINDOWS\system32\svchost.exe
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- H:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- H:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- H:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- H:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- H:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- H:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- H:\WINDOWS\system32\userinit.exe
[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- H:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- H:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- H:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2006.03.02 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- H:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- H:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.06.16 18:48:56 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- H:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2009.03.10 19:40:15 | 000,262,144 | ---- | M] () -- H:\WINDOWS\system32\config\default.sav
[2009.03.10 18:23:02 | 000,262,144 | ---- | M] () -- H:\WINDOWS\system32\config\security.sav
[2009.03.10 19:40:15 | 009,175,040 | ---- | M] () -- H:\WINDOWS\system32\config\software.sav
[2009.03.10 19:40:15 | 003,407,872 | ---- | M] () -- H:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.07.08 21:14:34 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\system32\winrtsnr.txt
[1 H:\WINDOWS\system32\*.tmp files -> H:\WINDOWS\system32\*.tmp -> ]
========== Files - Unicode (All) ==========
[2010.06.23 23:31:10 | 000,000,000 | ---D | M](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
[2010.06.23 23:31:10 | 000,000,000 | ---D | C](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B3D74A13
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B7ADB4DA
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:3BD4D405
@Alternate Data Stream - 110 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 107 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:88D03673
< End of report >
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji

Kód: Vybrat vše
:OTL
SRV - File not found [On_Demand | Stopped] -- H:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwhid.sys -- (btwhid)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btwdndis.sys -- (BTWDNDIS)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - File not found [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btport.sys -- (BTDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\drivers\btaudio.sys -- (btaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT)IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {511131f1-4629-4254-a85f-ed7b6d75dd3c} - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11
FF - prefs.js..extensions.enabledItems: xmlfiller@software602.cz:3.1.6
FF - prefs.js..extensions.enabledItems: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.0.9
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=FF_5&q="
O2 - BHO: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - No CLSID value found.
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EWABQAF7KL] H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe (Electronic Arts)
O4 - HKCU..\Run: [WindowsSysControl] H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe ()
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O33 - MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\Shell - "" = AutoRun
NetSvcs: SSHNAS - File not found
[2010.06.20 21:26:26 | 000,000,000 | ---D | C] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ
[9 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[2 H:\Documents and Settings\mirin\Data aplikací\*.tmp files -> H:\Documents and Settings\mirin\Data aplikací\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
[2010.07.08 21:16:01 | 000,000,282 | -H-- | M] () -- H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010.07.06 17:29:07 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe
[2010.07.06 17:28:23 | 000,073,728 | RHS- | M] () -- H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe
[2010.07.06 17:28:23 | 000,073,728 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe
[2010.07.06 17:28:23 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt
[2010.07.06 17:28:22 | 000,000,000 | R--- | C] () -- H:\Documents and Settings\mirin\Data aplikací\BgMek.txt
[2010.03.05 10:00:07 | 000,000,000 | ---D | M] -- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
@Alternate Data Stream - 120 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B3D74A13
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B7ADB4DA
@Alternate Data Stream - 112 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:3BD4D405
@Alternate Data Stream - 110 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 107 bytes -> H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:88D03673
[2010.04.18 14:02:47 | 000,087,608 | ---- | M] () -- H:\Documents and Settings\mirin\Data aplikací\inst.exe
[2010.06.23 23:31:10 | 000,000,000 | ---D | M](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
[2010.06.23 23:31:10 | 000,000,000 | ---D | C](H:\Documents and Settings\mirin\Data aplikac?) -- H:\Documents and Settings\mirin\Data aplikac�
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe"=-
:Commands
[EMPTYTEMP]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.
Re: prosim o kontrolu děkuji
All processes killed
========== OTL ==========
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File H:\WINDOWS\System32\appmgmts.dll not found.
Service AcrSch2Svc stopped successfully!
Service AcrSch2Svc deleted successfully!
File H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe not found.
Service VcommMgr stopped successfully!
Service VcommMgr deleted successfully!
File H:\WINDOWS\System32\Drivers\VcommMgr.sys not found.
Service VComm stopped successfully!
Service VComm deleted successfully!
File H:\WINDOWS\System32\DRIVERS\VComm.sys not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys not found.
Service btwhid stopped successfully!
Service btwhid deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btwhid.sys not found.
Service BTWDNDIS stopped successfully!
Service BTWDNDIS deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btwdndis.sys not found.
Service BTHidMgr stopped successfully!
Service BTHidMgr deleted successfully!
File H:\WINDOWS\System32\Drivers\BTHidMgr.sys not found.
Service BTHidEnum stopped successfully!
Service BTHidEnum deleted successfully!
File H:\WINDOWS\System32\Drivers\vbtenum.sys not found.
Service BTDriver stopped successfully!
Service BTDriver deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btport.sys not found.
Service Btcsrusb stopped successfully!
Service Btcsrusb deleted successfully!
File H:\WINDOWS\System32\Drivers\btcusb.sys not found.
Service btaudio stopped successfully!
Service btaudio deleted successfully!
File H:\WINDOWS\System32\drivers\btaudio.sys not found.
Service BT stopped successfully!
Service BT deleted successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{511131f1-4629-4254-a85f-ed7b6d75dd3c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "http://slirsredirect.search.aol.com/sli ... ie7&query=" removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3 removed from extensions.enabledItems
Prefs.js: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26 removed from extensions.enabledItems
Prefs.js: jqs@sun.com:1.0 removed from extensions.enabledItems
Prefs.js: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102 removed from extensions.enabledItems
Prefs.js: support@predictad.com:1.11 removed from extensions.enabledItems
Prefs.js: xmlfiller@software602.cz:3.1.6 removed from extensions.enabledItems
Prefs.js: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.0.9 removed from extensions.enabledItems
Prefs.js: "http://search.seznam.cz/?sourceid=FF_5&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{511131f1-4629-4254-a85f-ed7b6d75dd3c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EWABQAF7KL deleted successfully.
H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsSysControl deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe moved successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
H:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\ not found.
SSHNAS removed from NetSvcs value successfully!
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\temp folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\throbbers folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\stubs folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\sort folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\misc folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\images folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\blocks folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ folder moved successfully.
H:\WINDOWS\002559_.tmp deleted successfully.
H:\WINDOWS\SET21.tmp deleted successfully.
H:\WINDOWS\SET28.tmp deleted successfully.
H:\WINDOWS\SET2B.tmp deleted successfully.
H:\WINDOWS\SET3.tmp deleted successfully.
H:\WINDOWS\SET37.tmp deleted successfully.
H:\WINDOWS\SET4.tmp deleted successfully.
H:\WINDOWS\SET62.tmp deleted successfully.
H:\WINDOWS\SET8.tmp deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp deleted successfully.
H:\WINDOWS\System32\SET1CD.tmp deleted successfully.
H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job moved successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe moved successfully.
File H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe not found.
H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe moved successfully.
H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt moved successfully.
H:\Documents and Settings\mirin\Data aplikací\BgMek.txt moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP folder moved successfully.
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B3D74A13 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B7ADB4DA .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:3BD4D405 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:DFC5A2B2 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:88D03673 .
H:\Documents and Settings\mirin\Data aplikací\inst.exe moved successfully.
H:\Documents and Settings\mirin\Data aplikac�\Nokia\Ovi Suite folder moved successfully.
H:\Documents and Settings\mirin\Data aplikac�\Nokia folder moved successfully.
H:\Documents and Settings\mirin\Data aplikac� folder moved successfully.
Folder H:\Documents and Settings\mirin\Data aplikac�\ not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Administrator.VERA
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: All Users.WINDOWS
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY.001
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: mirek
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5243058 bytes
->FireFox cache emptied: 81046742 bytes
->Flash cache emptied: 3772 bytes
User: mirin
->Temp folder emptied: 572288 bytes
->Temporary Internet Files folder emptied: 12971502 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 139141815 bytes
->Google Chrome cache emptied: 417788062 bytes
->Flash cache emptied: 10412 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: NetworkService.NT AUTHORITY.001
->Temp folder emptied: 393290 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Pc
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 112623329 bytes
->Flash cache emptied: 4177 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 465220 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 51758370 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 784,00 mb
[EMPTYFLASH]
User: Administrator
User: Administrator.VERA
User: All Users
User: All Users.WINDOWS
User: Default User
User: Default User.WINDOWS
User: LocalService
User: LocalService.NT AUTHORITY
User: LocalService.NT AUTHORITY.000
User: LocalService.NT AUTHORITY.001
User: mirek
->Flash cache emptied: 0 bytes
User: mirin
->Flash cache emptied: 0 bytes
User: NetworkService
User: NetworkService.NT AUTHORITY
User: NetworkService.NT AUTHORITY.000
User: NetworkService.NT AUTHORITY.001
User: Pc
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.8.1 log created on 07082010_221852
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== OTL ==========
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File H:\WINDOWS\System32\appmgmts.dll not found.
Service AcrSch2Svc stopped successfully!
Service AcrSch2Svc deleted successfully!
File H:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe not found.
Service VcommMgr stopped successfully!
Service VcommMgr deleted successfully!
File H:\WINDOWS\System32\Drivers\VcommMgr.sys not found.
Service VComm stopped successfully!
Service VComm deleted successfully!
File H:\WINDOWS\System32\DRIVERS\VComm.sys not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File H:\DOCUME~1\mirin\LOCALS~1\Temp\catchme.sys not found.
Service btwhid stopped successfully!
Service btwhid deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btwhid.sys not found.
Service BTWDNDIS stopped successfully!
Service BTWDNDIS deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btwdndis.sys not found.
Service BTHidMgr stopped successfully!
Service BTHidMgr deleted successfully!
File H:\WINDOWS\System32\Drivers\BTHidMgr.sys not found.
Service BTHidEnum stopped successfully!
Service BTHidEnum deleted successfully!
File H:\WINDOWS\System32\Drivers\vbtenum.sys not found.
Service BTDriver stopped successfully!
Service BTDriver deleted successfully!
File H:\WINDOWS\System32\DRIVERS\btport.sys not found.
Service Btcsrusb stopped successfully!
Service Btcsrusb deleted successfully!
File H:\WINDOWS\System32\Drivers\btcusb.sys not found.
Service btaudio stopped successfully!
Service btaudio deleted successfully!
File H:\WINDOWS\System32\drivers\btaudio.sys not found.
Service BT stopped successfully!
Service BT deleted successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{511131f1-4629-4254-a85f-ed7b6d75dd3c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "http://slirsredirect.search.aol.com/sli ... ie7&query=" removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3 removed from extensions.enabledItems
Prefs.js: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26 removed from extensions.enabledItems
Prefs.js: jqs@sun.com:1.0 removed from extensions.enabledItems
Prefs.js: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102 removed from extensions.enabledItems
Prefs.js: support@predictad.com:1.11 removed from extensions.enabledItems
Prefs.js: xmlfiller@software602.cz:3.1.6 removed from extensions.enabledItems
Prefs.js: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.0.9 removed from extensions.enabledItems
Prefs.js: "http://search.seznam.cz/?sourceid=FF_5&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{511131f1-4629-4254-a85f-ed7b6d75dd3c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{511131f1-4629-4254-a85f-ed7b6d75dd3c}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EWABQAF7KL deleted successfully.
H:\Documents and Settings\mirin\Local Settings\temp\Kzh.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsSysControl deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe moved successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
H:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ca24f87-9c72-11de-8dfa-0009dd109f16}\ not found.
SSHNAS removed from NetSvcs value successfully!
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\temp folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\throbbers folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\stubs folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\sort folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\misc folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\images folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content\blocks folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox\content folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ\AlawarGameBox folder moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikacÝ folder moved successfully.
H:\WINDOWS\002559_.tmp deleted successfully.
H:\WINDOWS\SET21.tmp deleted successfully.
H:\WINDOWS\SET28.tmp deleted successfully.
H:\WINDOWS\SET2B.tmp deleted successfully.
H:\WINDOWS\SET3.tmp deleted successfully.
H:\WINDOWS\SET37.tmp deleted successfully.
H:\WINDOWS\SET4.tmp deleted successfully.
H:\WINDOWS\SET62.tmp deleted successfully.
H:\WINDOWS\SET8.tmp deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp deleted successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp deleted successfully.
H:\WINDOWS\System32\SET1CD.tmp deleted successfully.
H:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job moved successfully.
H:\Documents and Settings\mirin\Data aplikací\DRO110.tmp.exe moved successfully.
File H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe not found.
H:\Documents and Settings\mirin\Data aplikací\DRO10F.tmp.exe moved successfully.
H:\Documents and Settings\mirin\Data aplikací\bAf7e.txt moved successfully.
H:\Documents and Settings\mirin\Data aplikací\BgMek.txt moved successfully.
H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP folder moved successfully.
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B3D74A13 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:B7ADB4DA .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:3BD4D405 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:DFC5A2B2 .
Unable to delete ADS H:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:88D03673 .
H:\Documents and Settings\mirin\Data aplikací\inst.exe moved successfully.
H:\Documents and Settings\mirin\Data aplikac�\Nokia\Ovi Suite folder moved successfully.
H:\Documents and Settings\mirin\Data aplikac�\Nokia folder moved successfully.
H:\Documents and Settings\mirin\Data aplikac� folder moved successfully.
Folder H:\Documents and Settings\mirin\Data aplikac�\ not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\H:\Documents and Settings\mirin\Data aplikací\winsvrcn.exe deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Administrator.VERA
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: All Users.WINDOWS
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY.001
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: mirek
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5243058 bytes
->FireFox cache emptied: 81046742 bytes
->Flash cache emptied: 3772 bytes
User: mirin
->Temp folder emptied: 572288 bytes
->Temporary Internet Files folder emptied: 12971502 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 139141815 bytes
->Google Chrome cache emptied: 417788062 bytes
->Flash cache emptied: 10412 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: NetworkService.NT AUTHORITY.001
->Temp folder emptied: 393290 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Pc
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 112623329 bytes
->Flash cache emptied: 4177 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 465220 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 51758370 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 784,00 mb
[EMPTYFLASH]
User: Administrator
User: Administrator.VERA
User: All Users
User: All Users.WINDOWS
User: Default User
User: Default User.WINDOWS
User: LocalService
User: LocalService.NT AUTHORITY
User: LocalService.NT AUTHORITY.000
User: LocalService.NT AUTHORITY.001
User: mirek
->Flash cache emptied: 0 bytes
User: mirin
->Flash cache emptied: 0 bytes
User: NetworkService
User: NetworkService.NT AUTHORITY
User: NetworkService.NT AUTHORITY.000
User: NetworkService.NT AUTHORITY.001
User: Pc
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.8.1 log created on 07082010_221852
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji
celou dobu se chova normalně
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji

- Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
- Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

- Spusťte.
- Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

- Spusťte.
- Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)

- Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.
Záložka Čistič
- Dejte analyzovat, po dokončení dejte Spustit Ccleaner.
Záložka Registry
- Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
OK
Zavřít



Re: prosim o kontrolu děkuji
Logfile of random's system information tool 1.07 (written by random/random)
Run by mirin at 2010-07-08 22:59:29
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 98 GB (64%) free of 153 GB
Total RAM: 1015 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:59:40, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\Program Files\Seznam.cz\postak.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\ICQ6.5\ICQ.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 6434 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe [2009-12-26 289584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\uTorrent\uTorrent.exe"="H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
======List of files/folders created in the last 1 months======
2010-07-08 22:59:29 ----D---- H:\rsit
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 22:59:40 ----D---- H:\WINDOWS\Prefetch
2010-07-08 22:59:40 ----D---- H:\Program Files\Trend Micro
2010-07-08 22:59:36 ----SD---- H:\WINDOWS\Tasks
2010-07-08 22:59:28 ----D---- H:\WINDOWS\temp
2010-07-08 22:57:48 ----D---- H:\WINDOWS
2010-07-08 22:55:11 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 22:53:52 ----D---- H:\WINDOWS\system32\Restore
2010-07-08 22:53:51 ----SHD---- H:\System Volume Information
2010-07-08 22:52:25 ----N---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 22:19:01 ----D---- H:\WINDOWS\system32
2010-07-08 22:19:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-07-08 21:13:12 ----D---- H:\WINDOWS\UbiSoft
2010-07-08 21:13:12 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-29 23:49:50 ----SHD---- H:\WINDOWS\Installer
2010-06-29 23:49:50 ----D---- H:\Config.Msi
2010-06-29 23:49:32 ----HD---- H:\WINDOWS\inf
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 20:59:44 ----D---- H:\Program Files
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Run by mirin at 2010-07-08 22:59:29
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 98 GB (64%) free of 153 GB
Total RAM: 1015 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:59:40, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\Program Files\Seznam.cz\postak.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\ICQ6.5\ICQ.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 6434 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe [2009-12-26 289584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\uTorrent\uTorrent.exe"="H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
======List of files/folders created in the last 1 months======
2010-07-08 22:59:29 ----D---- H:\rsit
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 22:59:40 ----D---- H:\WINDOWS\Prefetch
2010-07-08 22:59:40 ----D---- H:\Program Files\Trend Micro
2010-07-08 22:59:36 ----SD---- H:\WINDOWS\Tasks
2010-07-08 22:59:28 ----D---- H:\WINDOWS\temp
2010-07-08 22:57:48 ----D---- H:\WINDOWS
2010-07-08 22:55:11 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 22:53:52 ----D---- H:\WINDOWS\system32\Restore
2010-07-08 22:53:51 ----SHD---- H:\System Volume Information
2010-07-08 22:52:25 ----N---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 22:19:01 ----D---- H:\WINDOWS\system32
2010-07-08 22:19:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-07-08 21:13:12 ----D---- H:\WINDOWS\UbiSoft
2010-07-08 21:13:12 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-29 23:49:50 ----SHD---- H:\WINDOWS\Installer
2010-06-29 23:49:50 ----D---- H:\Config.Msi
2010-06-29 23:49:32 ----HD---- H:\WINDOWS\inf
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 20:59:44 ----D---- H:\Program Files
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: prosim o kontrolu děkuji
Caroprd111 píše:V logu nevidím firewall, doinstalujte
Přehled: http://www.viry.cz/forum/viewtopic.php?f=41&t=6523
Re: prosim o kontrolu děkuji
Logfile of random's system information tool 1.07 (written by random/random)
Run by mirin at 2010-07-08 23:13:41
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 98 GB (64%) free of 153 GB
Total RAM: 1015 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:13:54, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\Program Files\Seznam.cz\postak.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\ICQ6.5\ICQ.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 6926 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
======List of files/folders created in the last 1 months======
2010-07-08 22:59:29 ----D---- H:\rsit
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 23:13:52 ----D---- H:\Program Files\Trend Micro
2010-07-08 23:12:52 ----D---- H:\WINDOWS\Prefetch
2010-07-08 23:12:52 ----D---- H:\Program Files
2010-07-08 23:12:50 ----D---- H:\Documents and Settings\mirin\Data aplikací\uTorrent
2010-07-08 23:12:34 ----D---- H:\WINDOWS\temp
2010-07-08 23:10:09 ----D---- H:\WINDOWS
2010-07-08 23:09:56 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 23:08:28 ----A---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 23:07:43 ----SHD---- H:\WINDOWS\Installer
2010-07-08 23:07:43 ----D---- H:\Config.Msi
2010-07-08 23:07:38 ----HD---- H:\WINDOWS\inf
2010-07-08 23:07:34 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 23:07:34 ----D---- H:\WINDOWS\system32
2010-07-08 22:59:36 ----SD---- H:\WINDOWS\Tasks
2010-07-08 22:53:52 ----D---- H:\WINDOWS\system32\Restore
2010-07-08 22:53:51 ----SHD---- H:\System Volume Information
2010-07-08 22:19:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-07-08 21:13:12 ----D---- H:\WINDOWS\UbiSoft
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 SbFw;SbFw; H:\WINDOWS\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; H:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; H:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 SbPF.Launcher;SbPF.Launcher; H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SPF4;Sunbelt Personal Firewall 4; H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Run by mirin at 2010-07-08 23:13:41
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 98 GB (64%) free of 153 GB
Total RAM: 1015 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:13:54, on 8.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
h:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\TUProgSt.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\hkcmd.exe
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
H:\Program Files\Microsoft Security Essentials\msseces.exe
H:\Program Files\RocketDock\RocketDock.exe
H:\Program Files\Seznam.cz\postak.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\ICQ6.5\ICQ.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe
H:\Documents and Settings\mirin\Plocha\RSIT.exe
H:\Program Files\trend micro\mirin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1098640
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - H:\Program Files\Seznam.cz\core.2.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] H:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [MSSE] "h:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [RocketDock] "H:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Seznam Postak] "H:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "H:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6706363312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9383834953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - H:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - H:\WINDOWS\System32\TUProgSt.exe
--
End of file - 6926 bytes
======Scheduled tasks folder======
H:\WINDOWS\tasks\1-Click Maintenance.job
H:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1241337759.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1085031214-682003330-1004UA.job
H:\WINDOWS\tasks\MP Scheduled Scan.job
H:\WINDOWS\tasks\Úklid 1 kliknutím.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - H:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-17 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-26 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - H:\Program Files\Seznam.cz\core.2.dll [2010-03-01 1107608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=H:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"igfxhkcmd"=H:\WINDOWS\system32\hkcmd.exe [2005-11-28 77824]
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"MSSE"=h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=H:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Seznam Postak"=H:\Program Files\Seznam.cz\postak.exe [2010-03-01 451224]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=H:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Google Update"=H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
H:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\mirin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-17 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
h:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
H:\Program Files\Nokia\Nokia Music\NokiaMusic.exe [2009-07-02 2327840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-06-18 671608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre6\bin\jusched.exe [2009-12-26 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
H:\Program Files\uTorrent\uTorrent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
H:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^Adobe Media Player.lnk]
H:\Program Files\Adobe Media Player\Adobe Media Player.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^Documents and Settings^mirin^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
H:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
H:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\VideoLAN\VLC\vlc.exe"="H:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"H:\Program Files\Real\RealPlayer\realplay.exe"="H:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Documents and Settings\mirin\Plocha\Skype.exe"="H:\Documents and Settings\mirin\Plocha\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594870da-d7a6-11de-8e85-0009dd109f16}]
shell\AutoRun\command - I:\InstallTomTomHOME.exe
======List of files/folders created in the last 1 months======
2010-07-08 22:59:29 ----D---- H:\rsit
2010-07-06 17:28:24 ----AH---- H:\WINDOWS\system32\winrtsnr.txt
2010-06-23 19:57:58 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2010-06-21 20:59:44 ----D---- H:\Program Files\Games
2010-06-20 22:14:49 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alawar Stargaze
2010-06-20 22:14:37 ----D---- H:\Program Files\Alawar.com
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\VisualShape
2010-06-20 21:26:59 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\VisualShape
2010-06-20 21:26:14 ----D---- H:\Program Files\Alawar
2010-06-16 18:52:49 ----D---- H:\Program Files\Conduit
2010-06-12 22:15:58 ----HDC---- H:\WINDOWS\$NtUninstallWdf01009$
2010-06-10 23:22:27 ----HDC---- H:\WINDOWS\$NtUninstallKB980218$
2010-06-10 23:21:00 ----HDC---- H:\WINDOWS\$NtUninstallKB980195$
2010-06-10 23:19:01 ----HDC---- H:\WINDOWS\$NtUninstallKB979559$
2010-06-10 23:13:47 ----HDC---- H:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 23:13:41 ----HDC---- H:\WINDOWS\$NtUninstallKB979482$
2010-06-10 23:13:35 ----HDC---- H:\WINDOWS\$NtUninstallKB975562$
======List of files/folders modified in the last 1 months======
2010-07-08 23:13:52 ----D---- H:\Program Files\Trend Micro
2010-07-08 23:12:52 ----D---- H:\WINDOWS\Prefetch
2010-07-08 23:12:52 ----D---- H:\Program Files
2010-07-08 23:12:50 ----D---- H:\Documents and Settings\mirin\Data aplikací\uTorrent
2010-07-08 23:12:34 ----D---- H:\WINDOWS\temp
2010-07-08 23:10:09 ----D---- H:\WINDOWS
2010-07-08 23:09:56 ----D---- H:\WINDOWS\system32\CatRoot2
2010-07-08 23:08:28 ----A---- H:\WINDOWS\SchedLgU.Txt
2010-07-08 23:07:43 ----SHD---- H:\WINDOWS\Installer
2010-07-08 23:07:43 ----D---- H:\Config.Msi
2010-07-08 23:07:38 ----HD---- H:\WINDOWS\inf
2010-07-08 23:07:34 ----D---- H:\WINDOWS\system32\drivers
2010-07-08 23:07:34 ----D---- H:\WINDOWS\system32
2010-07-08 22:59:36 ----SD---- H:\WINDOWS\Tasks
2010-07-08 22:53:52 ----D---- H:\WINDOWS\system32\Restore
2010-07-08 22:53:51 ----SHD---- H:\System Volume Information
2010-07-08 22:19:01 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-07-08 21:13:12 ----D---- H:\WINDOWS\UbiSoft
2010-07-08 21:00:03 ----A---- H:\mbam-error.txt
2010-07-08 21:00:02 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2010-07-06 18:52:59 ----D---- H:\Documents and Settings\mirin\Data aplikací\ICQ
2010-07-05 18:25:21 ----D---- H:\Documents and Settings\mirin\Data aplikací\vlc
2010-07-05 18:12:54 ----D---- H:\Documents and Settings\mirin\Data aplikací\dvdcss
2010-07-03 20:14:14 ----D---- H:\Documents and Settings\mirin\Data aplikací\Vso
2010-06-29 23:49:51 ----D---- H:\Program Files\Microsoft Security Essentials
2010-06-28 18:08:46 ----D---- H:\Program Files\Mozilla Firefox
2010-06-24 19:57:44 ----D---- H:\WINDOWS\Microsoft.NET
2010-06-24 19:57:40 ----RSD---- H:\WINDOWS\assembly
2010-06-24 00:13:45 ----D---- H:\WINDOWS\WinSxS
2010-06-23 20:05:14 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\OviInstallerCache
2010-06-23 20:00:33 ----D---- H:\Program Files\Common Files\Nokia
2010-06-23 19:59:08 ----DC---- H:\WINDOWS\system32\DRVSTORE
2010-06-23 19:59:03 ----D---- H:\Program Files\PC Connectivity Solution
2010-06-21 14:03:06 ----D---- H:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
2010-06-20 20:05:07 ----D---- H:\Program Files\GameTop.com
2010-06-18 14:14:12 ----D---- H:\Documents and Settings\mirin\Data aplikací\Skype
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Minidump
2010-06-17 22:03:28 ----D---- H:\WINDOWS\Debug
2010-06-17 21:59:34 ----D---- H:\Program Files\CCleaner
2010-06-17 18:30:43 ----SD---- H:\Documents and Settings\mirin\Data aplikací\Microsoft
2010-06-16 19:48:59 ----D---- H:\Program Files\ICQ6.5
2010-06-16 18:39:42 ----A---- H:\WINDOWS\NeroDigital.ini
2010-06-14 00:01:16 ----D---- H:\Documents and Settings\mirin\Data aplikací\skypePM
2010-06-13 22:11:02 ----D---- H:\Program Files\Common Files\Skype
2010-06-10 23:22:29 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-06-10 23:21:53 ----A---- H:\WINDOWS\win.ini
2010-06-10 23:20:59 ----HD---- H:\WINDOWS\$hf_mig$
2010-06-10 23:18:48 ----D---- H:\Program Files\Internet Explorer
2010-06-09 19:18:33 ----D---- H:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; H:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 SbFw;SbFw; H:\WINDOWS\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; H:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; H:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-11-28 1353820]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; H:\WINDOWS\System32\Drivers\pcouffin.sys [2010-04-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; H:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 snpstd;VideoCAM Messenger; H:\WINDOWS\system32\DRIVERS\snpstd.sys [2004-06-25 331008]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; H:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; H:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WsAudioDevice_383;WsAudioDevice_383; H:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S3 BthEnum;Ovladač pro Bluetooth Request Block; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 btnetBUs;Bluetooth PAN Bus Service; H:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 IvtBtBUs;IVT Bluetooth Bus Service; H:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; H:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; H:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; H:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; H:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre6\bin\jqs.exe [2009-12-26 153376]
R2 MsMpSvc;Microsoft Antimalware Service; h:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 SbPF.Launcher;SbPF.Launcher; H:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SPF4;Sunbelt Personal Firewall 4; H:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; H:\WINDOWS\System32\TUProgSt.exe [2010-03-07 603904]
R2 UxTuneUp;TuneUp Theme Extension; H:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; H:\WINDOWS\System32\TuneUpDefragService.exe [2010-03-07 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------