spusťte, až po vás bude chtít potvrzení, dejte Ano a nechte ho pracovat...sám uklidí po předchozích programech

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o kontrolu logu
Moderátor: Moderátoři
					Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
	Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
spusťte, až po vás bude chtít potvrzení, dejte Ano a nechte ho pracovat...sám uklidí po předchozích programech
Re: prosím o kontrolu logu
tu je ten log ...
ale pýtalo to odo mna aby som si namiesto SP3 čo mám v PC nainštaloval SP2, to je normálne?
ComboFix 10-07-28.01 - Tomáš 29.07.2010 10:32:55.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1279.807 [GMT 2:00]
Running from: c:\documents and settings\Tomáš\My Documents\Preberanie\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-29 )))))))))))))))))))))))))))))))
.
2010-07-28 17:04 . 2010-07-28 17:05 -------- d-----w- c:\program files\Ask.com
2010-07-25 19:23 . 2010-07-25 19:41 -------- d-----w- c:\program files\Counter-Strike Source
2010-07-25 15:34 . 2010-07-25 15:34 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-07-23 18:30 . 2010-07-23 18:30 -------- d-----w- c:\program files\ZoneAlarm
2010-07-23 18:29 . 2010-05-20 16:10 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-07-23 18:29 . 2010-05-20 16:10 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-07-23 18:29 . 2010-05-20 16:10 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-07-23 18:29 . 2010-07-23 18:31 -------- d-----w- c:\windows\system32\ZoneLabs
2010-07-23 18:29 . 2010-07-23 18:29 -------- d-----w- c:\program files\Zone Labs
2010-07-23 18:21 . 2010-07-23 18:21 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-17 16:03 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-29 09:04 . 2010-06-29 09:04 -------- d-----w- c:\program files\TeamViewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-29 08:23 . 2010-06-14 17:09 -------- d-----w- c:\program files\trend micro
2010-07-26 11:42 . 2010-04-28 13:13 -------- d-----w- c:\program files\JDownloader
2010-07-25 15:01 . 2010-01-09 18:27 -------- d-----w- c:\program files\Alfa
2010-07-25 08:21 . 2010-01-02 20:37 -------- d-----w- c:\program files\Steam
2010-07-25 08:20 . 2010-01-03 09:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-23 18:29 . 2010-06-14 18:21 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-06-18 18:34 . 2010-06-18 18:34 -------- d-----w- c:\program files\MSECache
2010-06-16 19:00 . 2010-06-16 18:58 -------- d-----w- c:\program files\ICQ7.2
2010-06-16 18:58 . 2010-02-25 17:06 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-06-16 18:58 . 2010-01-02 19:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 11:04 . 2010-06-16 11:04 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-14 18:22 . 2010-06-14 18:22 -------- d-----w- c:\program files\Conduit
2010-06-14 18:21 . 2010-06-14 18:21 -------- d-----w- c:\program files\CheckPoint
2010-06-14 14:31 . 2010-01-02 18:57 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:37 . 2010-06-12 15:37 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-06-12 15:36 . 2010-06-12 15:36 -------- d-----w- c:\program files\Common Files\Skype
2010-06-12 15:36 . 2010-06-12 15:36 -------- d-----r- c:\program files\Skype
2010-06-12 15:36 . 2010-01-03 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-06-10 18:46 . 2010-06-10 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-10 18:01 . 2010-01-18 17:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-06 11:52 . 2010-01-09 19:12 9661 ----a-w- c:\documents and settings\All Users\Application Data\DVD X Studios\DVD X Player 4.1 Professional\DVDXPlayer.dll
2010-06-04 20:59 . 2010-01-03 10:31 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-06 10:41 . 2007-12-07 02:01 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2007-08-27 12:42 1851264 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 09:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-11-20 2363392]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" [2007-04-21 563200]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-20 1043968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic Professional 6\\0iolobtdfg c:\windows\system32
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
2007-08-09 14:48 528384 ----a-r- c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX6000 Series]
2006-02-13 03:00 131072 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBIE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-06-25 14:12 1414144 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 14:12 26192168 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-08 18:21 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-18 19:05 204288 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Tomáš\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\SteamApps\\el_megi\\counter-strike source\\hl2.exe"=
"d:\\Counter Strike 1,6\\hl.exe"=
"d:\\Counter Strike 1,6\\cstrike.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.1.2010 12:32 138624]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [9.1.2010 20:27 51072]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2.1.2010 21:24 108289]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [18.5.2010 16:01 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [18.5.2010 16:01 493032]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5.5.2010 17:35 136176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8.1.2010 19:34 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-11-20 13:28 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-05 15:35]
2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-05 15:35]
2010-07-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 13:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&q=
FF - component: c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-29 10:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(764)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'explorer.exe'(3024)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2010-07-29 10:40:38
ComboFix-quarantined-files.txt 2010-07-29 08:40
Pre-Run: 3 478 425 600 bytes free
Post-Run: 3 471 519 744 voľných bajtov
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 3A63A8A0B36CCE6B1B571517DE1960CB
			
			
									
									
						ale pýtalo to odo mna aby som si namiesto SP3 čo mám v PC nainštaloval SP2, to je normálne?
ComboFix 10-07-28.01 - Tomáš 29.07.2010 10:32:55.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1279.807 [GMT 2:00]
Running from: c:\documents and settings\Tomáš\My Documents\Preberanie\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-29 )))))))))))))))))))))))))))))))
.
2010-07-28 17:04 . 2010-07-28 17:05 -------- d-----w- c:\program files\Ask.com
2010-07-25 19:23 . 2010-07-25 19:41 -------- d-----w- c:\program files\Counter-Strike Source
2010-07-25 15:34 . 2010-07-25 15:34 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-07-23 18:30 . 2010-07-23 18:30 -------- d-----w- c:\program files\ZoneAlarm
2010-07-23 18:29 . 2010-05-20 16:10 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-07-23 18:29 . 2010-05-20 16:10 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-07-23 18:29 . 2010-05-20 16:10 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-07-23 18:29 . 2010-07-23 18:31 -------- d-----w- c:\windows\system32\ZoneLabs
2010-07-23 18:29 . 2010-07-23 18:29 -------- d-----w- c:\program files\Zone Labs
2010-07-23 18:21 . 2010-07-23 18:21 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-17 16:03 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-29 09:04 . 2010-06-29 09:04 -------- d-----w- c:\program files\TeamViewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-29 08:23 . 2010-06-14 17:09 -------- d-----w- c:\program files\trend micro
2010-07-26 11:42 . 2010-04-28 13:13 -------- d-----w- c:\program files\JDownloader
2010-07-25 15:01 . 2010-01-09 18:27 -------- d-----w- c:\program files\Alfa
2010-07-25 08:21 . 2010-01-02 20:37 -------- d-----w- c:\program files\Steam
2010-07-25 08:20 . 2010-01-03 09:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-23 18:29 . 2010-06-14 18:21 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-06-18 18:34 . 2010-06-18 18:34 -------- d-----w- c:\program files\MSECache
2010-06-16 19:00 . 2010-06-16 18:58 -------- d-----w- c:\program files\ICQ7.2
2010-06-16 18:58 . 2010-02-25 17:06 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-06-16 18:58 . 2010-01-02 19:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 11:04 . 2010-06-16 11:04 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-14 18:22 . 2010-06-14 18:22 -------- d-----w- c:\program files\Conduit
2010-06-14 18:21 . 2010-06-14 18:21 -------- d-----w- c:\program files\CheckPoint
2010-06-14 14:31 . 2010-01-02 18:57 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:37 . 2010-06-12 15:37 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-06-12 15:36 . 2010-06-12 15:36 -------- d-----w- c:\program files\Common Files\Skype
2010-06-12 15:36 . 2010-06-12 15:36 -------- d-----r- c:\program files\Skype
2010-06-12 15:36 . 2010-01-03 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-06-10 18:46 . 2010-06-10 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-10 18:01 . 2010-01-18 17:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-06 11:52 . 2010-01-09 19:12 9661 ----a-w- c:\documents and settings\All Users\Application Data\DVD X Studios\DVD X Player 4.1 Professional\DVDXPlayer.dll
2010-06-04 20:59 . 2010-01-03 10:31 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-06 10:41 . 2007-12-07 02:01 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2007-08-27 12:42 1851264 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 09:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-11-20 2363392]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" [2007-04-21 563200]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-20 1043968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic Professional 6\\0iolobtdfg c:\windows\system32
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
2007-08-09 14:48 528384 ----a-r- c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX6000 Series]
2006-02-13 03:00 131072 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBIE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-06-25 14:12 1414144 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 14:12 26192168 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-08 18:21 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-18 19:05 204288 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Tomáš\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\SteamApps\\el_megi\\counter-strike source\\hl2.exe"=
"d:\\Counter Strike 1,6\\hl.exe"=
"d:\\Counter Strike 1,6\\cstrike.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.1.2010 12:32 138624]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [9.1.2010 20:27 51072]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2.1.2010 21:24 108289]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [18.5.2010 16:01 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [18.5.2010 16:01 493032]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5.5.2010 17:35 136176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8.1.2010 19:34 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-11-20 13:28 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-05 15:35]
2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-05 15:35]
2010-07-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 13:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&q=
FF - component: c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-29 10:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(764)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'explorer.exe'(3024)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2010-07-29 10:40:38
ComboFix-quarantined-files.txt 2010-07-29 08:40
Pre-Run: 3 478 425 600 bytes free
Post-Run: 3 471 519 744 voľných bajtov
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 3A63A8A0B36CCE6B1B571517DE1960CB
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
stáhněte  GMER , rozbalte a spusťte
proběhne sken, po jehož ukončení se zobrazí výsledky
poté klikněte na Save a uložíte tak log, jeho obsah sem vložte
pak dle tohoto návodu absolvujte druhý sken a opět obsah logu sem
			
			
									
									
						proběhne sken, po jehož ukončení se zobrazí výsledky
poté klikněte na Save a uložíte tak log, jeho obsah sem vložte
pak dle tohoto návodu absolvujte druhý sken a opět obsah logu sem
Re: prosím o kontrolu logu
log GMER 1
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-01 22:34:41
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\TOM~1\LOCALS~1\Temp\kxtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- EOF - GMER 1.0.15 ----
log GMER 2
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-01 22:32:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\TOM~1\LOCALS~1\Temp\kxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xB14DC610]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xB13ACA74]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xB13AC48E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xB13AC16A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xB13ADB10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xB14DCC10]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xB13AC286]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xB13AC36C]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xB14DC730]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xB13ACD38]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xB13AC7D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xB14DC4B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xB14DC570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xB14DC6D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xB14DC690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xB14DC650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xB14DC7D0]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xB13ABFDA]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xB14DC510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xB14DC590]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xB13ACC76]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xB14DC5D0]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xB13AC8FC]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xB14DC750]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9D45360, 0x24BB1D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1220] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1388] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1844] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1044721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- EOF - GMER 1.0.15 ----
			
			
									
									
						GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-01 22:34:41
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\TOM~1\LOCALS~1\Temp\kxtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- EOF - GMER 1.0.15 ----
log GMER 2
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-01 22:32:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\TOM~1\LOCALS~1\Temp\kxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xB14DC610]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xB13ACA74]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xB13AC48E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xB13AC16A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xB13ADB10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xB14DCC10]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xB13AC286]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xB13AC36C]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xB14DC730]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xB13ACD38]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xB13AC7D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xB14DC4B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xB14DC570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xB14DC6D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xB14DC690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xB14DC650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xB14DC7D0]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xB13ABFDA]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xB14DC510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xB14DC590]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xB13ACC76]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xB14DC5D0]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xB13AC8FC]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xB14DC750]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9D45360, 0x24BB1D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1220] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1388] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1844] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1044721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- EOF - GMER 1.0.15 ----
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
nic špatného tam nevidím, zkusíme ještě toto  
 
stáhněte si OTL z tohoto odkazu http://oldtimer.geekstogo.com/OTL.exe
stažený soubor spusťte jako správce
v otevřeném okně stiskněte tlačítko Prohledat, čímž spustíte sken; vyčkejte prosím dokončení skenu (cca 5 minut); poté se vám otevře okno Poznámkového bloku s logem, jehož obsah sem zkopírujte
			
			
									
									
						stáhněte si OTL z tohoto odkazu http://oldtimer.geekstogo.com/OTL.exe
stažený soubor spusťte jako správce
v otevřeném okně stiskněte tlačítko Prohledat, čímž spustíte sken; vyčkejte prosím dokončení skenu (cca 5 minut); poté se vám otevře okno Poznámkového bloku s logem, jehož obsah sem zkopírujte
Re: prosím o kontrolu logu
ospravedlňujem sa za meškanie, tu sú tie logy
OTL log
OTL logfile created on: 14.8.2010 19:42:27 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
 
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.10 Gb Free Space | 10.76% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 3.59 Gb Free Space | 6.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
 
========== Processes (SafeList) ==========
 
PRC - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
PRC - [2010.07.27 13:00:05 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010.07.02 12:43:36 | 002,202,704 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.05.28 14:45:00 | 000,132,096 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.03.30 11:11:14 | 000,120,320 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2008.07.09 23:34:30 | 001,343,840 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe
PRC - [2008.04.14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.16 10:27:38 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.05.16 10:27:16 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.04.21 16:22:34 | 000,563,200 | ---- | M] () -- C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
PRC - [2006.01.04 18:59:44 | 000,454,656 | ---- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
MOD - [2008.04.14 02:11:57 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mlang.dll
MOD - [2008.04.14 02:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010.07.02 12:44:10 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.07.29 20:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2002.12.17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\NTACCESS.SYS -- (WEBNTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Vsp.sys -- (Vsp)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 4\LU4\FLASHSYS.sys -- (FLASHSYS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\TOM~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010.04.28 08:17:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2010.04.28 08:17:46 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010.04.28 08:17:46 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.01.09 20:27:11 | 000,051,072 | ---- | M] (Identcode Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\ANGELNT.SYS -- (Angelnt)
DRV - [2009.03.19 15:48:18 | 000,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009.02.09 09:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 09:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 09:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 09:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007.05.02 12:09:26 | 010,222,720 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2006.10.22 13:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.10.17 20:22:26 | 000,009,216 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2006.03.28 03:54:00 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\filedisk.sys -- (FileDisk)
DRV - [2005.11.25 15:39:06 | 000,203,776 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: facebookfilter@chocolatesoftware.com:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... 2611275&q="
 
FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.08 19:40:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.07.31 19:54:45 | 000,000,000 | ---D | M]
 
[2010.01.08 17:25:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Extensions
[2010.08.14 18:48:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions
[2010.04.27 18:47:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.02.18 18:39:39 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.07.27 08:56:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.07.27 08:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\facebookfilter@chocolatesoftware.com
[2010.06.08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\conduit.xml
[2010.08.11 19:41:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\icqplugin.xml
[2010.04.02 09:53:40 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\mozilla-add-ons.xml
[2010.08.14 18:48:56 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.07.27 13:00:09 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.07.27 13:00:10 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.07.27 13:00:10 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.07.27 13:00:10 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.07.27 13:00:10 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.07.27 13:00:10 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
 
O1 HOSTS File: ([2010.07.25 20:05:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pre aplikáciu Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [SMSystemAnalyzer] C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic Professional 6\) - File not found
O34 - HKLM BootExecute: (iolobtdfg C:\WINDOWS\system32) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.08.13 20:34:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Desktop\Hudba Maroš
[2010.08.08 18:55:16 | 000,000,000 | ---D | C] -- C:\Program Files\VIAudioi
[2010.08.08 18:50:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Tomáš\Recent
[2010.08.08 18:38:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\Desktop\%USERPROFILE%
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\a3d.dll
[2010.08.04 22:06:53 | 000,000,000 | ---D | C] -- C:\Program Files\VIA Technologies, Inc
[2010.08.04 21:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\Setup Files
[2010.08.04 21:14:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSI
[2010.08.04 21:06:50 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 21:03:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2010.08.04 18:40:05 | 000,000,000 | ---D | C] -- C:\Next Video Converter
[2010.08.03 15:51:34 | 001,033,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlrcmd.dll
[2010.08.03 15:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\RamCleaner
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\ESET
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.07.31 19:55:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.07.31 19:49:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2010.07.31 16:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2010.07.29 10:39:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.07.29 10:31:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.07.29 10:27:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.07.29 10:27:13 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.07.29 10:27:13 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.07.29 10:27:13 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.07.29 10:26:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.07.25 21:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Counter-Strike Source
[2010.07.25 19:53:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.07.23 17:52:39 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010.07.17 18:03:41 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010.01.03 10:29:53 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2010.01.03 10:29:53 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
 
========== Files - Modified Within 30 Days ==========
 
[2010.08.14 19:40:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.14 18:24:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.14 18:24:11 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.14 18:24:09 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.14 18:24:05 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.14 18:24:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.14 18:24:00 | 1341,706,240 | -HS- | M] () -- C:\hiberfil.sys
[2010.08.14 16:27:50 | 005,505,024 | ---- | M] () -- C:\Documents and Settings\Tomáš\NTUSER.DAT
[2010.08.14 16:20:44 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Tomáš\ntuser.ini
[2010.08.14 16:20:35 | 001,577,090 | -H-- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\IconCache.db
[2010.08.14 15:50:39 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.10 21:06:24 | 000,100,864 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.10 20:54:37 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.10 20:48:12 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.08.10 20:38:11 | 000,480,262 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.08.10 20:38:11 | 000,087,200 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.08.10 20:38:09 | 000,557,642 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.09 12:57:56 | 005,841,221 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Rihanna -Te Amo.mp3
[2010.08.09 12:53:56 | 008,675,456 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Keri Hilson - I like.mp3
[2010.08.08 18:55:17 | 000,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vinyl Deck.lnk
[2010.08.08 18:35:49 | 000,000,789 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.08 18:35:49 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.08 18:35:49 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.08 15:49:40 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.INI
[2010.08.07 11:37:16 | 000,001,203 | ---- | M] () -- C:\WINDOWS\SysMech6.INI
[2010.08.04 21:08:15 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 18:47:03 | 000,019,472 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.03 19:22:12 | 000,001,071 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.08.03 15:51:34 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlrcmd.dll
[2010.08.02 20:21:07 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\Tomáš\default.pls
[2010.07.31 19:56:22 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:44:53 | 000,000,032 | ---- | M] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 23:39:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.07.28 19:04:33 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2010.07.27 08:30:35 | 008,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2010.07.25 21:32:30 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.07.25 20:05:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.07.23 20:29:33 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
 
========== Files Created - No Company Name ==========
 
[2010.08.10 20:32:02 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010.08.09 12:57:27 | 005,841,221 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Rihanna -Te Amo.mp3
[2010.08.09 12:53:08 | 008,675,456 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Keri Hilson - I like.mp3
[2010.08.04 21:24:09 | 1341,706,240 | -HS- | C] () -- C:\hiberfil.sys
[2010.08.04 21:06:58 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.07.31 19:56:22 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:40:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 10:27:13 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.07.29 10:27:13 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.07.29 10:27:13 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.07.29 10:27:13 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.07.29 10:27:13 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.07.25 21:32:30 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.02.26 20:56:44 | 000,000,020 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2010.02.01 17:04:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.01.11 16:30:14 | 000,000,391 | ---- | C] () -- C:\WINDOWS\COVERE~1.INI
[2010.01.09 21:11:36 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2010.01.09 20:27:11 | 000,000,405 | ---- | C] () -- C:\WINDOWS\System32\ANGELDOS.SYS
[2010.01.09 14:06:21 | 000,001,203 | ---- | C] () -- C:\WINDOWS\SysMech6.INI
[2010.01.09 13:56:11 | 001,212,928 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2010.01.05 15:02:39 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.03 11:06:51 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.01.03 10:29:54 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2010.01.02 22:05:53 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.01.02 22:05:49 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.01.02 22:05:49 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.01.02 22:05:48 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.01.02 22:05:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.01.02 22:05:47 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.02 22:04:58 | 000,001,071 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.01.02 21:27:31 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\giveio.sys
[2010.01.02 21:13:13 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2006.10.27 16:26:56 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2006.10.22 13:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 13:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 13:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 13:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 13:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 13:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 13:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2000.03.23 16:30:18 | 000,181,760 | ---- | C] () -- C:\WINDOWS\System32\IANGEL32.DLL
[1996.08.20 15:08:46 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\angel32.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
< End of report >
Extras log
OTL Extras logfile created on: 14.8.2010 19:42:27 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
 
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.10 Gb Free Space | 10.76% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 3.59 Gb Free Space | 6.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation)
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation)
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe" = C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam 732897 -- (Valve Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Documents and Settings\Tomáš\temp\TeamViewer\Version5\TeamViewer.exe" = C:\Documents and Settings\Tomáš\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer -- (TeamViewer GmbH)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Program Files\Steam\SteamApps\el_megi\counter-strike source\hl2.exe" = C:\Program Files\Steam\SteamApps\el_megi\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source -- ()
"D:\Counter Strike 1,6\hl.exe" = D:\Counter Strike 1,6\hl.exe:*:Enabled:Half-Life Launcher -- File not found
"D:\Counter Strike 1,6\cstrike.exe" = D:\Counter Strike 1,6\cstrike.exe:*:Enabled:Counter-Strike Launcher -- File not found
"C:\Program Files\Counter-Strike Source\hl2.exe" = C:\Program Files\Counter-Strike Source\hl2.exe:*:Enabled:hl2 -- ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM)
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 19
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{296EB02D-B675-4336-992F-99CD14666C63}" = ALFA 15.01.00
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{7EACD74C-147F-478C-9389-F9F52EE3C88A}" = LightScribe System Software
"{89661B04-C646-4412-B6D3-5E19F02F1F37}" = EAX4 Unified Redist
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9011041B-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1051-7B44-A93000000001}" = Adobe Reader 9.3.3 - Slovak
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D75BB658-662F-4082-B262-8228047F7D67}" = ESET Smart Security
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31051}" = Nero 7 Ultra Edition
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = StarCam Genie
"{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}" = Nokia Software Updater
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner (remove only)
"Counter-Strike: Source" = Counter-Strike: Source
"DVD X Player 4.1 Professional_is1" = DVD X Player 4.1 Professional
"E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Windows Driver Package - Nokia Modem (06/01/2009 4.1)
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
"GOM Player" = GOM Player
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.5.3
"Lexicon 3.0" = Lingea Lexicon 2000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Motocross Madness 2" = Microsoft Motocross Madness 2
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"System Mechanic Professional 6_is1" = iolo technologies' System Mechanic Professional 6
"Totalcmd" = Total Commander (Remove or Repair)
"uTorrent" = µTorrent
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12.5.2010 14:25:00 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie icq.exe, verzia 6.5.0.2024, zlyhanie modulu mshtml.dll,
verzia 7.0.6000.21228, adresa zlyhania 0x000b222c.
 
Error - 16.5.2010 9:04:24 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie matrix3w32s.bin, verzia 0.0.0.0, zlyhanie modulu
matrix3w32s.bin, verzia 0.0.0.0, adresa zlyhania 0x00146a21.
 
Error - 16.5.2010 9:05:10 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie matrix3w32s.bin, verzia 0.0.0.0, zlyhanie modulu
matrix3w32s.bin, verzia 0.0.0.0, adresa zlyhania 0x00146a21.
 
Error - 16.5.2010 9:09:35 | Computer Name = TOMAS | Source = Userenv | ID = 1512
Description = Systém Windows nemôže uvoľniť váš súbor databázy Registry. Pamäť používaná
databázou Registry nebola uvoľnená. Toto je často spôsobené službami spustenými
prostredníctvom používateľského konta. Pokúste sa nakonfigurovať služby tak, aby
pracovali v konte LocalService alebo NetworkService. Ak tento problém pretrváva,
obráťte sa na správcu. PODROBNOSTI - Nedostatok miesta na disku.
 
Error - 21.5.2010 7:53:45 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie icq.exe, verzia 6.5.0.2024, zlyhanie modulu mshtml.dll,
verzia 7.0.6000.21228, adresa zlyhania 0x000b222c.
 
Error - 30.5.2010 3:36:06 | Computer Name = TOMAS | Source = ESENT | ID = 490
Description = svchost (1112) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "Proces nemôže
získať prístup k súboru, pretože daný súbor práve používa iný proces. ". The open
file operation will fail with error -1032 (0xfffffbf8).
 
Error - 30.5.2010 10:03:43 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
 
Error - 1.6.2010 15:14:57 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
 
Error - 3.6.2010 15:00:52 | Computer Name = TOMAS | Source = Avira AntiVir | ID = 4118
Description =
 
Error - 8.6.2010 17:14:55 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
 
[ System Events ]
Error - 4.8.2010 15:04:20 | Computer Name = TOMAS | Source = DCOM | ID = 10005
Description = Server DCOM zistil chybu %1084 pri pokuse spustiť službu EventSystem
s argumentmi potrebnú na spustenie servera: {1BE1F766-5536-11D1-B726-00C04FB926AF}
 
Error - 4.8.2010 15:05:01 | Computer Name = TOMAS | Source = DCOM | ID = 10005
Description = Server DCOM zistil chybu %1084 pri pokuse spustiť službu StiSvc s
argumentmi potrebnú na spustenie servera: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
 
Error - 4.8.2010 15:05:30 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7001
Description = Spustenie služby Spyware Terminator Driver 2, od ktorej závisí služba
Spyware Terminator Realtime Shield Service, zlyhalo kvôli nasledujúcej chybe: %%31
 
Error - 4.8.2010 15:05:30 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7026
Description = Nasledujúce ovládače pre spustenie zavedenia alebo spustenie systému
zlyhali pri načítaní: ehdrv FileDisk Fips intelppm sp_rsdrv2
 
Error - 6.8.2010 3:53:29 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
 
Error - 6.8.2010 3:53:29 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
 
Error - 7.8.2010 3:11:09 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
 
Error - 7.8.2010 3:11:09 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
 
Error - 8.8.2010 12:52:48 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
 
Error - 8.8.2010 12:52:48 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
 
 
< End of report >
			
			
									
									
						OTL log
OTL logfile created on: 14.8.2010 19:42:27 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.10 Gb Free Space | 10.76% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 3.59 Gb Free Space | 6.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
PRC - [2010.07.27 13:00:05 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010.07.02 12:43:36 | 002,202,704 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.05.28 14:45:00 | 000,132,096 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.03.30 11:11:14 | 000,120,320 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2008.07.09 23:34:30 | 001,343,840 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe
PRC - [2008.04.14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.16 10:27:38 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.05.16 10:27:16 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.04.21 16:22:34 | 000,563,200 | ---- | M] () -- C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
PRC - [2006.01.04 18:59:44 | 000,454,656 | ---- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIAudioi\SBADeck\ADeck.exe
========== Modules (SafeList) ==========
MOD - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
MOD - [2008.04.14 02:11:57 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mlang.dll
MOD - [2008.04.14 02:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010.07.02 12:44:10 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.07.29 20:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2002.12.17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\NTACCESS.SYS -- (WEBNTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Vsp.sys -- (Vsp)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 4\LU4\FLASHSYS.sys -- (FLASHSYS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\TOM~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010.04.28 08:17:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2010.04.28 08:17:46 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010.04.28 08:17:46 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.01.09 20:27:11 | 000,051,072 | ---- | M] (Identcode Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\ANGELNT.SYS -- (Angelnt)
DRV - [2009.03.19 15:48:18 | 000,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009.02.09 09:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 09:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 09:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 09:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007.05.02 12:09:26 | 010,222,720 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2006.10.22 13:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.10.17 20:22:26 | 000,009,216 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2006.03.28 03:54:00 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\filedisk.sys -- (FileDisk)
DRV - [2005.11.25 15:39:06 | 000,203,776 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: facebookfilter@chocolatesoftware.com:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... 2611275&q="
FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.08 19:40:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.07.31 19:54:45 | 000,000,000 | ---D | M]
[2010.01.08 17:25:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Extensions
[2010.08.14 18:48:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions
[2010.04.27 18:47:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.02.18 18:39:39 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.07.27 08:56:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.07.27 08:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\facebookfilter@chocolatesoftware.com
[2010.06.08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\conduit.xml
[2010.08.11 19:41:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\icqplugin.xml
[2010.04.02 09:53:40 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\mozilla-add-ons.xml
[2010.08.14 18:48:56 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.07.27 13:00:09 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.07.27 13:00:10 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.07.27 13:00:10 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.07.27 13:00:10 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.07.27 13:00:10 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.07.27 13:00:10 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2010.07.25 20:05:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pre aplikáciu Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [SMSystemAnalyzer] C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic Professional 6\) - File not found
O34 - HKLM BootExecute: (iolobtdfg C:\WINDOWS\system32) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.08.13 20:34:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Desktop\Hudba Maroš
[2010.08.08 18:55:16 | 000,000,000 | ---D | C] -- C:\Program Files\VIAudioi
[2010.08.08 18:50:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Tomáš\Recent
[2010.08.08 18:38:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\Desktop\%USERPROFILE%
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\a3d.dll
[2010.08.04 22:06:53 | 000,000,000 | ---D | C] -- C:\Program Files\VIA Technologies, Inc
[2010.08.04 21:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\Setup Files
[2010.08.04 21:14:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSI
[2010.08.04 21:06:50 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 21:03:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2010.08.04 18:40:05 | 000,000,000 | ---D | C] -- C:\Next Video Converter
[2010.08.03 15:51:34 | 001,033,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlrcmd.dll
[2010.08.03 15:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\RamCleaner
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\ESET
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.07.31 19:55:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.07.31 19:49:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2010.07.31 16:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2010.07.29 10:39:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.07.29 10:31:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.07.29 10:27:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.07.29 10:27:13 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.07.29 10:27:13 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.07.29 10:27:13 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.07.29 10:26:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.07.25 21:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Counter-Strike Source
[2010.07.25 19:53:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.07.23 17:52:39 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010.07.17 18:03:41 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010.01.03 10:29:53 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2010.01.03 10:29:53 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
========== Files - Modified Within 30 Days ==========
[2010.08.14 19:40:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.14 18:24:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.14 18:24:11 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.14 18:24:09 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.14 18:24:05 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.14 18:24:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.14 18:24:00 | 1341,706,240 | -HS- | M] () -- C:\hiberfil.sys
[2010.08.14 16:27:50 | 005,505,024 | ---- | M] () -- C:\Documents and Settings\Tomáš\NTUSER.DAT
[2010.08.14 16:20:44 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Tomáš\ntuser.ini
[2010.08.14 16:20:35 | 001,577,090 | -H-- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\IconCache.db
[2010.08.14 15:50:39 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.10 21:06:24 | 000,100,864 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.10 20:54:37 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.10 20:48:12 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.08.10 20:38:11 | 000,480,262 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.08.10 20:38:11 | 000,087,200 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.08.10 20:38:09 | 000,557,642 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.09 12:57:56 | 005,841,221 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Rihanna -Te Amo.mp3
[2010.08.09 12:53:56 | 008,675,456 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Keri Hilson - I like.mp3
[2010.08.08 18:55:17 | 000,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vinyl Deck.lnk
[2010.08.08 18:35:49 | 000,000,789 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.08 18:35:49 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.08 18:35:49 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.08 15:49:40 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.INI
[2010.08.07 11:37:16 | 000,001,203 | ---- | M] () -- C:\WINDOWS\SysMech6.INI
[2010.08.04 21:08:15 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 18:47:03 | 000,019,472 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.03 19:22:12 | 000,001,071 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.08.03 15:51:34 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlrcmd.dll
[2010.08.02 20:21:07 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\Tomáš\default.pls
[2010.07.31 19:56:22 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:44:53 | 000,000,032 | ---- | M] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 23:39:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.07.28 19:04:33 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2010.07.27 08:30:35 | 008,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2010.07.25 21:32:30 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.07.25 20:05:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.07.23 20:29:33 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
========== Files Created - No Company Name ==========
[2010.08.10 20:32:02 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010.08.09 12:57:27 | 005,841,221 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Rihanna -Te Amo.mp3
[2010.08.09 12:53:08 | 008,675,456 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Keri Hilson - I like.mp3
[2010.08.04 21:24:09 | 1341,706,240 | -HS- | C] () -- C:\hiberfil.sys
[2010.08.04 21:06:58 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.07.31 19:56:22 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:40:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 10:27:13 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.07.29 10:27:13 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.07.29 10:27:13 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.07.29 10:27:13 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.07.29 10:27:13 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.07.25 21:32:30 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.02.26 20:56:44 | 000,000,020 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2010.02.01 17:04:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.01.11 16:30:14 | 000,000,391 | ---- | C] () -- C:\WINDOWS\COVERE~1.INI
[2010.01.09 21:11:36 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2010.01.09 20:27:11 | 000,000,405 | ---- | C] () -- C:\WINDOWS\System32\ANGELDOS.SYS
[2010.01.09 14:06:21 | 000,001,203 | ---- | C] () -- C:\WINDOWS\SysMech6.INI
[2010.01.09 13:56:11 | 001,212,928 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2010.01.05 15:02:39 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.03 11:06:51 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.01.03 10:29:54 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2010.01.02 22:05:53 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.01.02 22:05:49 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.01.02 22:05:49 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.01.02 22:05:48 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.01.02 22:05:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.01.02 22:05:47 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.02 22:04:58 | 000,001,071 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.01.02 21:27:31 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\giveio.sys
[2010.01.02 21:13:13 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2006.10.27 16:26:56 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2006.10.22 13:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 13:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 13:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 13:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 13:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 13:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 13:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2000.03.23 16:30:18 | 000,181,760 | ---- | C] () -- C:\WINDOWS\System32\IANGEL32.DLL
[1996.08.20 15:08:46 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\angel32.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
< End of report >
Extras log
OTL Extras logfile created on: 14.8.2010 19:42:27 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.10 Gb Free Space | 10.76% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 3.59 Gb Free Space | 6.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation)
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation)
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe" = C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam 732897 -- (Valve Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Documents and Settings\Tomáš\temp\TeamViewer\Version5\TeamViewer.exe" = C:\Documents and Settings\Tomáš\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer -- (TeamViewer GmbH)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Program Files\Steam\SteamApps\el_megi\counter-strike source\hl2.exe" = C:\Program Files\Steam\SteamApps\el_megi\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source -- ()
"D:\Counter Strike 1,6\hl.exe" = D:\Counter Strike 1,6\hl.exe:*:Enabled:Half-Life Launcher -- File not found
"D:\Counter Strike 1,6\cstrike.exe" = D:\Counter Strike 1,6\cstrike.exe:*:Enabled:Counter-Strike Launcher -- File not found
"C:\Program Files\Counter-Strike Source\hl2.exe" = C:\Program Files\Counter-Strike Source\hl2.exe:*:Enabled:hl2 -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM)
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 19
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{296EB02D-B675-4336-992F-99CD14666C63}" = ALFA 15.01.00
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{7EACD74C-147F-478C-9389-F9F52EE3C88A}" = LightScribe System Software
"{89661B04-C646-4412-B6D3-5E19F02F1F37}" = EAX4 Unified Redist
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9011041B-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1051-7B44-A93000000001}" = Adobe Reader 9.3.3 - Slovak
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D75BB658-662F-4082-B262-8228047F7D67}" = ESET Smart Security
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31051}" = Nero 7 Ultra Edition
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = StarCam Genie
"{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}" = Nokia Software Updater
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner (remove only)
"Counter-Strike: Source" = Counter-Strike: Source
"DVD X Player 4.1 Professional_is1" = DVD X Player 4.1 Professional
"E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Windows Driver Package - Nokia Modem (06/01/2009 4.1)
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
"GOM Player" = GOM Player
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.5.3
"Lexicon 3.0" = Lingea Lexicon 2000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Motocross Madness 2" = Microsoft Motocross Madness 2
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"System Mechanic Professional 6_is1" = iolo technologies' System Mechanic Professional 6
"Totalcmd" = Total Commander (Remove or Repair)
"uTorrent" = µTorrent
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12.5.2010 14:25:00 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie icq.exe, verzia 6.5.0.2024, zlyhanie modulu mshtml.dll,
verzia 7.0.6000.21228, adresa zlyhania 0x000b222c.
Error - 16.5.2010 9:04:24 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie matrix3w32s.bin, verzia 0.0.0.0, zlyhanie modulu
matrix3w32s.bin, verzia 0.0.0.0, adresa zlyhania 0x00146a21.
Error - 16.5.2010 9:05:10 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie matrix3w32s.bin, verzia 0.0.0.0, zlyhanie modulu
matrix3w32s.bin, verzia 0.0.0.0, adresa zlyhania 0x00146a21.
Error - 16.5.2010 9:09:35 | Computer Name = TOMAS | Source = Userenv | ID = 1512
Description = Systém Windows nemôže uvoľniť váš súbor databázy Registry. Pamäť používaná
databázou Registry nebola uvoľnená. Toto je často spôsobené službami spustenými
prostredníctvom používateľského konta. Pokúste sa nakonfigurovať služby tak, aby
pracovali v konte LocalService alebo NetworkService. Ak tento problém pretrváva,
obráťte sa na správcu. PODROBNOSTI - Nedostatok miesta na disku.
Error - 21.5.2010 7:53:45 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie icq.exe, verzia 6.5.0.2024, zlyhanie modulu mshtml.dll,
verzia 7.0.6000.21228, adresa zlyhania 0x000b222c.
Error - 30.5.2010 3:36:06 | Computer Name = TOMAS | Source = ESENT | ID = 490
Description = svchost (1112) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "Proces nemôže
získať prístup k súboru, pretože daný súbor práve používa iný proces. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 30.5.2010 10:03:43 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
Error - 1.6.2010 15:14:57 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
Error - 3.6.2010 15:00:52 | Computer Name = TOMAS | Source = Avira AntiVir | ID = 4118
Description =
Error - 8.6.2010 17:14:55 | Computer Name = TOMAS | Source = Application Error | ID = 1000
Description = Zlyhanie aplikácie hl2.exe, verzia 0.0.0.0, zlyhanie modulu datacache.dll,
verzia 0.0.0.0, adresa zlyhania 0x0000b423.
[ System Events ]
Error - 4.8.2010 15:04:20 | Computer Name = TOMAS | Source = DCOM | ID = 10005
Description = Server DCOM zistil chybu %1084 pri pokuse spustiť službu EventSystem
s argumentmi potrebnú na spustenie servera: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 4.8.2010 15:05:01 | Computer Name = TOMAS | Source = DCOM | ID = 10005
Description = Server DCOM zistil chybu %1084 pri pokuse spustiť službu StiSvc s
argumentmi potrebnú na spustenie servera: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 4.8.2010 15:05:30 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7001
Description = Spustenie služby Spyware Terminator Driver 2, od ktorej závisí služba
Spyware Terminator Realtime Shield Service, zlyhalo kvôli nasledujúcej chybe: %%31
Error - 4.8.2010 15:05:30 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7026
Description = Nasledujúce ovládače pre spustenie zavedenia alebo spustenie systému
zlyhali pri načítaní: ehdrv FileDisk Fips intelppm sp_rsdrv2
Error - 6.8.2010 3:53:29 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
Error - 6.8.2010 3:53:29 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
Error - 7.8.2010 3:11:09 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
Error - 7.8.2010 3:11:09 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
Error - 8.8.2010 12:52:48 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7038
Description = Služba WMPNetworkSvc sa nemohla s aktuálne nakonfigurovaným heslom
prihlásiť ako NT AUTHORITY\NetworkService kvôli nasledujúcej chybe: %%5 Ak chcete
zabezpečiť správne nakonfigurovanie služby, použite zásuvný modul konzoly MMC (Microsoft
Management
Console).
Error - 8.8.2010 12:52:48 | Computer Name = TOMAS | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Windows Media Player Network Sharing Service zlyhalo
kvôli nasledujúcej chybe: %%1069
< End of report >
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
vůbec nic se neděje, i já jsem teď časově hodně vytížená  
  mrknu na to zítra  
			
			
									
									
						- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
spustte HiJackThis odtud C:\Program Files\trend micro\Tomáš.exe
neprovádějte sken, ale klikněte na tlačítko Open the Misc Tools Section
nahoře jsou čtyři tlačítka, musí být zamáčknuté Misc Tools:

najděte vlevo tlačítko Open ADS Spy , klikněte na něj, v následujícím okně zrušte zaškrtnutí chlívku Quick scan (Windows base folder only), klikněte na Scan, chvíli vyčkejte, než proběhne sken, poté klikněte na Save log (obsah logu sem) a dále pak klikněte na Remove selected
po restartu sem vložte nový log z OTL
			
			
									
									
						neprovádějte sken, ale klikněte na tlačítko Open the Misc Tools Section
nahoře jsou čtyři tlačítka, musí být zamáčknuté Misc Tools:

najděte vlevo tlačítko Open ADS Spy , klikněte na něj, v následujícím okně zrušte zaškrtnutí chlívku Quick scan (Windows base folder only), klikněte na Scan, chvíli vyčkejte, než proběhne sken, poté klikněte na Save log (obsah logu sem) a dále pak klikněte na Remove selected
po restartu sem vložte nový log z OTL
Re: prosím o kontrolu logu
HijackThis log:
C:\Documents and Settings\Administrator.TOMAS\Favorites\Links\Navrhované lokality.url : favicon (25214 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : B3D74A13 (174 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : B3D74A13 (174 bytes)
C:\Documents and Settings\Tomáš\Favorites\Links\Navrhované lokality.url : favicon (25214 bytes)
			
			
									
									
						C:\Documents and Settings\Administrator.TOMAS\Favorites\Links\Navrhované lokality.url : favicon (25214 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : B3D74A13 (174 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : B3D74A13 (174 bytes)
C:\Documents and Settings\Tomáš\Favorites\Links\Navrhované lokality.url : favicon (25214 bytes)
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
na Remove selected jste kliknul? ještě ten nový log z OTL  
			
			
									
									
						Re: prosím o kontrolu logu
áno označil som všetky a klikol na remove 
log z OTL:
OTL logfile created on: 18.8.2010 20:14:36 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
 
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.22 Gb Free Space | 11.38% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 4.18 Gb Free Space | 7.60% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
 
========== Processes (SafeList) ==========
 
PRC - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
PRC - [2010.07.27 13:00:08 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010.07.27 13:00:05 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010.07.02 12:43:36 | 002,202,704 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.05.28 14:45:00 | 000,132,096 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.03.30 11:11:14 | 000,120,320 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2008.04.14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.16 10:27:38 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.05.16 10:27:16 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.04.21 16:22:34 | 000,563,200 | ---- | M] () -- C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
PRC - [2006.01.04 18:59:44 | 000,454,656 | ---- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
MOD - [2008.04.14 02:11:57 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mlang.dll
MOD - [2008.04.14 02:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010.07.02 12:44:10 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.07.29 20:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2002.12.17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\NTACCESS.SYS -- (WEBNTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Vsp.sys -- (Vsp)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 4\LU4\FLASHSYS.sys -- (FLASHSYS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\TOM~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010.04.28 08:17:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2010.04.28 08:17:46 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010.04.28 08:17:46 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.01.09 20:27:11 | 000,051,072 | ---- | M] (Identcode Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\ANGELNT.SYS -- (Angelnt)
DRV - [2009.03.19 15:48:18 | 000,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009.02.09 09:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 09:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 09:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 09:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007.05.02 12:09:26 | 010,222,720 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2006.10.22 13:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.10.17 20:22:26 | 000,009,216 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2006.03.28 03:54:00 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\filedisk.sys -- (FileDisk)
DRV - [2005.11.25 15:39:06 | 000,203,776 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: facebookfilter@chocolatesoftware.com:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... 2611275&q="
 
FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.08 19:40:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.07.31 19:54:45 | 000,000,000 | ---D | M]
 
[2010.01.08 17:25:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Extensions
[2010.08.17 21:30:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions
[2010.04.27 18:47:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.02.18 18:39:39 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.07.27 08:56:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.07.27 08:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\facebookfilter@chocolatesoftware.com
[2010.06.08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\conduit.xml
[2010.08.11 19:41:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\icqplugin.xml
[2010.04.02 09:53:40 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\mozilla-add-ons.xml
[2010.08.17 21:30:18 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.07.27 13:00:09 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.07.27 13:00:10 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.07.27 13:00:10 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.07.27 13:00:10 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.07.27 13:00:10 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.07.27 13:00:10 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
 
O1 HOSTS File: ([2010.07.25 20:05:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pre aplikáciu Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [SMSystemAnalyzer] C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic Professional 6\) - File not found
O34 - HKLM BootExecute: (iolobtdfg C:\WINDOWS\system32) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 90 Days ==========
 
[2010.08.08 18:55:16 | 000,000,000 | ---D | C] -- C:\Program Files\VIAudioi
[2010.08.08 18:50:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Tomáš\Recent
[2010.08.08 18:38:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\Desktop\%USERPROFILE%
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\a3d.dll
[2010.08.04 22:06:53 | 000,000,000 | ---D | C] -- C:\Program Files\VIA Technologies, Inc
[2010.08.04 21:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\Setup Files
[2010.08.04 21:14:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSI
[2010.08.04 21:06:50 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 21:03:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2010.08.04 18:40:05 | 000,000,000 | ---D | C] -- C:\Next Video Converter
[2010.08.03 15:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\RamCleaner
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\ESET
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.07.31 19:55:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.07.31 19:49:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2010.07.31 16:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2010.07.29 10:39:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.07.29 10:31:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.07.29 10:27:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.07.29 10:27:13 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.07.29 10:27:13 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.07.29 10:27:13 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.07.29 10:26:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.07.25 21:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Counter-Strike Source
[2010.07.25 19:53:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.07.23 17:52:39 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010.07.02 12:43:48 | 000,055,256 | ---- | C] (ESET) -- C:\WINDOWS\System32\drivers\epfwtdi.sys
[2010.07.02 12:43:04 | 000,140,752 | ---- | C] (ESET) -- C:\WINDOWS\System32\drivers\eamon.sys
[2010.06.29 11:04:22 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2010.06.18 20:34:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2010.06.16 20:58:09 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.2
[2010.06.15 21:57:56 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\PrivacIE
[2010.06.14 20:36:36 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\IECompatCache
[2010.06.14 20:27:34 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\IETldCache
[2010.06.14 20:22:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\CheckPoint
[2010.06.14 20:22:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\Conduit
[2010.06.14 20:22:05 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010.06.14 20:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2010.06.14 20:20:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010.06.14 20:18:27 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010.06.14 20:18:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\sk-SK
[2010.06.14 19:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.06.12 17:37:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\skypePM
[2010.06.12 17:36:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.06.12 17:36:45 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2010.06.10 20:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\Malwarebytes
[2010.06.10 20:46:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.06.10 20:02:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\Adobe
[2010.06.10 20:01:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010.01.03 10:29:53 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2010.01.03 10:29:53 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
 
========== Files - Modified Within 90 Days ==========
 
[2010.08.18 20:13:12 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.18 20:12:55 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.18 20:12:53 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.18 20:12:48 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.18 20:12:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.18 20:12:43 | 1341,706,240 | -HS- | M] () -- C:\hiberfil.sys
[2010.08.18 20:11:51 | 005,505,024 | ---- | M] () -- C:\Documents and Settings\Tomáš\NTUSER.DAT
[2010.08.18 20:11:45 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Tomáš\ntuser.ini
[2010.08.18 19:40:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.18 18:31:43 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\HijackThis.lnk
[2010.08.17 19:47:16 | 000,001,071 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.08.17 19:46:16 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.16 21:46:00 | 002,639,618 | -H-- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\IconCache.db
[2010.08.16 14:24:04 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.INI
[2010.08.10 21:06:24 | 000,100,864 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.10 20:54:37 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.10 20:48:12 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.08.10 20:38:11 | 000,480,262 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.08.10 20:38:11 | 000,087,200 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.08.10 20:38:09 | 000,557,642 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.08 18:55:17 | 000,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vinyl Deck.lnk
[2010.08.08 18:35:49 | 000,000,789 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.08 18:35:49 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.08 18:35:49 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.07 11:37:16 | 000,001,203 | ---- | M] () -- C:\WINDOWS\SysMech6.INI
[2010.08.04 21:08:15 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 18:47:03 | 000,019,472 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.02 20:21:07 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\Tomáš\default.pls
[2010.07.31 19:56:22 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:44:53 | 000,000,032 | ---- | M] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 23:39:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.07.28 19:04:33 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2010.07.25 21:32:30 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.07.25 20:05:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.07.23 20:29:33 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) -- C:\WINDOWS\System32\drivers\epfwtdi.sys
[2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) -- C:\WINDOWS\System32\drivers\eamon.sys
[2010.06.16 20:59:49 | 000,001,487 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.2.lnk
[2010.06.16 13:04:39 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.06.14 20:27:20 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\Spustiť prehľadávač Internet Explorer.lnk
[2010.06.12 17:37:30 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
 
========== Files Created - No Company Name ==========
 
[2010.08.18 18:31:43 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\HijackThis.lnk
[2010.08.10 20:32:02 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010.08.04 21:24:09 | 1341,706,240 | -HS- | C] () -- C:\hiberfil.sys
[2010.08.04 21:06:58 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.07.31 19:56:22 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:40:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 10:27:13 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.07.29 10:27:13 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.07.29 10:27:13 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.07.29 10:27:13 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.07.29 10:27:13 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.07.25 21:32:30 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.06.16 20:59:49 | 000,001,487 | ---- | C] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.2.lnk
[2010.06.16 13:04:39 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.06.14 20:21:36 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.06.14 20:10:32 | 000,008,370 | ---- | C] () -- C:\WINDOWS\System32\IE8Eula.rtf
[2010.06.12 17:37:30 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.02.26 20:56:44 | 000,000,020 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2010.02.01 17:04:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.01.11 16:30:14 | 000,000,391 | ---- | C] () -- C:\WINDOWS\COVERE~1.INI
[2010.01.09 21:11:36 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2010.01.09 20:27:11 | 000,000,405 | ---- | C] () -- C:\WINDOWS\System32\ANGELDOS.SYS
[2010.01.09 14:06:21 | 000,001,203 | ---- | C] () -- C:\WINDOWS\SysMech6.INI
[2010.01.09 13:56:11 | 001,212,928 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2010.01.05 15:02:39 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.03 11:06:51 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.01.03 10:29:54 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2010.01.02 22:05:53 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.01.02 22:05:49 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.01.02 22:05:49 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.01.02 22:05:48 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.01.02 22:05:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.01.02 22:05:47 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.02 22:04:58 | 000,001,071 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.01.02 21:27:31 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\giveio.sys
[2010.01.02 21:13:13 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2006.10.27 16:26:56 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2006.10.22 13:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 13:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 13:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 13:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 13:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 13:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 13:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2000.03.23 16:30:18 | 000,181,760 | ---- | C] () -- C:\WINDOWS\System32\IANGEL32.DLL
[1996.08.20 15:08:46 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\angel32.dll
 
========== LOP Check ==========
 
[2010.01.09 21:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD X Studios
[2010.07.31 19:54:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.06.16 20:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2010.01.08 19:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010.01.09 13:55:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2010.01.05 13:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2010.01.08 19:37:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2010.01.08 19:42:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010.08.08 18:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010.01.05 14:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\BSplayer PRO
[2010.06.14 20:22:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\CheckPoint
[2010.01.03 10:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\EPSON
[2010.07.31 19:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.08.18 18:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\ICQ
[2010.01.18 19:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\InterTrust
[2010.01.09 13:55:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\iolo
[2010.03.16 18:27:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mikrotik
[2010.01.02 22:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\MusicIP
[2010.01.08 19:46:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Nokia
[2010.01.08 19:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\PC Suite
[2010.01.11 20:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Publish Providers
[2010.01.11 20:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Sony
[2010.03.30 20:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\TeamViewer
[2010.01.03 11:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\URSoft
[2010.08.07 10:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\uTorrent
[2010.01.25 17:49:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\VitySoft
 
========== Purity Check ==========
 
 
< End of report >
			
			
									
									
						log z OTL:
OTL logfile created on: 18.8.2010 20:14:36 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Tomáš\My Documents\Preberanie
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2500D:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 2.22 Gb Free Space | 11.38% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 4.18 Gb Free Space | 7.60% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOMAS
Current User Name: Tomáš
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
PRC - [2010.07.27 13:00:08 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010.07.27 13:00:05 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2010.07.02 12:43:36 | 002,202,704 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.05.28 14:45:00 | 000,132,096 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.03.30 11:11:14 | 000,120,320 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2008.04.14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.16 10:27:38 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.05.16 10:27:16 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.04.21 16:22:34 | 000,563,200 | ---- | M] () -- C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
PRC - [2006.01.04 18:59:44 | 000,454,656 | ---- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIAudioi\SBADeck\ADeck.exe
========== Modules (SafeList) ==========
MOD - [2010.08.14 19:41:46 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tomáš\My Documents\Preberanie\OTL.exe
MOD - [2008.04.14 02:11:57 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mlang.dll
MOD - [2008.04.14 02:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010.07.02 12:44:10 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010.07.02 12:43:40 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009.06.02 11:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.07.29 20:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2002.12.17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 18:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\NTACCESS.SYS -- (WEBNTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Vsp.sys -- (Vsp)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 4\LU4\FLASHSYS.sys -- (FLASHSYS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\TOM~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010.04.28 08:17:46 | 000,134,488 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2010.04.28 08:17:46 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010.04.28 08:17:46 | 000,032,584 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.01.09 20:27:11 | 000,051,072 | ---- | M] (Identcode Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\ANGELNT.SYS -- (Angelnt)
DRV - [2009.03.19 15:48:18 | 000,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009.02.09 09:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 09:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 09:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 09:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007.05.02 12:09:26 | 010,222,720 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2006.10.22 13:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.10.17 20:22:26 | 000,009,216 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2006.03.28 03:54:00 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\filedisk.sys -- (FileDisk)
DRV - [2005.11.25 15:39:06 | 000,203,776 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: facebookfilter@chocolatesoftware.com:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... 2611275&q="
FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.08 19:40:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.06 21:28:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.07.31 19:54:45 | 000,000,000 | ---D | M]
[2010.01.08 17:25:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Extensions
[2010.08.17 21:30:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions
[2010.04.27 18:47:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.02.18 18:39:39 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.07.27 08:56:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.07.27 08:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\extensions\facebookfilter@chocolatesoftware.com
[2010.06.08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\conduit.xml
[2010.08.11 19:41:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\icqplugin.xml
[2010.04.02 09:53:40 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Mozilla\Firefox\Profiles\ahisvf8w.default\searchplugins\mozilla-add-ons.xml
[2010.08.17 21:30:18 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.07.27 13:00:09 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.07.27 13:00:10 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.07.27 13:00:10 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.07.27 13:00:10 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.07.27 13:00:10 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.07.27 13:00:10 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2010.07.25 20:05:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pre aplikáciu Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [SMSystemAnalyzer] C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomáš\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic Professional 6\) - File not found
O34 - HKLM BootExecute: (iolobtdfg C:\WINDOWS\system32) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010.08.08 18:55:16 | 000,000,000 | ---D | C] -- C:\Program Files\VIAudioi
[2010.08.08 18:50:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Tomáš\Recent
[2010.08.08 18:38:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\Desktop\%USERPROFILE%
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2010.08.04 22:06:53 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\a3d.dll
[2010.08.04 22:06:53 | 000,000,000 | ---D | C] -- C:\Program Files\VIA Technologies, Inc
[2010.08.04 21:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\Setup Files
[2010.08.04 21:14:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSI
[2010.08.04 21:06:50 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 21:03:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2010.08.04 18:40:05 | 000,000,000 | ---D | C] -- C:\Next Video Converter
[2010.08.03 15:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\RamCleaner
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\ESET
[2010.07.31 19:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.07.31 19:55:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.07.31 19:54:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.07.31 19:49:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2010.07.31 16:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2010.07.29 10:39:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.07.29 10:31:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.07.29 10:27:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.07.29 10:27:13 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.07.29 10:27:13 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.07.29 10:27:13 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.07.29 10:26:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.07.25 21:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Counter-Strike Source
[2010.07.25 19:53:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.07.23 17:52:39 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010.07.02 12:43:48 | 000,055,256 | ---- | C] (ESET) -- C:\WINDOWS\System32\drivers\epfwtdi.sys
[2010.07.02 12:43:04 | 000,140,752 | ---- | C] (ESET) -- C:\WINDOWS\System32\drivers\eamon.sys
[2010.06.29 11:04:22 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2010.06.18 20:34:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2010.06.16 20:58:09 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.2
[2010.06.15 21:57:56 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\PrivacIE
[2010.06.14 20:36:36 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\IECompatCache
[2010.06.14 20:27:34 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Tomáš\IETldCache
[2010.06.14 20:22:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\CheckPoint
[2010.06.14 20:22:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\Conduit
[2010.06.14 20:22:05 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010.06.14 20:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2010.06.14 20:20:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010.06.14 20:18:27 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010.06.14 20:18:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\sk-SK
[2010.06.14 19:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.06.12 17:37:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\skypePM
[2010.06.12 17:36:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.06.12 17:36:45 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2010.06.10 20:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Application Data\Malwarebytes
[2010.06.10 20:46:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.06.10 20:02:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\Adobe
[2010.06.10 20:01:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010.01.03 10:29:53 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2010.01.03 10:29:53 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2010.01.03 10:29:53 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
========== Files - Modified Within 90 Days ==========
[2010.08.18 20:13:12 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.18 20:12:55 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.18 20:12:53 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.18 20:12:48 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.18 20:12:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.18 20:12:43 | 1341,706,240 | -HS- | M] () -- C:\hiberfil.sys
[2010.08.18 20:11:51 | 005,505,024 | ---- | M] () -- C:\Documents and Settings\Tomáš\NTUSER.DAT
[2010.08.18 20:11:45 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Tomáš\ntuser.ini
[2010.08.18 19:40:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.18 18:31:43 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\HijackThis.lnk
[2010.08.17 19:47:16 | 000,001,071 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.08.17 19:46:16 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.16 21:46:00 | 002,639,618 | -H-- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\IconCache.db
[2010.08.16 14:24:04 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.INI
[2010.08.10 21:06:24 | 000,100,864 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.10 20:54:37 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.10 20:48:12 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.08.10 20:38:11 | 000,480,262 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.08.10 20:38:11 | 000,087,200 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.08.10 20:38:09 | 000,557,642 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.08 18:55:17 | 000,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vinyl Deck.lnk
[2010.08.08 18:35:49 | 000,000,789 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.08 18:35:49 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.08 18:35:49 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.07 11:37:16 | 000,001,203 | ---- | M] () -- C:\WINDOWS\SysMech6.INI
[2010.08.04 21:08:15 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.08.04 21:06:50 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.08.04 18:47:03 | 000,019,472 | ---- | M] () -- C:\Documents and Settings\Tomáš\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.02 20:21:07 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\Tomáš\default.pls
[2010.07.31 19:56:22 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:44:53 | 000,000,032 | ---- | M] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 23:39:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.07.28 19:04:33 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2010.07.25 21:32:30 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.07.25 20:05:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.07.23 20:29:33 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.07.02 12:43:48 | 000,055,256 | ---- | M] (ESET) -- C:\WINDOWS\System32\drivers\epfwtdi.sys
[2010.07.02 12:43:04 | 000,140,752 | ---- | M] (ESET) -- C:\WINDOWS\System32\drivers\eamon.sys
[2010.06.16 20:59:49 | 000,001,487 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.2.lnk
[2010.06.16 13:04:39 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.06.14 20:27:20 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\Spustiť prehľadávač Internet Explorer.lnk
[2010.06.12 17:37:30 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
========== Files Created - No Company Name ==========
[2010.08.18 18:31:43 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\HijackThis.lnk
[2010.08.10 20:32:02 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010.08.04 21:24:09 | 1341,706,240 | -HS- | C] () -- C:\hiberfil.sys
[2010.08.04 21:06:58 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.07.31 19:56:22 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\ESET Smart Security.lnk
[2010.07.31 17:01:54 | 000,001,805 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Motocross Madness 2.lnk
[2010.07.31 14:40:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.07.29 10:27:13 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.07.29 10:27:13 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.07.29 10:27:13 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.07.29 10:27:13 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.07.29 10:27:13 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.07.25 21:32:30 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\Tomáš\Desktop\Counter-Strike Source.lnk
[2010.06.16 20:59:49 | 000,001,487 | ---- | C] () -- C:\Documents and Settings\Tomáš\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.2.lnk
[2010.06.16 13:04:39 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.06.14 20:21:36 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.06.14 20:10:32 | 000,008,370 | ---- | C] () -- C:\WINDOWS\System32\IE8Eula.rtf
[2010.06.12 17:37:30 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.02.26 20:56:44 | 000,000,020 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2010.02.01 17:04:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.01.11 16:30:14 | 000,000,391 | ---- | C] () -- C:\WINDOWS\COVERE~1.INI
[2010.01.09 21:11:36 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2010.01.09 20:27:11 | 000,000,405 | ---- | C] () -- C:\WINDOWS\System32\ANGELDOS.SYS
[2010.01.09 14:06:21 | 000,001,203 | ---- | C] () -- C:\WINDOWS\SysMech6.INI
[2010.01.09 13:56:11 | 001,212,928 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2010.01.05 15:02:39 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.03 11:06:51 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.01.03 10:29:54 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2010.01.02 22:05:53 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.01.02 22:05:49 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.01.02 22:05:49 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.01.02 22:05:48 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.01.02 22:05:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.01.02 22:05:47 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.02 22:04:58 | 000,001,071 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.01.02 21:27:31 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\giveio.sys
[2010.01.02 21:13:13 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2006.10.27 16:26:56 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2006.10.22 13:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 13:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 13:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 13:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 13:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 13:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 13:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2000.03.23 16:30:18 | 000,181,760 | ---- | C] () -- C:\WINDOWS\System32\IANGEL32.DLL
[1996.08.20 15:08:46 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\angel32.dll
========== LOP Check ==========
[2010.01.09 21:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD X Studios
[2010.07.31 19:54:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010.06.16 20:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2010.01.08 19:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010.01.09 13:55:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2010.01.05 13:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2010.01.08 19:37:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2010.01.08 19:42:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010.08.08 18:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010.01.05 14:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\BSplayer PRO
[2010.06.14 20:22:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\CheckPoint
[2010.01.03 10:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\EPSON
[2010.07.31 19:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\ESET
[2010.08.18 18:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\ICQ
[2010.01.18 19:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\InterTrust
[2010.01.09 13:55:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\iolo
[2010.03.16 18:27:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Mikrotik
[2010.01.02 22:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\MusicIP
[2010.01.08 19:46:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Nokia
[2010.01.08 19:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\PC Suite
[2010.01.11 20:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Publish Providers
[2010.01.11 20:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\Sony
[2010.03.30 20:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\TeamViewer
[2010.01.03 11:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\URSoft
[2010.08.07 10:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\uTorrent
[2010.01.25 17:49:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tomáš\Application Data\VitySoft
========== Purity Check ==========
< End of report >
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
jsou stále nějaké problémy s pc?
			
			
									
									
						Re: prosím o kontrolu logu
no asi by som povedal že ani nie, síce sa občas stane že ho nejak sekne no neni to už tak časté ako predtým 
ďakujem vám, za váš čas
			
			
									
									
						ďakujem vám, za váš čas
- 1danab
 - Nováček

 - Příspěvky: 1412
 - Registrován: 21 říj 2007 13:04
 - Bydliště: České Budějovice
 - Kontaktovat uživatele:
 
Re: prosím o kontrolu logu
nemáte vůbec zač a kdyby byl nějaký problém, klidně se zase ozvěte  
			
			
									
									
						


        Přispějete na provoz fóra?